SOCRadar's Response to the USDoD’s Claim of Scraping 330 Million Emails - SOCRadar® Cyber Intelligence Inc. (2024)

SOCRadar's Response to the USDoD’s Claim of Scraping 330 Million Emails - SOCRadar® Cyber Intelligence Inc. (1)

TL;DR

  1. The claim that the threat actor extracted the data from the SOCRadar platform is inaccurate and does not reflect the true source of the information.
  2. ​In reality, they acquired public Telegram channel names through the SOCRadar Platform, then proceeded to scrape publicly available data from these public Telegram channels.
  3. They manipulated this information to create the false impression that it originated from SOCRadar.
  4. We’ve compiled a comprehensive report with all pertinent details for our customers and partners. To access this report, contact us at [emailprotected].

What Exactly Happened in This Incident?

Recently, a threat actor identified as USDoD posted a claim on an online forum, alleging the breach and leak of over 330 million email addresses, supposedly attributed to SOCRadar. This prompted an immediate investigation by SOCRadar’s security team.

The investigation revealed that SOCRadar’s internal systems were not breached. The threat actor acquired a license from SOCRadar under a legitimate company name, providing access to the platform similar to any other customer. With this account, the actor could search for well-known domain names, collect Telegram channel names, and crawl these channels to harvest email addresses.

It is important to note that no technical vulnerabilities in the SOCRadar platform were exploited. The actor merely utilized functionalities inherent in the platform’s standard offerings, designed to gather information from publicly available sources. This incident highlights a significant issue in information ethics and security: distinguishing between legitimate use and potential misuse.

Is There a Risk to SOCRadar’s Customers?

Following an in-depth analysis of the situation, it has been determined that no access was granted to customer data or critical information. Our findings confirm no data breach involving our customers or SOCRadar’s internal systems.

While the collected data does not present an immediate risk, we maintain close contact with law enforcement and closely monitor the situation as it evolves.

Which Data Was Allegedly Leaked?

The threat actor used our platform to identify Telegram channel names and subsequently crawled these channels to collect email addresses. We have verified that these email addresses were sourced from publicly accessible channels.

How Did the Threat Actor Access the Data?

The threat actor purchased a Dark Web license using a legitimate company account, granting them access to SOCRadar’s platform like any other customer. While technically compliant with our Terms of Service, this method did not adhere to our intended use policies.

Was There a Breach of SOCRadar’s Security Systems?

Our comprehensive investigation concluded that SOCRadar’s security systems were not breached or vulnerabilities were exploited. The threat actor utilized our platform by the Terms of Service but in a manner that did not align with our intended use policies.

Why is Cybersecurity Companies Like SOCRadar Targeted?

Cybersecurity vendors, including KnowBe4, CrowdStrike, and SOCRadar, have recently faced increased attacks from threat actors. These companies are leaders in the fight against cyber threats and enhancing cybersecurity for organizations, making them prime targets for malicious actors seeking to exploit their resources.

What Measures Has SOCRadar Taken in Response?

In response to this incident, SOCRadar is conducting a comprehensive security review. This includes enhancing our monitoring systems to detect anomalies and reinforcing the security of our platform to prevent misuse of legitimate features that could lead to unauthorized actions.

What Should SOCRadar’s Customers and Partners Do?

Currently, no specific actions are required from our customers or partners.

What is SOCRadar’s Commitment Moving Forward?

SOCRadar remains committed to our clients’ security and privacy. We are taking proactive measures, including upgrading our monitoring and access controls, to prevent future misuse.

We also collaborate with law enforcement to ensure all necessary actions are taken. We value transparency and will keep our clients and the security community updated with any significant developments.

A detailed post-mortem analysis report has been prepared for SOCRadar customers and partners. Those wishing to access the report can request it by emailing [emailprotected].

Related Articles

August 2024 Patch Tuesday Highlights: 89 CVEs, 6 Zero-Day Vulnerabilities Under Exploitation

Aug 14, 2024

Critical Vulnerabilities in Progress WhatsUp Gold, Jenkins Could Lead to RCE Attacks (CVE-2024-4885, CVE-2024-43044)

Aug 08, 2024

Unlocking the Future of Cybersecurity: SOCRadar’s Advanced AI Training Returns

Aug 08, 2024

SOCRadar Recognized in Gartner Report on Digital Risk Protection Services and External Attack Surface Management Again

Aug 07, 2024

Major Cyber Attacks in Review: July 2024

Aug 06, 2024

Subscribe to our newsletter and stay updated on the latest insights!

SOCRadar's Response to the USDoD’s Claim of Scraping 330 Million Emails - SOCRadar® Cyber Intelligence Inc. (2024)

References

Top Articles
Craigslist Of Valdosta Georgia
Fedex Drop Off Brooklyn
Custom Screensaver On The Non-touch Kindle 4
O'reilly's Auto Parts Closest To My Location
Martha's Vineyard Ferry Schedules 2024
Craigslist In South Carolina - Craigslist Near You
Becky Hudson Free
Sotyktu Pronounce
What Is A Good Estimate For 380 Of 60
อพาร์ทเมนต์ 2 ห้องนอนในเกาะโคเปนเฮเกน
Best Food Near Detroit Airport
Flower Mound Clavicle Trauma
Belle Delphine Boobs
Spartanburg County Detention Facility - Annex I
Bowlero (BOWL) Earnings Date and Reports 2024
charleston cars & trucks - by owner - craigslist
Bcbs Prefix List Phone Numbers
Aucklanders brace for gales, hail, cold temperatures, possible blackouts; snow falls in Chch
Trac Cbna
Jbf Wichita Falls
Apply for a credit card
Indiana Wesleyan Transcripts
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
The Creator Showtimes Near R/C Gateway Theater 8
پنل کاربری سایت همسریابی هلو
2015 Kia Soul Serpentine Belt Diagram
Astro Seek Asteroid Chart
Little Einsteins Transcript
Warren County Skyward
Www Craigslist Com Shreveport Louisiana
Steven Batash Md Pc Photos
Weekly Math Review Q4 3
Tamilyogi Ponniyin Selvan
Barrage Enhancement Lost Ark
Blue Beetle Movie Tickets and Showtimes Near Me | Regal
Craigslist Lakeside Az
Kelly Ripa Necklace 2022
Tiny Pains When Giving Blood Nyt Crossword
Orion Nebula: Facts about Earth’s nearest stellar nursery
Gary Lezak Annual Salary
Dee Dee Blanchard Crime Scene Photos
Cl Bellingham
Hovia reveals top 4 feel-good wallpaper trends for 2024
Promo Code Blackout Bingo 2023
844 386 9815
Eat Like A King Who's On A Budget Copypasta
How to Install JDownloader 2 on Your Synology NAS
Bf273-11K-Cl
Underground Weather Tropical
18443168434
Runelite Ground Markers
Leslie's Pool Supply Redding California
Latest Posts
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5801

Rating: 4.8 / 5 (48 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.