home.social

#ddosecrets — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ddosecrets, aggregated by home.social.

fetched live
  1. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

  2. How to obtain and read the leaked Kash Patel emails on Linux (maybe will work on other OS?)

    First download the files from @ddosecrets. They offer both direct DL and torrent options:

    ddosecrets.org/article/kash-pa

    Once you have them unzip the file. These emails are in EML format, and it's possible to import them into Thunderbird so they look just like real emails.

    WARNING: If you have TBird hooked up to a live email account you will be able to answer these emails just as if they'd been sent to you. You probably don't want to do this.

    I'm running Mint 20.3. Unfortunately the version of TBird in the repository is too old to allow the necessary plugin to work, so I had to install the latest version directly. I used the FlatPak, but any way you can get the latest version is fine. You can download it from:

    thunderbird.net/en-US/

    After you have the latest TBird installed go to Addons in the hamburger menu. Search for and install ImportExportTools-NG.

    If you already have an actual email account hooked up in TBird skip the next step. If you don't, as I didn't, the only way I could create a local folder was to add a real email account. I could then create a local folder and delete the real account from TBird. It's not necessary to delete it, but having an outgoing server configured when reading leaked emails worries me.

    So create a local folder and then right-click on it. You should see an ImportExportTools menu item. Click on that and then Import EML messages and then (most efficient) Import All EML Messages from a Directory and all Subdirectories.

    Choose the directory created by unzipping and you're good to go!

    #KashPatel #LeakedEmails #DDOSecrets #Handala #Leaks #FBI #HandalaHackTeam

  3. The group "Department of Peace" hacked the DHS' internal tool for managing contracts and leaked a list of contractors working with ICE ~6000 of them released today. ddosecrets.org/article/ice-con

    Here is a handy explorer for it micahflee.github.io/ice-contra
    #ice #DepartmentOfPeace #ddosecrets

  4. How Debt Collectors Spin Riches from Zombie Home Loans bloomberg.com/graphics/2025-zo

    A new investigation from Bloomberg using exclusive #DDoSecrets exposes how debt collectors and the housing industry take advantage of people

  5. If you want to help keep #DDoSecrets releasing new publications for the rest of 2025, donate to our new fundraiser: donorbox.org/supporting-ddosec

    Speaking of "2025" and "new publications"... stay tuned....

  6. NEW: DDoSecrets has indexed 410GB of data from the #TeleMessage breach, including messages and metadata tied to a Signal clone used by US officials.

    🔗 hackread.com/ddosecrets-adds-410gb-telemessage-breach-data-index/

    #CyberSecurity #DataBreach #DDoSecrets #Privacy

  7. Charli’s Confessions: Interview with Gang Leader who Pacted with Nayib Bukele elfaro.net/en/202515/ef_tv/278 #DDoSecrets #Guacamaya

    In January, El Faro interviewed leaders of the 18th Street Revolucionarios gang who not only cut deals for years with the entourage of Nayib Bukele, but also escaped the country with the complicity of his government. This is the first time that gang leaders who entered supermax prisons in masks during the negotiations reveal the agreements that permitted Bukele’s ascent.

  8. RELEASE: Mineral Resources Authority of Papua New Guinea (356 GB)

    Approximately a million emails and other files from the Mineral Resources Authority of Papua New Guinea, the government agency responsible for overseeing the exploration, mining and other exploitation of mineral resources in Papua New Guinea. The files range approximately from 2009 to 2022.

    ddosecrets.org/article/mineral

    Support #DDoSecrets: donorbox.org/ddosecrets

  9. One possible origin of the #Moustassleaks posted to #DDoSecrets this week: techcrunch.com/2024/11/14/us-c According to victims of the wiretapping and leak, calls recorded in the leak were both conventional cell calls and WhatsApp audio.

  10. RELEASE: APIII leaders target DDoSecrets (3 MB) ddosecrets.org/article/apiii-l

    Dozens of chat messages, photos and audio from inside the APIII State Leaders' private chat. The messages reveal that the militia leadership's interest in #DDoSecrets lasted for at least a year, with the intent of identifying and locating its members. According to the chats, once located, members of the APIII militia planned to visit people from DDoSecrets to make "house calls" and hack them "with an axe".

  11. "Israel’s #ministryofjustice commissioned advice from powerhouse law firm Crowell & Moring on how to “mitigate or reverse the impact” of “a [UN] database of companies undertaking activities in the settlements”.

    "The database, which had been requested by the UN Human Rights Council in 2016, would go on to identify 112 businesses complicit in illegal Israeli settlements. They included several UK-based firms such as digger manufacturer JCB." New research from the #DDoSecrets leak from Israel's government: declassifieduk.org/israels-sec