Hacktivists claiming to be Anonymous said they breached web host and domain registrar Epik, a provider used by sites including Gab, Parler, QAlerts, and other far-right platforms, and released what they described as roughly a decade of internal and customer data. Reports said the dump included domain registration and transfer records, account credentials, emails, payment history, employee mailbox contents, and more than 500,000 private keys, affecting data tied to more than 15 million people and websites. Epik CEO Rob Monster initially downplayed the incident, then later acknowledged in a public video session that company backup data appeared to have been compromised and said information from the breach was allegedly used in an attempt to target his Coinbase account.
Subsequent reporting said the leaked records exposed internal support tickets, subpoenas, and preservation requests for customer information, including requests that appeared linked to investigations after the Jan. 6 Capitol riot and at least one FBI request tied to a domain allegedly connected to malware used in the SolarWinds intrusion. The data also reportedly helped trace efforts by figures such as Ali Alexander to obscure domain ownership and digital infrastructure, while additional releases expanded scrutiny of how hosting and registrar services supported extremist networks online. The breach became one of the most consequential hacktivist leaks involving internet infrastructure providers because it revealed both customer identities and sensitive law-enforcement-related records.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
By October 7, coverage of the Epik breach placed it alongside other major hack-and-leak incidents, including Twitch, as examples of hacktivists exposing internal corporate data and infrastructure. This reflected the broader significance of the Epik disclosures beyond the initial victim alone.
On September 30, reporting indicated that another batch of stolen Epik data had been released, extending the fallout from the original breach. The new dump suggested the attackers continued publishing material beyond the initial archive.
Internal ticketing records from the breach exposed subpoenas, grand jury requests, and 90-day preservation demands for customer information, including requests apparently tied to investigations after the January 6 Capitol riot. The leaked records also showed an FBI preservation request and subpoena in late 2020 for an Epik-hosted domain allegedly linked to malware used in the SolarWinds attack.
By September 21, mainstream reporting described the Epik hack as exposing information tied to more than 15 million people and websites. Coverage also highlighted Epik's role as a service provider for far-right and extremist-linked platforms, increasing the public impact of the breach.
Analysis of the leaked Epik records showed how figures such as Ali Alexander appeared to have tried to obscure their online footprint after the January 6 Capitol riot. The reporting used the breach data to connect domains and infrastructure to post-riot activity.
During a chaotic public video session, Rob Monster acknowledged that Epik had been breached after earlier denials and described it as involving a compromised company backup. He also said a hacker nearly stole about $100,000 from his Coinbase account using information exposed in the incident.
Weeks before the hack became public, a security researcher reported a critical flaw in Epik's website that exposed customer account data and could allow account takeover. The report said Epik did not promptly fix the issue before the later breach disclosures.
After the breach claim surfaced, Epik CEO Rob Monster publicly downplayed it on Twitter, calling the matter insignificant and questioning the authenticity of the leaked material. This marked the company's first public response to the incident.
Anonymous said it hacked web host and domain registrar Epik and obtained roughly a decade of internal and customer data, including domain records, credentials, payment history, employee mailboxes, and hundreds of thousands of private keys. Early reporting on the leak appeared on September 14, 2021, as the group said it was working to make the archive more accessible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
washingtonpost.com
Open sourcetheregister.com
Open sourcedailydot.com
Open sourcecnn.com
Open sourcedailydot.com
Open sourcedailydot.com
Open sourcetechcrunch.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.