Epik, a U.S. domain registrar and hosting provider known for servicing deplatformed far-right platforms including Gab, Parler, 8chan, Proud Boys and QAnon-linked sites, suffered a major breach that attackers publicly claimed in September 2021. Reporting said roughly 180 GB of company and customer data was stolen, including customer lists, passwords, home addresses, payment histories, encryption keys and, in some cases, unencrypted credit card numbers. After initially disputing reports of a compromise, Epik later told customers that some systems had been breached and urged them to monitor payment methods, email accounts and passwords.
The leaked material was widely reported as authentic and exposed serious security weaknesses at Epik, while also stripping anonymity from users of the company’s privacy services. Researchers and activists used the data to identify administrators and operators tied to Proud Boys, Oath Keepers, QAnon and other extremist or scam-linked sites, intensifying scrutiny of Epik’s role as infrastructure for extremist ecosystems. The fallout continued well beyond the intrusion, contributing to reputational and operational turmoil that preceded Epik’s later sale to Registered Agents Inc., whose new owners said they were trying to rebuild trust and move the registrar in a different direction.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2024-02-09, TechRadar reported that Registered Agents Inc. had acquired Epik and was repositioning it toward entrepreneurs and small businesses. The new owner said Epik had changed terms of service, removed a small number of problematic clients, and worked through a difficult accreditation transfer while maintaining service continuity.
By 2021-12-09, CEO Rob Monster acknowledged the breach’s impact and said Epik needed to improve its security. He attributed some problems to outdated code and said new funding and hires would be used to strengthen infrastructure.
By 2021-09-20, news reports said the leaked Epik material appeared genuine and exposed highly sensitive information, including unencrypted credit card numbers and data that deanonymized users of Epik’s privacy services. Researchers and activists used the leak to identify administrators tied to Proud Boys, Oath Keepers, QAnon, and scam-linked sites.
On 2021-09-18, after initially denying a compromise, Epik told customers that an intrusion had affected some of its systems. The company advised users to monitor payment methods, email accounts, and passwords.
On 2021-09-13, a message attributed to Anonymous claimed responsibility for breaching Epik and stealing about 180 GB of company and customer data, including customer records, encryption keys, and payment histories. The operation was framed by the attackers as part of “Operation Jane.”
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
techradar.com
Open sourcecnn.com
Open sourcewashingtonpost.com
Open sourcelemonde.fr
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.