Categories: Cyber CrimeHacking

Fappening 4 archive leaked online, the controversy continues

The Fappening 4 – The fourth wave of nude celebrity photos hacked from the iCloud system was leaked online, new stars victimized including a male.

A new episode of the Fappening Saga is out, online comes the fourth archive (the Fappening 4), of celebrity nude photos leak, and for the happiness of women the collection includes the photos of a male for the first time.  The Fappening 4 contains the picture of Nick Hogan, the son of the legend of the wrestling Hulk Hogan,  the actresses Winona Ryder, Nina Dobrev and AnnaLynne McCord, the Victoria’s Secret model Erin Heatherton and singer Ingrid Michaelson. The star most affected is the Vampire Diaries actress Nina Dobrev, the Fappening 4 archive includes 147 personal images leaked online, fortunately none of them is a naked picture. Another illustrious victim is the actress Zoe Kazan.
The Fappening 4 archive was disclosed on Thursday through Reddit as the latest “Fappening”, Reddit and 4Chan immediately banned it and any other discussion titled Fappening in compliance to the Digital Millennium Copyright Act (DMCA).
The Fappening 4 archive was disclosed after Google has decided to remove the photos from its systems, an official statement released by the IT giant states:
“We’ve removed tens of thousands of picture – within hours of the requests being made – and we have closed hundreds of accounts. The internet is used for many good things. Stealing people’s private photos is not one of them.”

The Hollywood lawyer Marty Singer, acting on behalf of his unnamed clients, sent a letter to Google execs Larry Page, Sergey Brin and Eric Schmidt, accusing the company of “blatantly unethical behavior” that has made their company “millions from the victimization of women.” Singer threatened to sue Google for $100,000,000 if the images were not removed immediately.

“Google knows that the Images are hacked stolen property, private and confidential photos and videos unlawfully obtained and posted by pervert predators who are violating the victims’ privacy rights and basic human decency by stealing and displaying confidential private photos and videos (most of which depict the women in private settings, while nude or semi-nude, engaging in private intimate conduct) without the permission of the owners of the Images,” said the letter. “Yet Google has taken little or no action to stop these outrageous violations, or to limit the Images from appearing in Google search results.” wrote Marty Singer

The saga begun this summer, In august a first massive leak was announced online and the pictures were everywhere on the web. The list of victims is very long and includes many celebrities like Kim Kardashian, Vanessa Hudgens, the US national women’s soccer team player Hope Solo, Mary-Kate Olsen, Avril Lavigne, Hayden Panettiere, Lake Bell, Leelee Sobieski and former Disney stars Aly and AJ Michalka.

Law enforcement are currently investigating in the data leakage, all the images were stored on the Apple iCloud service, security experts attribute the responsibility of the incident to a flaw in the cloud storage. Apple has always sustained that the nude celebrity photos come from different sources, they were probably obtained via targeted attacks and not exploiting the flaw in its systems.
I desire close this post on the Fappening 4 with an abstract from my previous post on the Fappening 3, the piece I have chosen is related to accusations to Apple for a superficial management of the flaw affecting its iCloud infrastructure.
According to the Daily Dot the company was aware of a serious flaw in its iCloud since March 2014.

The emails, obtained earlier this month by the Daily Dot and reviewed by multiple security experts, show Ibrahim Balic, a London-based software developer, informing Apple of a method he’d discovered for infiltrating iCloudaccounts. ” states a blog post published by the Daily Dot on the Fappening case.

“In a March 26 email, Balic tells an Apple official that he’s successfully bypassed a security feature designed to prevent “brute-force” attacks—a method used by hackers to crack passwords by exhaustively trying thousands of key combinations.” continues the post.

The reply from Apple is anyway questionable, below the image reported in the article.

Resuming, Apple was alerted in March on the security issue …. but now we are reading of The Fappening 4, whatever the source would be it is likely that other photos will be released in the next weeks.

Stay tuned for further information on the Fappening 4.

Pierluigi Paganini

(Security Affairs – Fappening 4, celebrity nude photos leak)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 84

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

2 hours ago

Security Affairs newsletter Round 563 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

2 hours ago

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

23 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

24 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

This website uses cookies.