back
232 comments
Again highlighting the unrecognized liability companies are taking on by logging every scrap of internal communication, no matter how informal or ill-conceived it may be.
It may be a requirement or law depending on where the company does business.

For example, the financial companies I used to work for had a “standard practice” of archiving all e-mails and internal chats for 7-8 years. Not sure if phone calls on company equipment were recorded or retained though (may be a YMMV case).

This is why I separate work and personal assets. I never do work on personal devices nor do I use work devices for personal activities (ie, social media, e-commerce, shit posting). Also if I’m shit talking the boss’s boss. It’s never using work devices.

Have been asked a few times to use personal devices for work but absolutely refused. I would be asked to install their invasive spyware and root kits so they can abide by their draconian corporate policies. So far, they haven’t forced me otherwise I would have quit those companies long ago.

Setting (formally or informally) corporate policies which destroy or even prevent the creation of a record of internal communications, regardless of how formal those communications may be - is very well illegal depending on a variety of factors.

The shining poster boy for this would be Google, who told staff to disable logging when discussing sensitive topics:

https://www.techspot.com/news/102874-doj-alleges-google-dest...

They also told employees to never use certain keywords, so that records of conversations would not be found by legal teams using search tools, but also they wouldn't be shown talking like monopolists:

https://arstechnica.com/tech-policy/2023/09/google-hid-evide...

In a very large company like Disney there are often legal data retention requirements from ongoing litigation, which means Corporate Slack might be more complicated than the AT&T customer data breach.
Interestingly Disney has done this since inception which is why the (IMO, excellent) biography Walt Disney: The Triumph of the American Imagination can be so detailed.
> the unrecognized liability companies are taking on by logging every scrap of internal communication

Do any large companies not delete everything at the first opportunity?

I wonder why there are so few articles considering this happened last night. Also, it's sad how the "insider" (who probably was hacked/RATed) had his SSN and other info leaked :/
After the bell on Friday is an infamous time for releasing news you don’t want to be covered.
This is going to be a anti-DEI treasure trove. The unsaid things will be shown to have very much been said.
Will it?
Considering the social and political controversies that Disney is unvolved in, I would expect a lot of scrutiny of the contents of this link.
This is the same group that put malware in ComfyUI_LLMVISION and said they were against crypto but then extorted people for crypto.

(ComfyUI_LLMVISION is probably what caused this breach)

Anecdotally it feels like there has been an uptick in these high-profile hacks recently, maybe a result of more security people being laid off as a result of companies thinking they would replace everyone with AI?
Probably not - The reason we continue to see attacks is for a couple of reasons:

1) There are very few consequences. At worst, a hacker will get 5-7 years, and the chance of getting caught is low.

2) Security is very very very hard. The defender must get everything right. The attacker only needs to find one flaw.

3) Security does not just depend on security staff. It depends on every software engineer, operations (or devops) engineer, every software dependency, every piece of hardware, etc. If one of these people or dependencies has a problem, the whole system can be cracked. Examples of problems include writing insecure code, getting hacked, not removing old employees from an ACL or group, installing a tool with a back door, etc.

The point is security is hard and it depends on people doing the right thing. It's very hard to get people to do the right thing.

If AI is a factor at all, then more likely on the hackers’ side.
More security people laid off but also layouts in general put strain on the remaining workers who are supposed to do more work to make up the difference hence more likely to cut corners to deliver products
Perhaps even hybrid warfare
Seems like slack has a problem

Maybe a dumping tool that uses a stolen api key? Rate limiting and monitoring on slack’s part could help…

Whether you’re talking about enterprise file storage, email, or chat messaging software, they all have APIs and/or admin user interface to allow retrieving any and all data to support eDiscovery.
Hardly slacks fault. With so many clients and so much money behind that, theres such a big target on their back that shoring up defenses is fundamentally impossible. It’s probably best to just consider such services from such large providers as already compromised, and keep sensitive data off them entirely.
All their APIs are rate limited. Disney would have a Grid and with Grids you get data dumps. The feature is normally used for litigation and you need pretty high admin access to get a dump. They either found an exploit or they compromised an Admins account.
I don't understand the situation with the insider (Matthew J Van Andel). Is the implication that he was originally collaborating with the hackers to give them access, then regretted doing so and decided to cut off their access, and the hackers retaliated by doxxing him?
this video alleges that it might've been because he downloaded an infected mod for a game: https://youtu.be/ZGScvWIyw2E

Not sure why they would dox him, maybe to throw him under the bus after he found out he got pwned and cut them off?

They should learn opsec from the Disney Vault.
As someone who literally used to own the digital version of the Disney vault I find this leak highly unlikely what it is claimed to be.

Disney doesn’t just use one Slack instance across the whole company and everyone knows to not put pre-release content on my public platforms.

Maybe they compromised an instance owned by DTSS (Disneys centralized IT entity), but this would have little to do with Disney Studios like they imply.

Its pretty standard in the industry to only store pre-release content on airgapped systems.

No, they should learn opsec from whoever runs our elections--the most secure elections in the world.
Disney seems to be just shooting themselves in the foot over and over again recently.

It will be interesting to see what happens here. Information that leaks could actually impact share price.

Is it even legal to view that data ?
Why would it not be? What data is it illegal to view? Other than perhaps CSAM, which I would strongly hope Disney don't host on their Slack.
Train an LLM on it...
Thats for Ruining MCU!
Dark side of API-based access to everything on SaaS where companies have no control.

I can’t guard the front door effectively.

Nor, I can easily guard the back doors.

Will data breaches like these: AT&T, Ticketmaster, and now Disney—-a nail in Security coffins for SaaS?

lol. no. besides which all of these hacks would have been prevented by simple, well established controls (eg. MFA everywhere, not hoarding every scrap of customer data and internal comms).

so all of those basics are going to magically happen when you move your data on-prem?

I’d like to know if that’s really how Kathleen Kennedy eats her Linguini.
Could you please explain this reference? I know who she is but I don’t get it.
The spin from Disney is going to be entertaining.
It's clear that 1Tb is a lot of data, but I would have expected more from Disney's slack?
Any news on the contents in terms of unreleased films?
where can i actually read it
> leaked 1.1 TiB (1.2 TB)

I don't know why but I find this funny.

Can someone explain why hackers dump the files publicly rather than just tell the victim they got access? What's the point?
I can’t stop giggling at this group’s name.