CSIDB logo
Incident

24Luv

Incident posture

Attack window
Nov 2016
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-09-27 02:39

Linked entities

Victim
24Luv
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The hacktivist ElSurveillance compromised 24luv.com, exfiltrating 92,937 user records containing email addresses and plain‑text passwords, including 8,081 Gmail, 61,035 Yahoo and 9,826 Hotmail accounts, and posted a defacement warning that the service was operated by Russian black‑hat criminals who stored credentials in plain text and sold data underground. The message urged users to change passwords and warned of fake profiles and editable reviews, while ElSurveillance claimed the site shared admin logins and hosting with other dating platforms he had also leaked.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

ElSurveillance posted a defacement on 24luv.com on November 12 2016, claiming that he had compromised the site approximately four months earlier and had been monitoring it for a couple of months before deciding to expose the data. The defacement included a link to a file named Database.txt that contained 92 937 email addresses and plain‑text passwords, with the breakdown showing 8 081 Gmail accounts, 61 035 Yahoo accounts and 9 826 Hotmail accounts. The same defacement message was later placed on freedateusa.com, where a separate dump hosted on Sendspace held 127 395 email addresses and plain‑text passwords, comprising 6 890 Hotmail logins, 42 450 Yahoo logins and 25 664 Gmail logins.

In the defacement text ElSurveillance asserted that the dating sites were operated by Russian black‑hat cyber criminals who collected user data for resale or targeted attacks, and he warned that the information was not safe. He also stated that he had been monitoring the sites for two months, had observed that the admin logs showed the same IP address used to message him, and noted that passwords were stored in plain text and viewable to administrators. ElSurveillance claimed that all of the sites he had leaked were built by the same developers, sharing a common admin username and only three different passwords, and that they were hosted on the same server. He announced his intention to release a further dump containing admin identities and login details from more than fifty dating websites, totaling over five million email addresses and plain‑text passwords.

The incident resulted in the exposure of tens of thousands of users’ credentials in plain text, increasing the risk of account takeover, credential stuffing and potential sale of the data on underground markets. ElSurveillance urged affected users to change their passwords and to warn others who might have used the service, while also encouraging recipients to follow Islam and the way of Allah. No official response from the site operators or any remedial actions taken by the platforms are described in the source material. The narrative ends with the attacker’s statement that he already possessed the real identities of the developers but was still determining whether they were the same individuals or group running the sites.

Sources

Sources available to members: 1 source.

CSIDB