{"id":24365,"date":"2024-04-22T04:10:04","date_gmt":"2024-04-22T12:10:04","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/04\/22\/news-18095\/"},"modified":"2024-04-22T04:10:04","modified_gmt":"2024-04-22T12:10:04","slug":"news-18095","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/04\/22\/news-18095\/","title":{"rendered":"Billions of scraped Discord messages up for sale"},"content":{"rendered":"\n<p>Four billions public Discord messages are for sale on an internet scraping service called Spy.pet.<\/p>\n<p>At first sight there doesn\u2019t seem to be much that is illegal about it. The messages were publicly accessible and there are no laws against scraping data. However, it turns out the site did disregard some laws: more on that later.<\/p>\n<p>To get this amount of data the platform gathered information from 14,201 servers about 627,914,396 users.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1102\" height=\"183\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/04\/big_numbers.png?w=1024\" alt=\"information gathered from 14,201 servers about 627,914,396 users produced 4,098,054,528 logged messages\" class=\"wp-image-109054\" \/><\/figure>\n<p>The way in which Spy.pet organized the information could turn out to be problematic for certain users. It built a database based on user profiles which contains all known aliases, pronouns, connected accounts (such as Steam and GitHub), Discord servers joined, and public messages.<\/p>\n<p>The buyers don\u2019t need to descend into the dark dungeons of the <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2021\/09\/what-is-the-dark-web-the-dark-web-explained\">dark web<\/a> to buy this information. It&#8217;s available for anyone on the regular web.<\/p>\n<p>For a search of information about a specific user, all you need is their Discord User-ID and some cryptocurrency.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"659\" height=\"289\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/04\/payments.png\" alt=\"A credit costs $0.01 and you\u2019ll have to buy a minimum of 500 credits. A new search for a profile costs 10 credits (7 for a cached profile). \" class=\"wp-image-109055\" \/><\/figure>\n<p>To look up profiles, you\u2019ll first have to buy credits. A credit costs $0.01 and you\u2019ll have to buy a minimum of 500 credits.<\/p>\n<p>A new search for a profile will put you back 10 credits (7 for a cached profile).<\/p>\n<p>Interestingly the platform also offers an enterprise version for which interested parties are invited to contact the administrator.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"694\" height=\"207\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/04\/Enterprise_option.png\" alt=\"Interested in training an AI model with Discord messages? Are you a group of federal agents looking for a new source of intel? Or maybe something else? We\u2019ve got you covered. Contact us and let us know how we can help.\" class=\"wp-image-109056\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-breaking-a-few-laws\">Breaking a few laws<\/h2>\n<p>Scraping data is a common practice nowadays, but there are a few rules that, when broken, will cost a lot more than a few dollars. Scraping and selling data about minors, especially without consent, is illegal in most parts of the world, including the US.<\/p>\n<p>And when you are gathering data about European Union (EU) citizens, you\u2019ll need to have a method in place for those citizens to have their information removed. Spy.pet does have a \u201cRequest Removal\u201d button, but clicking it will show you an annoying snippet of a Spiderman movie where the news editor laughs at Peter Parker.<\/p>\n<p>Discord told <a href=\"https:\/\/www.theregister.com\/2024\/04\/16\/discord_network_sale\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the Register<\/a> it is probing Spy.pet to see if any action needs to be taken against the chat-harvesting service.<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>&#8220;Discord is committed to protecting the privacy and data of our users. We are currently investigating this matter. If we determine that violations of our Terms of Service and Community Guidelines have occurred, we will take appropriate steps to enforce our policies. We cannot provide further comments as this is an ongoing investigation.&#8221;<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\" id=\"h-check-your-digital-footprint\">Check your digital footprint<\/h2>\n<p><span>Malwarebytes has a new free tool for you to check how much of your personal data has been exposed online. Submit your email address (it\u2019s best to give the one you most frequently use) to our\u00a0<\/span><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">free Digital Footprint scan<\/a><span>\u00a0and we\u2019ll give you a report and recommendations.<\/span><\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-7ba16f0b-04e8-4679-9512-2f21a0971dcf\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2c_pro_acq_fy25dfplaunch_171269600960&amp;utm_content=V1\"><\/a><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">SCAN NOW<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a><\/p>\n<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/04\/billions-of-scraped-discord-messages-up-for-sale\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> An internet scraping platform is offering access to a database filled with over four billion Discord messages and combined user profiles. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[13656,32,5897,31299],"class_list":["post-24365","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-discord","tag-news","tag-privacy","tag-spy-pet"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24365"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24365\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}