A dialog box claiming to have been hacked. A misconfigured website left its members exposed


Dialogue, by invitation only The group he co-founded Peter Thielnotified Members and participants of the previous event Last week, a database containing their personal information was hacked, apparently by a criminal hacker. But a WIRED analysis found that the files were readable to anyone who visited the landing page of the group’s app, which cybersecurity experts described as a misconfiguration that effectively made the data publicly available.

The notification to people affected by the data disclosure, which was emailed by Dialog Managing Director Juliet Levine and provided to WIRED, said forensic investigators found that the names of 113 former participants in Dialog events had been disclosed and, separately, that the information of “certain” people registered for this summer’s Dialog retreat had been accessed. The organization temporarily shut down many of its systems in response, Levin said.

Levin claimed that this exposure “was a hack carried out by a known and wanted criminal in the United States,” adding that the group acted “out of an abundance of caution” to protect “the safety, privacy, and reputation of every Dialoger past and present.”

However, multiple reviews of the publicly accessible site structure generally indicate a configuration error, not an intrusion.

Wired It was first reported in dialogue records Last week. It includes a list of 113 names that Dialog confirmed were former participants in disclosing the hack — including a current NATO commander, two U.S. senators, and the U.S. Treasury secretary — as well as a separate, longer list of people registered at a resort in August outside Dublin, Ireland. WIRED also reported on records that revealed how the group operated Attendance is recorded privatelyweighing their wealth and prominence in decisions related to admission, seating, and pricing.

The dialogue website, which was set up to distribute a mobile app for the August gathering, allows any visitor to register using any email address. It did not ask for a password. After sending the email, the visitor is taken to a nearly empty waiting page; The same page also loaded the internal files of about 200 people into their browser. Viewing files requires little more than scanning the page using the tools built into every major Internet browser.

Records accessed through this process include prominent national security and technology figures, both current and former. Those who records show are registered for the upcoming dialogue event include NATO officials; Current White House intelligence official; A retired general who held a senior position in US intelligence; and heads of national security policy and partnerships at two leading AI companies. Other figures include a former British security minister, a former Japanese defense minister, and a former Pakistani diplomat. For almost everyone, the data exposed is extensive, from private contact information to active login codes.

Records also contain participant lists, schedules, and links to completed surveys hosted by the Fill Service, a conversational service used to collect information from attendees and store it in Airtable databases. Loading one of these forms returned much more information than the dialog page itself contained, including dates of birth, emergency contacts, cell phone numbers, the political leanings that the dialog assigns to its members, internal ratings and rating notes, and numeric keys that serve as member logins. Much of this information appears to come directly from Dialog’s Airtable logs.

Airtable did not respond to requests for comment.

In a statement to WIRED, fillout said it is “not aware of any hack into fillout’s systems or active vulnerability in the platform.” The company says that customers configure their own forms, connected data sources, and workflows, and that “the behavior of a particular form depends on this configuration.” fillout declined to comment on any specific client’s forms or records.

Leave a Reply

Your email address will not be published. Required fields are marked *