
Social Blade – Social media analytics platform Social Blade confirmed the data breach after its database was breached and sold on a hacking forum.
Social Blade is an analytics platform that provides statistical graphs for YouTube, Twitter, Twitch, Daily Motion, Mixer and Instagram accounts, allowing clients to see projected revenue and projects.
The company provides APIs to integrate customers’ social media data directly into its platform.
After Social contacted Blade about the sale of their data, the company confirmed they were in violation of the law and began sending customers notices about the data breach.
“On December 14th, we were notified of a possible data breach by an individual who exported user databases and attempted to sell them on hacking forums,” the breach notice sent to customers said.
“The pictures have been sent and we have confirmed that they are authentic. “It appears that this individual exploited a vulnerability in our website to gain access to our database.”
This data breach notification states that a customer hacker accessed the company’s database and stole the following information:
While Social Blade notes that users’ passwords are hashed using the bcrypt algorithm and cannot be easily solved, the company still recommends that all users reset their passwords. However, the certificate cannot be reinstalled across the entire platform.
Authorization tokens for business users and connected social media accounts also prevented threat actors from continuing to use those listed in the stolen database.
In response to further questions about whether copyright was used in the attack, SocialBlade sent the following statement:
“As far as we know, no automated signs have been misused. For third-party tokens, they expire and cannot be used within one hour of initial creation.
Some data includes customer IDs and tokens used by users of the Social Edge Business API. These could have been used, but we have no record of their existence. Most of them do not have any credit, so it is useless to try to use them. For users who have paid with credit, we have notified them that they have used their credit. So far no one has reported any problems. If messages arrive, we check them and return the tokens used by the attacker. – SocialBlade.
We first became aware of the data breach on Monday, December 12, when a threat actor began selling company data.
In a forum post on a hacker forum, the threat actor said that the data was stolen in September 2022 and that he wanted to sell it to up to two people.
The hacker claims that the stolen database contains 5.6 million records and the leaked information includes IP addresses, email addresses, database structures and more.
At the time, Tigh was contacted by social media to comment on the accuracy of the sample, and the information was confirmed to be correct.
The company said it has now patched the security loophole the attackers used to gain access to the system and is conducting further investigations to ensure all systems are sufficiently hardened to prevent similar incidents in the future.
“We know that bad actors will continue to infiltrate IT infrastructure around the world, and rest assured that we at Social Edge will never relax our efforts to strengthen our security and defense measures,” the statement said.
Social Blade puts users on the defensive against large-scale data breach fraud attempts, such as stealing passwords and credit card numbers, impersonating a compromised company.
Bill Tolas is a technology writer and news reporter who has worked for a variety of online publications covering open source, Linux, malware, data breaches, and hacking for decades.
Social blade rank, social blade youtube stats, pewdiepie social blade, social blade stats, social blade insta, sites like social blade, blade social, social blade facebook, social blade com youtube, instagram social blade, social blade tiktok, social media blade