Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationunderground-data-leakmass-credential-exposurebreach-disclosure-notification

Anonymous Leak of Epik Data Exposed Far-Right Sites and Federal Records

Updated 29d agoFirst seen May 25, 20268 sources

Hacktivists claiming to be Anonymous said they breached web host and domain registrar Epik, a provider used by sites including Gab, Parler, QAlerts, and other far-right platforms, and released what they described as roughly a decade of internal and customer data. Reports said the dump included domain registration and transfer records, account credentials, emails, payment history, employee mailbox contents, and more than 500,000 private keys, affecting data tied to more than 15 million people and websites. Epik CEO Rob Monster initially downplayed the incident, then later acknowledged in a public video session that company backup data appeared to have been compromised and said information from the breach was allegedly used in an attempt to target his Coinbase account.

Subsequent reporting said the leaked records exposed internal support tickets, subpoenas, and preservation requests for customer information, including requests that appeared linked to investigations after the Jan. 6 Capitol riot and at least one FBI request tied to a domain allegedly connected to malware used in the SolarWinds intrusion. The data also reportedly helped trace efforts by figures such as Ali Alexander to obscure domain ownership and digital infrastructure, while additional releases expanded scrutiny of how hosting and registrar services supported extremist networks online. The breach became one of the most consequential hacktivist leaks involving internet infrastructure providers because it revealed both customer identities and sensitive law-enforcement-related records.

Share:
Anonymous Leak of Epik Data Exposed Far-Right Sites and Federal Records
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Oct 7, 20215y ago

Epik hack cited as part of wider hacktivist disclosures affecting tech firms

By October 7, coverage of the Epik breach placed it alongside other major hack-and-leak incidents, including Twitch, as examples of hacktivists exposing internal corporate data and infrastructure. This reflected the broader significance of the Epik disclosures beyond the initial victim alone.

Sep 30, 20215y ago

A second tranche of stolen Epik data is reportedly leaked

On September 30, reporting indicated that another batch of stolen Epik data had been released, extending the fallout from the original breach. The new dump suggested the attackers continued publishing material beyond the initial archive.

Sep 24, 20215y ago

Leaked Epik tickets reveal subpoenas and preservation requests

Internal ticketing records from the breach exposed subpoenas, grand jury requests, and 90-day preservation demands for customer information, including requests apparently tied to investigations after the January 6 Capitol riot. The leaked records also showed an FBI preservation request and subpoena in late 2020 for an Epik-hosted domain allegedly linked to malware used in the SolarWinds attack.

Sep 21, 20215y ago

Broader coverage says Epik breach exposed data on millions of people and sites

By September 21, mainstream reporting described the Epik hack as exposing information tied to more than 15 million people and websites. Coverage also highlighted Epik's role as a service provider for far-right and extremist-linked platforms, increasing the public impact of the breach.

Sep 20, 20215y ago

Reporting links leaked Epik data to Jan. 6-related digital traces

Analysis of the leaked Epik records showed how figures such as Ali Alexander appeared to have tried to obscure their online footprint after the January 6 Capitol riot. The reporting used the breach data to connect domains and infrastructure to post-riot activity.

Sep 17, 20215y ago

Epik CEO publicly acknowledges the breach in a live video Q&A

During a chaotic public video session, Rob Monster acknowledged that Epik had been breached after earlier denials and described it as involving a compromised company backup. He also said a hacker nearly stole about $100,000 from his Coinbase account using information exposed in the incident.

Researcher warned Epik of critical account-takeover flaw before breach

Weeks before the hack became public, a security researcher reported a critical flaw in Epik's website that exposed customer account data and could allow account takeover. The report said Epik did not promptly fix the issue before the later breach disclosures.

Web host Epik was warned of a critical security flaw weeks before it was hacked | TechCrunch
Sep 14, 20215y ago

Epik CEO initially dismisses the reported incident

After the breach claim surfaced, Epik CEO Rob Monster publicly downplayed it on Twitter, calling the matter insignificant and questioning the authenticity of the leaked material. This marked the company's first public response to the incident.

Anonymous claims breach of Epik and begins releasing stolen data

Anonymous said it hacked web host and domain registrar Epik and obtained roughly a decade of internal and customer data, including domain records, credentials, payment history, employee mailboxes, and hundreds of thousands of private keys. Early reporting on the leak appeared on September 14, 2021, as the group said it was working to make the archive more accessible.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.