DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

ElSurveillance hacks and dumps two more dating sites; warns users about “Russian black hats”

Posted on November 12, 2016 by Dissent

The hacktivist known as ElSurveillance, whose operation is #EscortsOffline, is back with two more data dumps from dating sites.

The first target was 24luv.com, where ElSurveillance claims he hacked and dumped 92,937 users’ email addresses and plain-text passwords.

24luvcom
In a defacement on the site, ElSurveillance writes, in part:

I compromised this website about four months ago and I have been watching it for couple of months now
I finally decided to warn all the users and anybody who’s thinking about join this service
This dating website runs under a Russian black hat cyber criminals who aims to collect all your data
As much as possible so they can target you or sell it in the underground market forms
You’re data/personal information ain’t safe, So you are
And you better start thinking about the long term damage this may/might cost you, Your family and friends
There are plenty of profiles out here which are fake and even the reviews are editable and more
Download {92937} Hacked accounts “Email & password” in plain-text
Make sure you change all your passwords
And make sure you warn anybody you know who uses/used this website
I did my best & you should do the rest
Stay safe mate

The message was followed by an encouragement to users to follow Islam and the way of Allah.

The data dump includes 8,081 Gmail logins, 61,035 Yahoo logins, and 9,826 Hotmail logins.

The second site was freedateusa.com, where ElSurveillance left the same defacement message. The database, uploaded to Sendspace, contains 127,395 email addresses and plain-text passwords, including 6,890 Hotmail logins, 42,450 Yahoo logins, and 25,664 Gmail logins.

I asked ElSurveillance if he was serious about the claim that the site was run by Russian blackhats or if he was just trying to scare users off.  In a private chat, he replied that all of the sites that he has been leaking data from are developed by the same developers:

They all share the same Admin username and only 3 different passwords [and are] Hosted on the same server

They edited a profile that I created and the reviews

They even messaged my (sic) on behalf of the users and asked for money or my account will get deleted

The IP address who messaged me matched the IP Address of the admin logs including some of the profiles that were created and many more Passwords are store in plain-text and view-able to the admin

I have been monitoring them for 2 months, And I don’t have a reason why should I scare the users, They will get punished anyway 🙂

ElSurveillance tells DataBreaches.net that in the next few days, he plans to include all the admin identities and login details in a final dump that will include more than 50 dating websites/databases and over 5 million emails and passwords in plain-text.

“I already got the real identities of the developer(s),” ElSurveillance tells this site, “But still trying to figure out if the developer(s) and who runs the sites are the same person/group”

A site lookup shows that both 24luv.com and freedateusa.com are hosted on datingcreator.com and are registered in Russia.

When asked if he had any evidence that the sites are actually selling user data on the dark web, ElSurveillance acknowledged that he had no proof, as he hadn’t looked:

But from the way how I have seen they collect/collected the users data, I strongly believe it’s only to be sold, These targets seems to me never been hacked before “Which I’m surprised” because they all have the same multiple vulnerabilities and the passwords are easy to guess, I never visited any darkweb before to see wither they already are in the darkweb or no, But it could be for the future plan

In any event, we should expect another and larger data dump from ElSurveillance within the week.

Category: Breach IncidentsBusiness SectorHack

Post navigation

← MI: Lansing Board of Water & Light paid $25,000 ransom after cyberattack in April
MLS seeks, finds, plugs data breach →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Why Dumping Sensitive Data on Network Shares is a Liability
  • A militarily degraded Iran may turn to asymmetrical warfare – raising risk of proxy and cyber attacks
  • Pro-Russian hackers disrupt Dutch government websites ahead of NATO summit
  • Iran-Linked Threat Actors Leak Visitors and Athletes’ Data from Saudi Games
  • UK: Oxford City Council still investigating cyberattack from earlier this month
  • Steelmaker Nucor Says Hackers Stole Data in Recent Attack
  • People’s Republic of China cyber threat activity: Cyber Threat Bulletin
  • Ukrainian Web3 security auditing company Hacken suffered an attack that allowed a hacker to create 900 million HAI tokens
  • McLaren provides written notice to 743,131 patients after ransomware attack in July 2024 (2)
  • A state forensics lab was leaking its files. Getting it locked down involved a number of people.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Sky Views Personal Data as a Potential Weapon in IPTV Piracy War
  • Florida Used a Nationwide Surveillance Camera Network 250 Times To Aid in Immigration Arrests
  • Federal Court Strikes Down HIPAA Reproductive Health Care Privacy Rule
  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.