ADVERTISEMENT

LADbible Group leaks internal data

LADBible group, a popular viral media publisher, has leaked employee email addresses, links to its social media, a list of advertisers, and data on articles, among other information of high value to attackers.

LADbible data leak

By Cybernews

Jurgita Lapienytė
Jurgita Lapienytė Chief Editor
September 6, 2023 Updated: November 15, 2023 4 min read

LADbible data leak

  • Leaked employee emails, including 280 that belonged to employees of all their brands: LADbible, GAMINGbible, SPORTbible, UNILADadventure, UNILADtech, UNILAD, ODDSbible, UNILADsound, and Tyla.
  • Links to employee social media profiles.
  • Current employee access roles – making those with more permissions within the company much more lucrative targets.
  • Employee device IDs.
  • Access to TheLADbible Group’s EMS (Microsoft Enterprise Mobility + Security) system login panel. The EMS system is most often used to control all employee devices, servers, provide threat protection, and remote administration tools even though we can’t discern how LADbible used it.
LADbible data leak proof
ADVERTISEMENT

The aftermath

  • Attackers could gain control of all devices within the organization, including encryption and decryption of device data storage.
  • Attackers could install additional software on devices, add and remove users.
  • Attackers could change passwords and security policies.
  • Attackers could mark a malicious code as bening to bypass threat protection systems.

Mitigation in a nutshell

  • The EMS authentication panel is used to verify access to a resource on the Azure Active Directory (ADD) domain, or to the whole network managed by ADD.
  • The login panel being publicly accessible allows for remote attackers to attempt to authenticate to the Active Directory resource or network.
  • 2FA is enabled by default on ADD, meaning it would be more difficult for attackers to breach systems.
  • TheLADbible Group should ensure that Active Directory resources are only accessible from a trusted network., and that such panels cannot be accessed from any internet connected device.
  • In the context of the EMS system, email addresses serve as partial credentials for logging into the system, as well as contact addresses for communications regarding password resets or any other communications in relation to the EMS system.
  • Social media handles most likely do not serve a significant purpose. User roles describe the level of access a user has, as well as what rules may be applied to their device as well as their account.
  • Device IDs help identify and direct requests to and from that employee’s work device.
  • Leaked email addresses can be used for phishing those employees with the most access, as this is also described in the user roles. Since the authentication system is configured securely (employees are asked to use 2FA when signing in), attackers may attempt to send cookie-stealing malware, among other things.
  • The EMS login page should be made only accessible from trusted networks, and system administrators should ensure that employees change their passwords (in case some of them use previously leaked passwords as their EMS password). They should also check that MFA is enabled and required for all employees, ensure that their authentication configuration is “hardened,” authentication cookies expire in a reasonable period of time, and that their EDR and XDR services are working correctly with “hardened” configurations.
ADVERTISEMENT