CSIDB logo
Incident

Captain 69

Incident posture

Attack window
Jul 2015
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-01-14 16:40

Linked entities

Victim
Captain 69
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The UK-based site Captain69.co.uk experienced a data breach when attacker @ElSurveillance compromised its systems and publicly released 2,653 user credentials, including usernames and passwords stored as SHA-256 hashes. The threat actor, known for targeting escort service platforms, directed individuals to use third-party tools to decrypt the exposed password hashes, potentially enabling unauthorized access to affected accounts. This incident highlighted risks associated with credential reuse across multiple services despite the site's implementation of password hashing as a security measure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 19, 2015, the UK-based website Captain 69™ Worldwide Escort Reviews experienced a data breach involving unauthorized access and public exposure of user credentials. The threat actor @ElSurveillance, previously linked to attacks on escort service platforms including MeetMeInYourCity.com, publicly released a data dump containing 2,653 usernames and associated passwords from the captain69.co.uk domain. The compromised credentials were stored as SHA-256 hashes, indicating the site implemented cryptographic password protection prior to the breach. @ElSurveillance directed individuals to third-party password cracking service crackstation.net to convert the hashed credentials into plain text. The breach disclosure occurred through public channels consistent with the attacker’s established pattern of targeting escort industry platforms.

The incident exposed authentication details of users registered on the UK escort review service, creating risks of credential reuse across other platforms. Publicly available SHA-256 hashes allowed threat actors to systematically attempt password decryption, potentially compromising account security. The data dump’s publication enabled broad access to the stolen credentials without technical barriers. Captain 69’s implementation of password hashing represented a higher security standard than comparable escort service sites breached during the same period, though the hashing mechanism alone proved insufficient to prevent credential exposure. No information exists in available sources regarding post-breach remediation actions by the site operators, detection methods employed, or containment measures implemented following the disclosure.

Sources

Sources available to members: 1 source.

CSIDB