Cyber Incident Victim: Liker.com
Date:
Mar 2021
Location:
United States of America
Summary
A social media platform experienced a significant security breach when attackers exploited an SQL injection vulnerability to compromise its servers, resulting in the exfiltration of 90 databases containing extensive user information. The incident impacted approximately 464,000 accounts, exposing emails, IP addresses, private messages, phone numbers, security questions, birthdates, and biographical details. Following the intrusion, the service was taken offline indefinitely, with operators attributing the attack to disgruntled political adversaries and citing system upgrades as justification for the shutdown.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around March 9, 2021, attackers compromised the social media platform Liker.com through an SQL injection vulnerability, gaining unauthorized access to its servers. The breach resulted in the exfiltration of all 90 databases containing user data. Founded by Omar Rivero, creator of the influential Occupy Democrats Facebook page, Liker.com positioned itself as an anti-Trump platform and had attracted approximately 464,000 registered users prior to the incident. The stolen datasets included personally identifiable information such as email addresses, IP addresses, private messages, phone numbers, security questions, birthdates, biographical details, and support tickets. Specific geographic impacts included exposure of data belonging to over 7,000 French users and 11,900 Canadian users. The platform's operators did not publicly disclose detection methods or initial containment efforts prior to system compromise.

Following the breach, Liker.com administrators took the platform offline entirely, replacing it with a maintenance message stating the site would remain unavailable for 4-8 weeks pending a redesign. Rivero attributed the attack to pro-Trump supporters allegedly retaliating against content restrictions, claiming the shutdown aimed to "protect our community." However, the attackers had already disseminated the stolen databases externally by the time of the platform's closure. No evidence of ransom demands or financial motives was disclosed in available reports. The incident rendered all user accounts compromised, with particularly severe privacy implications due to the exposure of private messages and security credentials. Liker.com remained non-operational following the breach announcement, with no subsequent reactivation confirmed in the documented timeline.
