{"id":20797,"date":"2023-08-17T18:34:40","date_gmt":"2023-08-17T09:34:40","guid":{"rendered":"https:\/\/automaton-media.com\/en\/?p=20797"},"modified":"2023-08-17T18:34:40","modified_gmt":"2023-08-17T09:34:40","slug":"20230817-20797","status":"publish","type":"post","link":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/","title":{"rendered":"Users of popular Japanese BL social network have their information stolen and ransomed after security breach"},"content":{"rendered":"\n<p>PictBLand, a popular Japanese boys&#8217; love social media platform, has recently experienced a significant data breach, resulting in hackers gaining unauthorized access to user information. The site&#8217;s lack of security leaves many users concerned of what will become of their personal data.<\/p>\n\n\n\n<p>Beginning on August 15th (JST), PictBLand users began to experience pop-up ads praising Kim Jong-un, malicious redirects and other intrusive content. Subsequently, sister sites pictMalFem (similar to PictBLand but for heterosexual content) and pictGLand (girls\u2019 love focused) have also been affected. PictBLand\u2019s official X account has also stated that PictSQUARE, an exhibition and sale service affiliated with the previously mentioned sites, has had users\u2019 shipping addresses leaked. PictBLand claims that no credit card information was stored on their sites\u2019 servers, however. In response to the attack, the sites\u2019 administration has decided to temporarily shut down their servers to investigate further.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"ja\" dir=\"ltr\">\u30d4\u30af\u30d6\u30e9\u306a\u3093\u304b\u4e57\u3063\u53d6\u3089\u308c\u3066\u306a\u3044\uff1f\uff1f\uff1f\uff1f\u8b0e\u306e\u30dd\u30c3\u30d7\u30a2\u30c3\u30d7\u51fa\u3066\u308b\u3057\u5185\u5bb9\u304c\u306a\u3093\u304b\u307e\u305a\u3044\u3067\u3059\u3088 <a href=\"https:\/\/t.co\/8V6TvcTcEC\">pic.twitter.com\/8V6TvcTcEC<\/a><\/p>&mdash; \u88cf\u7d05\u4e5f@booth\u901a\u8ca9\u306f\u3058\u3081\u307e\u3057\u305f (@urakouya) <a href=\"https:\/\/twitter.com\/urakouya\/status\/1691077879038169088?ref_src=twsrc%5Etfw\">August 14, 2023<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><figcaption class=\"wp-element-caption\"><strong>Post Translation: <\/strong><font size=\"2\">Has PictBLand been taken over??? There&#8217;s strange popups appearing, and there\u2019s something very off about their content<\/font><\/figcaption><\/figure>\n\n\n\n<p>The text on the screenshoted popup translates to \u201cChairman Kim Jong-un is a great leader of North Korea, working tirelessly for the nation&#8217;s people. Under his guidance, North Korea has consistently progressed and achieved development. His patriotism and dedication have left an impression on people around the world.\u201d<\/p>\n\n\n\n<p>Many users believe that it was the sites\u2019 method of password encryption that led to the data breach. The sites used MD5, a cryptographic hashing function, to store their passwords. Unfortunately, MD5 has long been considered to be insecure for password storage and is no longer recommended for that reason. Additionally, many users reported that upon registering with the site, they were emailed their passwords in plain text. According to <a href=\"https:\/\/www.passcamp.com\/blog\/dangers-of-storing-and-sharing-passwords-in-plaintext\/\" target=\"_blank\" rel=\"noreferrer noopener\">PassCamp,<\/a> \u201cIf you store a password in clear, readable text, anyone who has (un)authorized access to your account or device can read it. And if that person is a hacker who has just broken into the database, your sensitive data now belongs to him.\u201d<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/twitter.com\/eystc\/status\/1691398552352960512\n<\/div><figcaption class=\"wp-element-caption\"><strong><font size=\"2\">Post translation:<\/font><\/strong><font size=\"2\"> When I had forgotten my PictBLand password, they emailed it to me in plain text, so I immediately unsubscribed, citing that as the reason. When I registered again a few years later, it still hadn&#8217;t changed, so it\u2019s very much possible that they are managing passwords in plain text. At least they did a few years ago.<\/font><\/figcaption><\/figure>\n\n\n\n<p>On the same day as the attack on the site, the supposed hacker put users\u2019 data up for sale on Breachforums, a black hat hacking crime site. According to the hacker\u2019s post on the <a href=\"https:\/\/breachforums.is\/Thread-Japan-pictSQUARE-800K-phones-emails-unsalted-MD5-4-XMR-otaku-culture\" target=\"_blank\" rel=\"noreferrer noopener\">forum<\/a>, they were looking for three people to buy the data for 4 Monero each. Currently 1 Monero is worth less than 200 USD, so it&#8217;s a relatively low price for the amount of trouble it\u2019s caused for users of the fansites. It seems as though they have already found their buyers, posting that their last copy of the data has now been sold.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1708\" height=\"1080\" sizes=\"auto, (max-width: 1708px) 100vw, 1708px\" src=\"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-1708x1080.jpeg\" alt=\"\" class=\"wp-image-20800\" srcset=\"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-1708x1080.jpeg 1708w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-600x379.jpeg 600w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-380x240.jpeg 380w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-768x486.jpeg 768w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-1536x971.jpeg 1536w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-2048x1295.jpeg 2048w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-150x95.jpeg 150w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-300x190.jpeg 300w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-696x440.jpeg 696w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-1068x675.jpeg 1068w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-1920x1214.jpeg 1920w, https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-001-664x420.jpeg 664w\" \/><\/figure>\n\n\n\n<p>Upon learning that their data was being sold for such a low price on the hacking forum, some users were upset that PictBLand didn\u2019t make an offer to save their data. One user <a href=\"https:\/\/twitter.com\/otk_space\/status\/1691449263199551490\" target=\"_blank\" rel=\"noreferrer noopener\">inquired<\/a>,&nbsp;\u201cWhy didn&#8217;t you pay the money? Is money more important to you than your customers?\u201d There were also numerous users who criticized the site\u2019s lack of security and inability to protect their users.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"ja\" dir=\"ltr\">\u3082\u3046\u58f2\u308a\u306b\u51fa\u3055\u308c\u3066\u308b<br><br>pictSQUARE\u3063\u3066\u30e6\u30fc\u30b6\u30fc\u3067\u3042\u308b\u4e8b\u3082\u77e5\u3089\u308c\u305f\u304f\u306a\u3044\u30bb\u30f3\u30b7\u30c6\u30a3\u30d6\u306a\u754c\u9688\u306a\u306e\u306b\u8a8d\u8a3c\u60c5\u5831\u3069\u3053\u308d\u304b\u5b9f\u540d\u306b\u96fb\u8a71\u756a\u53f7\u307e\u3067\u6d41\u3055\u308c\u3066\u308b\u4eba\u304c\u3044\u308b\u3068\u8a00\u3046\u306e\u306f\u524d\u4ee3\u672a\u805e\u306e\u5927\u60e8\u4e8b\u3067\u306f\u306a\u3044\u304b<br><br>\u307e\u3055\u304b\u30bd\u30eb\u30c8\u629c\u304d\u306eMD5\u3067\u6697\u53f7\u5316\u3057\u307e\u3057\u305f\uff08\uff83\uff8d\uff8d\uff9f\uff9b\uff09\u3068\u304b\u3053\u306e\u3054\u6642\u4e16\u306b\u76ee\u306b\u3059\u308b\u3068\u3082\u601d\u308f\u306a\u304b\u3063\u305f\u304c <a href=\"https:\/\/t.co\/K7uaiyoe3R\">https:\/\/t.co\/K7uaiyoe3R<\/a><\/p>&mdash; \u3082\u3063\u3075\u3093 (@Musician_Moffun) <a href=\"https:\/\/twitter.com\/Musician_Moffun\/status\/1691549616020545786?ref_src=twsrc%5Etfw\">August 15, 2023<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><figcaption class=\"wp-element-caption\"><strong>Post translation:<\/strong> <font size=\"2\">It&#8217;s already up for sale. pictSQUARE is so sensitive that people don&#8217;t even want to be known as users, but the fact that some have had their real names and phone numbers, not to mention authentication information leaked is a disaster of unprecedented proportions. I never thought I\u2019d see someone using unsalted MD5 encryption in this day and age.<\/font><\/figcaption><\/figure>\n\n\n\n<p>Users are understandably upset with their data being sold and their favorite sites being shut down without a clear notice of when they will be back up. PictBLand has yet to announce when it and its sister sites will return, however, they have announced on their official account that once their investigation on the matter is complete, steps will be taken to further strengthen the sites\u2019 security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A popular Japanese boys&#8217; love social media platform gets hacked. Users are worried about their data as it&#8217;s revealed to be up for sell on a black hat hacking crime site.<\/p>\n","protected":false},"author":57,"featured_media":20802,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gspb_post_css":"","footnotes":""},"categories":[3,65],"tags":[17],"class_list":["post-20797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-nongaming-news","tag-japan-related-news"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Users of popular Japanese BL social network have their information stolen and ransomed after security breach - AUTOMATON WEST<\/title>\n<meta name=\"description\" content=\"A popular Japanese boys&#039; love social media platform gets hacked. Users are worried about their data as it&#039;s revealed to be up for sell on a black hat hacking crime site.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Users of popular Japanese BL social network have their information stolen and ransomed after security breach - AUTOMATON WEST\" \/>\n<meta property=\"og:description\" content=\"A popular Japanese boys&#039; love social media platform gets hacked. Users are worried about their data as it&#039;s revealed to be up for sell on a black hat hacking crime site.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/\" \/>\n<meta property=\"og:site_name\" content=\"AUTOMATON WEST\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-17T09:34:40+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-header.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Remi Morisawa\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@AUTOMATON_ENG\" \/>\n<meta name=\"twitter:site\" content=\"@AUTOMATON_ENG\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Remi Morisawa\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Users of popular Japanese BL social network have their information stolen and ransomed after security breach - AUTOMATON WEST","description":"A popular Japanese boys' love social media platform gets hacked. Users are worried about their data as it's revealed to be up for sell on a black hat hacking crime site.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/","og_locale":"en_US","og_type":"article","og_title":"Users of popular Japanese BL social network have their information stolen and ransomed after security breach - AUTOMATON WEST","og_description":"A popular Japanese boys' love social media platform gets hacked. Users are worried about their data as it's revealed to be up for sell on a black hat hacking crime site.","og_url":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/","og_site_name":"AUTOMATON WEST","article_published_time":"2023-08-17T09:34:40+00:00","og_image":[{"width":1600,"height":1200,"url":"http:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-header.jpg","type":"image\/jpeg"}],"author":"Remi Morisawa","twitter_card":"summary_large_image","twitter_creator":"@AUTOMATON_ENG","twitter_site":"@AUTOMATON_ENG","twitter_misc":{"Written by":"Remi Morisawa","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#article","isPartOf":{"@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/"},"author":{"name":"Remi Morisawa","@id":"https:\/\/automaton-media.com\/en\/#\/schema\/person\/6b0dd1f7c4e8f1fef9bf670fcf868e8a"},"headline":"Users of popular Japanese BL social network have their information stolen and ransomed after security breach","datePublished":"2023-08-17T09:34:40+00:00","mainEntityOfPage":{"@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/"},"wordCount":722,"commentCount":0,"publisher":{"@id":"https:\/\/automaton-media.com\/en\/#organization"},"image":{"@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#primaryimage"},"thumbnailUrl":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-header.jpg","keywords":["News (Japan-related)"],"articleSection":["News","Non-Gaming News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/","url":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/","name":"Users of popular Japanese BL social network have their information stolen and ransomed after security breach - AUTOMATON WEST","isPartOf":{"@id":"https:\/\/automaton-media.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#primaryimage"},"image":{"@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#primaryimage"},"thumbnailUrl":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-header.jpg","datePublished":"2023-08-17T09:34:40+00:00","description":"A popular Japanese boys' love social media platform gets hacked. Users are worried about their data as it's revealed to be up for sell on a black hat hacking crime site.","breadcrumb":{"@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/automaton-media.com\/en\/news\/20230817-20797\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#primaryimage","url":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-header.jpg","contentUrl":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/08\/20230817-20797-header.jpg","width":1600,"height":1200},{"@type":"BreadcrumbList","@id":"https:\/\/automaton-media.com\/en\/news\/20230817-20797\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u30db\u30fc\u30e0","item":"https:\/\/automaton-media.com\/en\/"},{"@type":"ListItem","position":2,"name":"Users of popular Japanese BL social network have their information stolen and ransomed after security breach"}]},{"@type":"WebSite","@id":"https:\/\/automaton-media.com\/en\/#website","url":"https:\/\/automaton-media.com\/en\/","name":"AUTOMATON WEST","description":"AUTOMATON is a website that covers the Japanese gaming world. We bring you the news on video games from Osaka and Tokyo.","publisher":{"@id":"https:\/\/automaton-media.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/automaton-media.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/automaton-media.com\/en\/#organization","name":"\u682a\u5f0f\u4f1a\u793e\u30a2\u30af\u30c6\u30a3\u30d6\u30b2\u30fc\u30df\u30f3\u30b0\u30e1\u30c7\u30a3\u30a2","url":"https:\/\/automaton-media.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/automaton-media.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2021\/04\/activegamingmedia_logo.png","contentUrl":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2021\/04\/activegamingmedia_logo.png","width":374,"height":190,"caption":"\u682a\u5f0f\u4f1a\u793e\u30a2\u30af\u30c6\u30a3\u30d6\u30b2\u30fc\u30df\u30f3\u30b0\u30e1\u30c7\u30a3\u30a2"},"image":{"@id":"https:\/\/automaton-media.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/AUTOMATON_ENG","https:\/\/www.youtube.com\/channel\/UCabvYnvuUUbbGUrxkaFRgSA"]},{"@type":"Person","@id":"https:\/\/automaton-media.com\/en\/#\/schema\/person\/6b0dd1f7c4e8f1fef9bf670fcf868e8a","name":"Remi Morisawa","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/07\/pz-WVnDc_400x400-100x100.jpg","url":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/07\/pz-WVnDc_400x400-100x100.jpg","contentUrl":"https:\/\/automaton-media.com\/en\/wp-content\/uploads\/2023\/07\/pz-WVnDc_400x400-100x100.jpg","caption":"Remi Morisawa"},"url":"https:\/\/automaton-media.com\/en\/author\/remi-morisawa\/"}]}},"_links":{"self":[{"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/posts\/20797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/comments?post=20797"}],"version-history":[{"count":8,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/posts\/20797\/revisions"}],"predecessor-version":[{"id":20809,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/posts\/20797\/revisions\/20809"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/media\/20802"}],"wp:attachment":[{"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/media?parent=20797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/categories?post=20797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/automaton-media.com\/en\/wp-json\/wp\/v2\/tags?post=20797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}