Reborn LulzSec claims hack of dating site for military personnel

An announcement posted by hackers on Pastebin links to what it says are details of 163,792 MilitarySingles.com users

A group of hackers claiming to be the reborn Lulz Security (LulzSec) took credit for an alleged compromise of MilitarySingles.com, a dating website for military personnel, and the leak of over 160,000 account details from its database.

The group announced the MilitarySingles.com hack on Twitter and Pastebin on Sunday, using the name "LulzSec Reborn" and ASCII art previously associated with LulzSec, the hacker group that apparently disbanded and merged with the Anonymous hacktivist collective last year.

The Pastebin post included links to RAR archives hosted on public file sharing websites that allegedly contain the names, usernames, e-mail addresses, IP addresses, and passwords of 163,792 MilitarySingles.com users. "There are emails such as @us.army.mil ; @carney.navy.mil ; @greatlakes.cnet.navy.mil ; @microsoft.com ; etc.," the group wrote.

Someone claiming to be the administrator of MilitarySingles.com posted a comment on databreaches.net after the site reported on the breach, saying that there is no evidence of a compromise.

The comment also suggested that ESingles, the company which runs the dating website, is nevertheless investigating the claims and taking the necessary security precautions.

The message annoyed members of "LulzSec Reborn" who, in response, called the administrator "stupid" and uploaded a "hacked by" page to the website in order to prove that they have access to it.

ESingles didn't immediately return a request for comment.

The directory in which the rogue page was uploaded is unprotected and appears to contain internal files associated with the site's content management software. If the credentials used for the database connection are available in one of those files, it would make stealing the user information fairly easy.

The original LulzSec hacker group took credit for many high-profile attacks during the spring of 2011. The FBI and other law enforcement agencies worldwide have since arrested several individuals believed to have been associated with the group. At the beginning of March it was revealed in official court records that LulzSec's alleged leader, a hacker known online as Sabu, has been working as a cooperating witness with the FBI since August 2011.

The rebirth of LulzSec seems to be the hacktivist community's response to Sabu's perceived betrayal of their cause and the arrests that resulted from his cooperation with the authorities. The LulzSec Reborn Twitter account was created on March 9 and was accompanied by videos posted on YouTube announcing the group's return on the hacking scene.

This isn't the only hack that Lulsec Reborn has claimed: On Monday, the group said it had compromised csscorp.com, the website of a San Jose-based information and communication technology company called CSS Corp.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Webroot Web Security

Proactive web security that blocks threats in the cloud before they reach users’ machines, or enter customers’ networks.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.