Nowadays, many people read comics on their mobile phones and tablets. There are various online comics applications, and “Mangatoon” is an application that is very famous around the world. But things have not been quiet on “Mangatoon” recently. 23 million user information was stolen by hackers and then leaked after being resold. However, it is said to be one of the largest leaks in recent times.

The data of the well-known online comic reading application “Mangatoon” was leaked, and the data of 23 million users was leaked
Mangatoon, a very popular comic reading platform on both Android and iOS platforms, recently suffered a data breach. Hackers stole 23 million user information from its database on the Elasticsearch server and directly leaked it. Mangatoon users can now HIBP Search by email address to see if their account is on the compromised list.

Recently, HIBP (Have I Been Pwned) added 23 million leaked materials from Mangatoon to its platform. Troy Hunt, the creator of the HIBP service, wrote on his Twitter account that the data stolen from Mangatoon in May included the user’s name, email address, gender, social media account identity, social login identity token and MD5 password hash. The massive breach was added to the HIBP website after Troy Hunt unsuccessfully contacted Mangatoon about the data breach.
Lot’s of chirping crickets at @MangatoonEN, both on Twitter and via email. Any other ideas? At least one other person has been trying to reach them for much longer than me too.
— Troy Hunt (@troyhunt) July 6, 2022
The entire breach was carried out by a well-known hacker named “pompompurin”, and was successful because the security of the Elasticsearch server used by Mangatoon to store the database was too weak. pompompurin to foreign media BleepingComputer He said that after he sent a letter to Elasticsearch, they only changed the credentials but did not receive any reply or even notify their customers. Pompompurin also shared samples of the stolen data with BleepingComputer, which were confirmed to be valid accounts on the Mangatoon platform. When asked if they would publish or sell the database publicly, they said it might be leaked at some point.

Pompompurin has also been involved in other high-profile hacking incidents, including sending fake cyberattack emails through the FBI’s Law Enforcement Enterprise Portal (LEEP) and stealing customer data from Robinhood. After the RaidForums hacking forum was shut down by law enforcement, pompompurin launched a similar forum called Obsible.
Source: KOCPC Chinese