Dialog, an invite-only network and private events group cofounded by Peter Thiel, exposed sensitive data on roughly 200 members and past participants through a misconfigured app distribution site that appears to have made internal files publicly accessible. Reporting indicates that anyone could submit an email address without a password and reach a page that loaded plaintext records through standard browser developer tools, exposing details such as dates of birth, cell phone numbers, emergency contacts, internal rankings and grading notes, political leanings assigned by Dialog, and active digital login tokens.
Dialog told members the database had been breached by a criminal hacker, but WIRED reported it found no evidence that an intrusion was required and concluded the exposure stemmed from insecure configuration tied to Fillout forms and Airtable-connected data. Fillout said its own systems were not known to be compromised and that customers are responsible for secure setup, while security experts cited in coverage said the incident reflects the persistent risk of security misconfiguration, ranked by OWASP as a leading application security weakness.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
WIRED reported that the Pentagon is looking into the Dialog data exposure after records reportedly revealed personal information belonging to multiple US national security officials, including intelligence and military personnel. The development marked a government response and highlighted that the exposed victim set included especially sensitive individuals.
A misconfigured landing page for Dialog's app made internal files containing personal information for roughly 200 members and past participants publicly accessible without a demonstrated intrusion. Reporting said the exposed workflow involved Fillout forms connected to Airtable and that access could be obtained through standard browser developer tools.
WIRED published an analysis concluding there was no evidence of an actual intrusion into Dialog's systems and that the exposed files appeared reachable through a publicly accessible app page. Experts cited by WIRED described the incident as a security misconfiguration rather than a confirmed hack.
Dialog told members and past event participants that a database containing their personal information had been breached by a purported criminal hacker. The company characterized the exposure as a hack, despite later reporting finding no evidence that an intrusion was required.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.