It was about a month and a half ago when Twitter and other major social media platforms banned Donald Trump and other users with far-right views . Many of those users were forced to move to other platforms, such as Parler and Gab , which were more tolerant of hate speech and misinformation. A few days later, Parler was taken off Amazon ’s hosting services and taken offline. Although it has now been restored, some of its users were transferred to Gab, another platform also known for its far-right users.

However, it appears that Gab was hacked resulting in the theft of its content, including passwords and private communications.
On Sunday night, the Distributed Denial of Secrets (DDoSecrets) group revealed what it calls “GabLeaks,” a collection of more than 70 gigabytes of Gab data, including more than 40 million posts. DDoSecrets says that a hacktivist calling himself “JaXpArO and My Little Anonymous Revival Project” leaked this data from Gab’s backend databases in order to expose far-right users of the platform. These users include conspiracy theory Qanon and election fraud conspiracies, supporters of white supremacy, and more.
Emma Best from DDoSecrets says the breached data includes not only all public posts and profiles on Gab (with the exception of photos or videos), but also private posts and messages, as well as passwords .“ Itcontains almost all the data about Gab, including user data and private posts, everything someone would need to perform a comprehensive analysis of Gab’s users and content.”

DDoSecrets said it would not publish online the stolen data, but would share it with journalists, social scientists and researchers. Gab CEO Andrew Torba reported the breach on Sunday.
Passwords for private groups are not encrypted, while for user accounts they are hashed, meaning they can be protected from a breach, but the level of security depends on the hashing scheme and the strength of the underlying password.
It is said that among the users whose hashed passwords were stolen are Donald Trump, Marjorie Taylor Greene, Mike Lindell and Alex Jones.
The compromised data also includes a chatlogs.txt file containing private conversations between users.
According to DDoSecrets, the hacker who breached Gab says he exploited a SQL injection vulnerability on the site. Called the “Anonymous Revival Project,” the hacker or hackers behind the breach say they “want to represent the anonymous masses fighting against capitalists and fascists.”
Gab CEO Andrew Torbasaid the company was aware of the vulnerability and patched it last week. The company also said the social media platform does not collect personal information from its users, such as phone numbers, social security numbers, dates of birth, etc. “DMs have only been live for a few weeks and are not currently a supported feature on the site, so if there has in fact been a breach in this area, we expect the number of accounts affected to be low,” Torba added on Friday, adding that it will update users on any new findings.
Although Torba did not confirm the security in his statement on Friday, two days later he admitted that both his and Donald Trump's accounts had been hacked.
"The entire company is investigating what happened and working to identify and fix the problem," Torba wrote on Sunday.

Gab is the second far-right social media platform to be hacked in recent months. Following the attack on the US in January, other hacktivists breached Parler to download all of its public content.
A researcher said the Gab data leak is significant. The data, he said, could offer a window into how users migrate from one service to another when faced with bans or other issues. It could also help build tools to prevent the spread of misinformation on other sites and platforms. “There’s so much hate, harassment, racism, neo-Nazism on a site like that,” the researcher says, “data from that could help develop ways to automatically detect that type of content so that other places that don’t allow it can remove it immediately.”
Source: Wired
