Dialog Misconfigured Website Exposed Members in Hack

▼ Summary
– Dialog’s database was breached, but a WIRED analysis found the data was publicly accessible due to a misconfiguration, not a criminal hack.
– The exposed data includes names of 113 past event participants, including a NATO commander, US senators, and the treasury secretary.
– A Dialog app landing page allowed anyone to sign up without a password, making internal files on 200 people viewable through standard browser tools.
– Exposed records contained comprehensive personal information, including private contact details, login tokens, and internal rankings of attendee wealth and prominence.
– Dialog claimed the breach was a criminal hack, but multiple reviews of the site’s architecture attribute the exposure to a misconfiguration.
The invite-only community Dialog, cofounded by billionaire investor Peter Thiel, recently alerted its members and past event attendees that a database containing personal data had been compromised, allegedly by a criminal hacker. However, a review by WIRED reveals that the files were actually accessible to anyone who visited a specific landing page for the group’s app,a scenario cybersecurity experts describe as a misconfiguration that essentially left the data publicly exposed.
In a notification sent to affected individuals and shared with WIRED, Dialog managing director Juliette Levine stated that forensic investigators determined the names of 113 former participants in Dialog events had been exposed. Additionally, some individuals registered for this summer’s Dialog retreat had their information accessed. Levine noted that the organization had shut down many of its systems as a precautionary measure.
Levine characterized the incident as “a hack executed by a well-known criminal who is wanted in the United States,” emphasizing that the group acted “out of caution” to safeguard “the safety, privacy, and reputation of every Dialoger past and present.”
Yet multiple examinations of the site’s publicly accessible structure point to a configuration error, not a break-in.
WIRED initially reported on the Dialog records last week. They include the list of 113 names that Dialog confirmed as past participants in its breach disclosure,among them a sitting NATO commander, two US senators, and the US treasury secretary. A separate, longer list contains people registered for an August retreat outside Dublin, Ireland. WIRED also uncovered records showing how the group privately scores attendees, weighing their wealth and prominence in decisions about admission, seating, and pricing.
A Dialog site, created to distribute a phone app for the August gathering, allowed any visitor to sign up using any email address. No password was required. After submitting an email, the visitor was taken to a near-empty holding page. The same page also loaded internal files on roughly 200 people into their browser. Viewing the files required little more than inspecting the page with tools built into every major internet browser.
The records made accessible through this process include senior figures in national security and technology, both current and former. Among those shown as registered for the upcoming Dialog event are NATO officials; a current White House intelligence official; a retired general who held a senior role in US intelligence; and the heads of national security policy and partnerships at two leading AI firms. Other figures include a former British security minister, a former Japanese defense minister, and a former Pakistani diplomat. For nearly all, the exposed data is comprehensive, from private contact information to active login tokens.
The records also contained participant lists, schedules, and links to completed questionnaires hosted by Fillout, a service Dialog used to collect information from attendees and store it in Airtable databases. Loading one of those forms returned far more information than the Dialog page itself contained, including dates of birth, emergency contacts, cell phone numbers, the political leanings Dialog assigns to its members, internal rankings and grading notes, and the digital keys that serve as members’ logins. Much of that information appeared to come directly from Dialog’s Airtable records.
Airtable did not respond to requests for comment.
Got a Tip? If you have information about Dialog you’d like to share, we’d like to hear from you. Using a nonwork phone or computer, contact the reporters securely on Signal at dell.3030 and dmehro.89.
In a statement to WIRED, Fillout says it was “not aware of any compromise of Fillout systems or active platform vulnerability.” The company explains that customers configure their own forms, connected data sources, and workflows, and that “the behavior of a given form depends on that configuration.” Fillout declined to comment on any specific customer’s forms or records.
(Source: Wired)




