Security

Cyber-crime

Andrew Tate's site ransacked, subscriber data stolen

He'll just have to take this one on the chin


The website of self-proclaimed misogynist and alleged sex trafficker and rapist Andrew Tate has been compromised and data on its paying subscribers stolen.

His now-ransacked Real World site is where the antagonistic online influencer preaches eyebrow-raising life advice primarily to young disillusioned men.

The British-American ex-kickboxer charges subscribers $50 a month with a promise to help make them wealthier, fitter, and more masculine. The site is said to have more than 113,000 active users, and the guy himself has accumulated millions of followers on various social networks, some of which he has been banned and unbanned from.

Intruders said they copied the contents of Real World's 221 public and 395 private chat servers, as well as 794,000 of its usernames for current and former members plus a list of 324,382 registered email addresses. This info has apparently been sent to the security breach notification service at Have I Been Pwned and the leak site DDoSecrets.

The self-styled hacktivists also spammed Real World's chat rooms with LGBTQ+ related emojis – owing to Tate's views on gender and sexuality – and told the Daily Dot his site was "hilariously insecure." An unpatched flaw allowed them “to upload emojis, delete attachments, crash everyone’s clients, and temporarily ban people.”

The cyberattack unfolded while Tate was livestreaming from his home in Romania, where he remains under house arrest. The 37-year-old is facing trial on charges of rape, human trafficking, and forming an organised crime ring to sexually exploit women. He denies any wrongdoing. An appeals court this week ruled some evidence was inadmissible, giving prosecutors days to respond.

During the data heist on Thursday, the intruders also flooded the main message board with pro-trans imagery and AI-generated pictures of Tate draped in a rainbow flag.

This comes after Real World was found to have left an 88GB MongoDB database instance unprotected online containing records on 968,447 user accounts, thus exposing user IDs, email addresses, encrypted passwords, verification statuses, account recovery codes, password expiration dates, and reset tokens.

Real World had no response at the time of publication. ®

Send us news
106 Comments

GoDaddy slapped with wet lettuce for years of lax security and 'several major breaches'

Watchdog alleged it had no SIEM or MFA, orders rapid adoption of basic infosec tools

Biden signs sweeping cybersecurity order, just in time for Trump to gut it

Ransomware, AI, secure software, digital IDs – there's something for everyone in the presidential directive

Microsoft eggheads say AI can never be made secure – after testing Redmond's own products

If you want a picture of the future, imagine your infosec team stamping on software forever

Look for the label: White House rolls out 'Cyber Trust Mark' for smart devices

Beware the IoT that doesn’t get a security tag

CISA: Wow, that election had a lot of foreign trolling. Trump's Homeland Sec pick: And that's none of your concern

Cyber agency too 'far off mission,' says incoming boss Kristi Noem

After China's Salt Typhoon, the reconstruction starts now

If 40 years of faulty building gets blown down, don’t rebuild with the rubble

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

'Codefinger' crims on the hunt for compromised keys

Database tables of student, teacher info stolen from PowerSchool in cyberattack

Class act: Cloud biz only serves 60M-plus folks globally, no biggie

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

3 CVEs added to CISA's catalog

Raspberry Pi hands out prizes to all in the RP2350 Hacking Challenge

Power-induced glitches, lasers, and electromagnetic fields are all tools of the trade

FCC to telcos: By law you must secure your networks from foreign spies. Get on it

Plus: Uncle Sam is cross with this one Chinese biz over Salt Typhoon mega-snooping