Site navigation

Secret-Sharing App Whisper Exposes Nearly a Billion Users

Dominique Adams

,

secret

Fetishes, intimate confessions, locations, nicknames, sexual orientation and workplaces are among the details exposed by the breach.

Free secret-sharing app Whisper has suffered a massive data breach exposing the confessions, often of an intimate nature, of almost 900 million of its users.

Confessions are often highly compromising and can be related to sensitive issues such as cheating, unwanted pregnancies, abortions, domestic abuse and sexuality.

One confession linked to an exposed account stated: “My son was conceived at a time when I cheated on his father.”

Whisper, which proclaimed it was “the safest place on the internet” stored its users’ intimate information online in a non-password-protected database accessible to the public.

Users’ confessions, fetishes, ages, ethnicity, genders, and location data were exposed online. The breach, first reported by the Washington Post (WP), also included 1.3 million records involving users who had listed their age as young as 15.

Geolocation information attached to many users’ last submitted post pointed back to specific schools, residential neighbourhoods, workplaces, and international military bases, including a secure US military missile facility.

Although real names were not revealed, the information that was exposed could have lead to an individual being identified or even blackmailed.

Independent cybersecurity consultants Matthew Porter and Dan Ehrlich, who are responsible for discovering and disclosing the oversight to the WP, described the breach as a data blackmailer’s dream.

Recommended 

Porter and Ehrlich’s discovery has debunked Whisper’s claims that its app is totally anonymous. Ehrlich said Whisper’s failure to secure users’ records was “grossly negligent.”

The pair say they were able to access nearly 900m users’ records dating from the app’s launch eight years ago right up to the present day. They were also able to access any user’s account and view which messages they had responded to and the time of their last login.

As part of the investigation into the breach, Porter and Ehrlich learned that the app rates its users on the likelihood that they are a sexual predator. Roughly 9,000 of Whisper users had a 100% “predator probability” score.

Whisper’s operators and federal law enforcement have been notified of the breach and access to the data has now been removed. In a statement released on Tuesday, the Whisper team said the database Porter and Ehrlich stumbled upon was “not designed to be queried directly.”

It is unclear how long the database was online and if it had been accessed. First launched in 2012, the app claims it does not follow or track its users, however it was found in 2014 to collect location data.

Dominique Profile Picture

Dominique Adams

Marketing Content Manager, Trickle

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data