Guys, I have a research request. Does anyone here have the original link, or at least an archive.* link, for the following tweet by Keffals?
View attachment 3698730
Keffals tweeted this and then deleted it straight after to cover up the fact that he was openly urging his fellow cyber criminals to leak all of the doxx they stole from KF during the hack:
If you have the original link to this deleted tweet please please share it here or DM it to me.
I still see people asking about any leaks of KF user data, so I'll address that question here.
The only two alleged leaks of KF user data that I've personally encountered on Twatter were the following two:
1) this pastebin file of a small number of KF users:
https://archive.ph/XBEDH
2) this tweet from someone claiming to have access to the stolen user data and to have identified a number of Danish KF users amongst that data set:
Since he's redacted the screengrab in the above tweet, it's hard to determine if this person is telling the truth about 1) having access to the full stolen dataset and 2) having identified Danish KF users in that supposed data set.
Does this mean the hackers didn't manage to export the user data they tried to steal and transfer to poz.hiv (and onward to poz.com)?
Does this mean the hackers weren't already snooping on KF throughout August, using the alleged backdoor they claim to have? (Has there been a post about this claim? If so, please link me to it.)
I am going to err on the side of caution and assume, on the basis of the above, that the hackers did steal (some) KF user data. Speculating on the reason they haven't posted it yet, I would suspect it's because they're trying to make the user data they stole readable and researchable. The next step is for them to format all the user data they stole so as to upload it online and to make it available via an easily searchable database. Again, this is pure speculation on my part based on what I've read about happening during other hacks where hackers stole user data.
Another likely use for the KF user data the hackers stole is to use it for blackmail, basically threatening to release the user data if Joshua Moon refuses to keep KF down. In this version, we the KF users are effectively being held as "digital hostages" to force Joshua Moon into keeping his site down. The hackers don't have to make such threats explicitly. The threat is implied in the above tweet by Keffals, which he deletes to cover up. That tweet was Keffals giving his cyber criminals his blessings to use the stolen user data to blackmail and engage in digital hostage-taking. Again, pure speculation on my part, based on how other hackers employed the user data they stole as a bargaining chip against their victims.
I personally suspect that first they will do the "digital hostage taking" where they implicitly threaten to release everything if Joshua Moon doesn't keep KF down, and then they will proceed to leak it but not as a huge data dump (like the 2019 one that just got removed from Archive.org) but as a neat, searchable database to make the blatant privacy violation seem respectable and less likely to be removed outright. It's still 100% stolen data and completely undeniably criminal. Recall, the hackers not only claim to have stolen user data but also our DMs, our private messages amongst KF users, which they are threatening to make public too.