Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptionunderground-data-leakbreach-disclosure-notificationend-of-life-software

4chan Hack Exposed Internal Systems and Staff Data

Updated 26d agoFirst seen May 25, 20264 sources

4chan was knocked largely offline after an alleged breach exposed internal systems, moderation tools, source code, and staff information, with users from rival forum Soyjak Party claiming responsibility. Reports said the attackers published screenshots of administrative panels, ban templates, and internal discussions, while the site returned Cloudflare timeout errors and was at times only intermittently reachable in text-only mode. The outage began late on April 14, and moderators were reportedly forced to take servers offline to regain control.

Multiple reports said the intrusion may have persisted for more than a year before the attackers reopened and defaced the previously banned /qa/ board and released data tied to administrators, moderators, and janitors. Some reporting said affected moderators confirmed at least parts of the leaked material were authentic, and that data belonging to paid 4chan Pass subscribers may also have been accessed. Researchers and journalists also pointed to the possibility that 4chan was running an outdated 2016 version of PHP, which may have contributed to the compromise, while broader claims that the leak proved government involvement were not substantiated.

Share:
4chan Hack Exposed Internal Systems and Staff Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 15, 20251y ago

Reports suggest outdated PHP version may have contributed

Coverage of the breach said 4chan may have been exposed in part because it was running an outdated 2016 version of PHP. This technical detail emerged as journalists and researchers examined the incident.

Moderators reportedly confirm authenticity of some leaked data

By April 15, 2025, reporting cited some affected moderators who said leaked data from the breach appeared authentic. Reports also said the attackers accessed personal data tied to paid 4chan Pass subscribers.

Apr 14, 20251y ago

Moderators take servers offline to regain control

Following the breach, 4chan moderators were reported to have taken servers offline as part of efforts to contain the incident and recover control of the platform. The site later appeared only intermittently, including in limited text-only mode.

Attackers allegedly deface /qa/ and leak internal 4chan data

During the incident, the attackers allegedly reopened and defaced the previously banned /qa/ board and published screenshots and leaked materials from 4chan's internal systems. The exposed data reportedly included moderator tools, administrative panels, source code, and contact details for staff and janitors.

Attack on 4chan begins and site goes offline

On April 14, 2025, 4chan reportedly suffered a hack that led to a major outage beginning Monday evening or late Monday night. The site became largely inaccessible, with users seeing downtime and Cloudflare timeout errors.

Apr 14, 20242y ago

4chan hack reportedly carried out after long-term access

Reporting on the April 2025 incident says the attacker may have maintained access to 4chan's systems for more than a year before launching the operation. Rival forum users later claimed responsibility for the breach.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
1 linked
Affected products
4 linked
CloudflarePhpmyadminPhpDiscord
Organizations
11 linked
4chanBleepingComputerTechCrunchCloudflareDiscordRedditDowndetectorGizmodoThe Daily DotSoyjack PartyHyperfixed
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.