The Post Millennial, a conservative news outlet, was subjected to a significant data breach and subsequent data leak. This event compromised the personal information of millions, including hundreds of the site's writers and editors, as well as a large number of subscribers.
The breach occurred on May 2, 2024, and was confirmed by Have I Been Pwned (HIBP) on May 10. The attackers not only accessed and leaked data but also defaced the website, posting a fake letter and links to download the stolen data. The leaked data includes sensitive personal information:
- Writers and Editors: IP, physical addresses, and email addresses were exposed.
- Subscribers: Names, emails, usernames, phone numbers, and passwords in plain text were compromised.
- Mailing Lists: Tens of millions of email addresses from several thousand mailing lists were leaked, though the affiliation of these lists with The Post Millennial has not been independently verified.
The total number of compromised accounts tallies up to 26,818,266, however, it has not been confirmed if all the records belong to Post Millennial subscribers. HIBP mentions it's possible that a portion of the data dump was taken from third party email marketing service providers.
The attack was first noticed when The Post Millennial and its sister site, Human Events, were taken offline by the hackers. The attackers replaced the homepage with a fake “coming out” letter purportedly from Post Millennial senior editor Andy Ngo, rebranded as “Angelina Ngo” in the letter, and used this as a segue to announce the data leak.
Both sites were briefly taken down, and their Twitter accounts were made private, either as a protective response by the owners or potentially by the hackers themselves. The defaced content and hacker's note were removed within an hour, replaced by a maintenance message.
Soon, it became clear that the incident wasn't limited to just website defacement. The attackers linked to data dumps that were downloaded by an undetermined number of users, who later shared them on hacking forums and torrent sites.
For users affected by this breach, it is crucial to change passwords and monitor accounts for any unusual activity. Unfortunately, the exposed information contains sensitive data that cannot be reset, such as home locations, so the impact of this incident is particularly severe.
Ashley Bryant
I am currently going to court for this breach that has caused identity theft and fraudulent card use under my name. They have used my identity to steal someone else’s information and I am being wrongfully charged with it. My jail bond was 40,000. I am not happy about this. this is serious and I will file a lawsuit or something to get my money back for a crime I didn’t commit.
Betty Beck
I can’t figure out how and why my information was even on filed with this company but yes it showed up on my identity theft report. I’m so tired of this. Every year I seem to be breached by some company.
Roxie.Gimenez
I’ve never heard of this Post Millennial either. Have no idea how these people could be compromise my info?
Connie Geraci
I found out that this Company used all me details in a Data breach. I have proof of it. How do I start a lawsuit against them?
Lucas
I’ve literally never heard of this website, nor did I sign up, and yet my information was part of the breach. I love the fact that my information can be stolen from companies I’ve never heard of, worked with, supported or been within 50 miles of and there’s literally nothing I can do.
Sandi L Teel
I discovered the hack from Post millenia today, 5/16/24. I have never signed up at that website for ANYTHING, or it’s sister company. Nor do I plan to. I’m not impressed with the fact somehow my info was compromised. I hope that website and it’s owners get exactly what they SHOULD have coming to them. I also hope their information was placed on the dark web as well with open gates to their data.
Jonas
Lol no sympathy for these guys.
John
My dude a lot of email addresses that got leaked are from the email list the post millennial bought. A lot of people have never subscribed to that shit and still got their information leaked because of this