惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
爱范儿
爱范儿
GbyAI
GbyAI
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
C
Check Point Blog
H
Help Net Security
P
Proofpoint News Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog RSS Feed
Y
Y Combinator Blog
U
Unit 42
T
Tailwind CSS Blog
MyScale Blog
MyScale Blog
N
Netflix TechBlog - Medium
S
SegmentFault 最新的问题
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

WIRED

‘Avatar: Aang, The Last Airbender’ Leaked Online. Some Fans Say Paramount Deserves the Fallout NASA Wants to Put Nuclear Reactors on the Moon AI Could Democratize One of Tech's Most Valuable Resources Microsoft Surface PCs Are Getting Big Price Hikes, and the Cheaper Models Are Going Away Why Amazon Is Buying Globalstar—and What It Means for Your iPhone The US Government Will Ask Data Centers How Much Power They Use MAGA Is Starting to Look Beyond Trump Allbirds Is Pivoting to AI Compute. Sure, Why Not Best Smart Smoke Detector (and Why You Still Need a Dumb One) 12 Best Standing Desks of 2026, Tested and Reviewed Best Wi-Fi Routers of 2026 for Working, Gaming, and Streaming Best GoPro Camera (2026): Compact, Budget, Accessories The Caves That Could Help Us Find, or Become, Aliens AI Slop Is Making the Internet Fake-Happy The Deepfake Nudes Crisis in Schools Is Much Worse Than You Thought In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market The FCC Has a Fast Lane for Complaints About Trump’s Media Critics Top iRestore Deals for Hair Growth and LED Therapy Devices Meta Is Warned That Facial Recognition Glasses Will Arm Sexual Predators You Should Be More Freaked Out by Shingles BYD’s Fastest-Charging Car in the World Is Astonishing—in Good and Bad Ways The 4 Best Water Filter Pitchers (2026): PFAS, Microplastics The Internet's Most Powerful Archiving Tool Is in Peril The Dumbest Hack of the Year Exposed a Very Real Problem AI Agents Are Coming for Your Dating Life ‘The Audacity’ Is the Broligarchy Takedown You Were Waiting For Why Is It So Hard to Fix an Electric Bike? (2026) Best 2-in-1 Laptops (2026): Microsoft, Lenovo, and the iPad There’s a Secret Ingredient to Making Luxury Ice at Home
Dialog Claims It Was Hacked. A Misconfigured Website Left...
Dell Cameron,Dhruv Mehrotra · 2026-06-24 · via WIRED

Dialog, the invite-only group cofounded by Peter Thiel, notified members and past event participants last week that a database containing their personal information had been breached, supposedly by a criminal hacker. But a WIRED analysis found that the files were readable to anyone who visited a landing page for the group’s app—what cybersecurity experts describe as a misconfiguration that effectively made the data publicly accessible.

The notification to people affected by the data exposure, emailed by Dialog managing director Juliette Levine and provided to WIRED, said that forensic investigators found that the names of 113 past participants in Dialog events had been exposed and, separately, “some” people registered for this summer's Dialog retreat had their information accessed. Levine said the organization had temporarily closed many of its systems in response.

The exposure, Levine alleged, “was a hack executed by a well-known criminal who is wanted in the United States,” adding that the group had acted “out of caution” to protect “the safety, privacy, and reputation of every Dialoger past and present.”

Multiple reviews of the site's publicly accessible architecture, though, point to a misconfiguration, not a break-in.

WIRED first reported on the Dialog records last week. They include the list of 113 names that Dialog confirmed to be past participants in its breach disclosure—among them a sitting NATO commander, two US senators, and the US treasury secretary—as well as a separate, longer list of people registered for an August retreat outside Dublin, Ireland. WIRED also reported on records that revealed how the group privately scores attendees, weighing their wealth and prominence in decisions about admission, seating, and pricing.

A Dialog site, set up to distribute a phone app for the August gathering, let any visitor sign up using any email address. It did not request a password. After submitting an email, the visitor was taken to a near-empty holding page; the same page also loaded the internal files on some 200 people into their browser. Viewing the files required little more than inspecting the page with tools built into every major internet browser.

The records made accessible by this process include senior figures in national security and technology, both current and former. Among those whom records showed as being registered for the upcoming Dialog event were NATO officials; a current White House intelligence official; a retired general who held a senior role in US intelligence; and the heads of national security policy and partnerships at two leading AI firms. Other figures included a former British security minister, a former Japanese defense minister, and a former Pakistani diplomat. For nearly all, the exposed data is comprehensive, from private contact information to active login tokens.

The records also contained participant lists, schedules, and links to completed questionnaires hosted by Fillout, a service Dialog used to collect information from attendees and store it in Airtable databases. Loading one of those forms returned far more information than the Dialog page itself contained, including dates of birth, emergency contacts, cell phone numbers, the political leanings Dialog assigns to its members, internal rankings and grading notes, and the digital keys that serve as members' logins. Much of that information appeared to come directly from Dialog's Airtable records.

Airtable did not respond to requests for comment.

In a statement to WIRED, Fillout says it was “not aware of any compromise of Fillout systems or active platform vulnerability.” The company says customers configure their own forms, connected data sources, and workflows, and that “the behavior of a given form depends on that configuration.” Fillout declined to comment on any specific customer's forms or records.

Dialog, which did not respond to requests for comment, had outside counsel send a letter this weekend demanding WIRED hand over a copy of the data it had received. The letter, signed by partner D. Reed Freeman at the law firm ArentFox Schiff, characterizes the breach as a “cyberattack” by a “known cybercriminal,” argues the files were “stolen,” and says Dialog has also reported the incident to law enforcement. WIRED has not provided Dialog or its attorneys with any data.

The exposure first came to light after maia arson crimew—a Swiss journalist and cybersecurity researcher who was indicted in the US in 2021 on hacking-related charges but has not been convicted of any crimes—received tips from two sources, she says. One had been reviewing US Department of Justice records related to Jeffrey Epstein when they noticed Dialog’s name on an invitation sent to a third party in 2012, which had been forwarded to the infamous sex offender, and grew curious about the secretive group. A second source later pointed crimew to the retreat app.

crimew says she neither exploited a software flaw nor bypassed any security measures to access the Dialog data, and viewed the same records that were available to every visitor’s browser.

Nicholas Weaver, a member of the nonprofit International Computer Science Institute's network security team, says the exposure bears the hallmarks of a web design error rather than a sophisticated intrusion. “This is negligence and a not-actually-unheard-of anti-pattern,” Weaver says, referring to a common but avoidable mistake.

Aaron Mackey, deputy legal director at the Electronic Frontier Foundation, a digital rights nonprofit, says that based on what’s publicly known about outside access to Dialog data, characterizing the activity as “criminal” appears “far-fetched.” He warns that broad computer-crime laws are sometimes invoked to chill security research, journalism, and other First Amendment–protected activity.

Based on the available details, Mackey says, the incident involved Dialog’s website giving data to people who had entered an email address on the site, rather than anyone bypassing a technical control to gain access. “In that circumstance, they've done nothing more than follow a link on a website,” he says.

The Dialog exposure set off a public scramble among prominent attendees to explain their presence on the list. Ezra Klein, the New York Times columnist, wrote on X that he had attended Dialog twice, in 2018 and 2022, but did not see or speak with Peter Thiel and noted that the people named in his statement “do not trust each other and do not have aligned agendas.” Actor Joseph Gordon-Levitt said on Instagram that he had been to two conferences but had never met or spoken with Thiel, whom he described as his political and ideological opposite. Actress Sophia Bush, who has campaigned against deepfake technology, said she had attended to push back on AI hype and was surprised to learn the group was cofounded by someone “you could not pay me to be in a room with.”