Cybersecurity

ALM counts human cost of Ashley Madison hack

Life
Image: Stockfresh

25 August 2015

The fallout from the Ashley Madison leak continued with accusations that the human cost of the hack goes well beyond broken relationships and embarrassment for the infidelity website’s parent company.

Despite concerns over the quality of a third data dump released over the weekend, Ashley Madison owner Avid Life Media is facing at least two class action lawsuits in the US and Canada from ‘John Doe’ former members alleging the company had inadequate security measures and failed to delete their accounts, despite charging a $19 fee to do so.

In the meantime ALM has gone on the offensive, offering a $500,000 reward for information leading to the hackers’ arrests and convictions.

The Web is still hopping with speculation about the method of the hack, how many well-known users will be outed and to what extent a case of suicide in the US can be attributed to the leak.

Malware
Over the weekend, spammers started hijacking conversations on social media by promoting a number of bogus links. Some of them lead to questionable destinations.

While a malware attack hasn’t been confirmed, many of the links tested by Salted Hash routed through several locations before landing on the final page, an affiliate link used to promote books on Amazon. The books themselves are guides and self-help publications geared towards online anonymity. There were also keyword-based items using ‘Ashley Madison’ and offers for romance novels.

On Twitter, many of the profiles promoting the questionable links appear to be bots that are triggered by the phrase ‘Ashley Madison Suicide’ and are using the dlvr.it URL shortening service. Some are recycling the links through Tumblr as well.

The topic is centered on reports that emerged late last week of a San Antonio city employee took their own life after their data was discovered in the Ashley Madison client list. However, this story hasn’t been fully confirmed.

While three San Antonio e-mail addresses were found among the leaked profiles and a city worker in in the area committed suicide last week, the city hasn’t commented on any connection.

The Impact Team has also broken its silence by commenting to the media on ALM’s lack of security around credit card transactions.

During an e-mail exchange with Vice’s technology website Motherboard, Impact Team said: “They [ALM] said they don’t store CC [credit card information]. Sure, they don’t store e-mail either; they just log in every day to [the] server and read. They had password to CC processor. We dumped from CC processor… They have payment processors. The payment processors store most of the credit card number and billing address. Like how Gmail stores their e-mail. They can log in and look up transactions.”

Security
It also seems that security was a concern internally but that little was done to upgrade it on a regular basis. A self-assessment form completed by ALM’s vice president and general counsel Avi Weisman noted that compliance issues were a concern.

In the form Weisman noted there were “voids in understanding compliance and regulatory legal requirements in countries we operate in or are going to operate in. Anytime we have an issue with a regulator/government/legal or administrative body takes time, lobbying, resources, expertise, cost, etc…”

A follow-up question spoke to areas where he’d hate to see something go wrong, to which Weisman listed hacking or operational issues, as a concern, but also singled out “legal mishaps where we need to involve regulators, law enforcement, etc…”.

IDG News Service and TechCentral Reporters

Read More:


Back to Top ↑