The Walt Disney Company is facing a potential cyber-attack allegedly committed by NullBulge, which may have breached sensitive company data.
The hacktivist group claimed to carry out the incident on 12 July, announcing the act on X as well as on Breach Forums.
NullBuldge claimed to have breached Disney’s internal communications via its Slack, leading it to 1.2 terabytes of data which it then leaked online.
Allegedly, the breached data included confidential information including messages, code, and files from around 10,000 different Slack channels on the company’s workspace.
#DisneySlackLeak#Disney has had their entire dev slack dumped. 1.1TiB of files and chat messages. Anything we could get our hands on, we downloaded and packaged up. Want to see what goes on behind the doors? go grab it.https://t.co/saVx4lxgsy pic.twitter.com/FitM8hmOEE
— NullBulge (@NullBulgeGroup) July 12, 2024
According to Stack Diary, which viewed some parts of the leaked data, the breach shows a variety of Disney’s operations, including emails, financial data, project information, and even sensitive information like developer data and internal network structures.
Employee information – including names, emails, and addresses – may have also been contained in the leak, as well as budgeting information for the Disney company.
NullBulge describes itself as a hacktivist group, and claims its motive behind the alleged attack was to expose corporate malpractice. The group is particularly concerned with artist compensation, and has instigated itself in ongoing arguments around Disney’s treatment of artists and creators.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Disney has yet to comment on the alleged breach, which could potentially interrupt some of its services and projects.
The attack follows two high profile breaches on US companies, including on telecommunications company AT&T and ticket seller Ticketmaster. The AT&T breach, which took place last week, affected the call records and texts of nearly all of its customers, totally around 110 million people. The Ticketmaster data breach is currently ongoing, and involves concert ticket barcodes.





