Kiwi Farms says it has been hacked and user details leaked

security
(Image credit: Shutterstock / Song_about_summer)

Controversial online forum Kiwi Farms has reportedly been hacked, with the user details of some accounts being leaked as a result.

The site, which describes itself as a "community dedicated to discussing eccentric people who voluntarily make fools of themselves", has had an extremely muddied history since it was founded in 2013, being linked to at least three suicides and to the 2019 Christchurch Mosque shooting in New Zealand. 

Kiwi Farms has struggled to find support within the tech industry, with cloud hosting infrastructure companies Cloudflare and DDoS-Guard recently choosing to stop providing their services to the site, causing it to become overrun by DDOS attacks.

What actually happened?

Joshua Moon, the defacto leader of the website said in a statement that "a bad actor was able to upload a webpage disguised as an audio file" to XenForo, using the .OPUS lossy audio coding format.

ZenForo is a commercial Internet forum software package used to build forums such as Kiwi Farms

According to Moon, the attacker was then "able to load this webpage (probably as an inline frame), causing random users to make automated requests and send their authentication cookies off-site, so that the attacker could use it to gain access to their account".

Moon added; "Once they had access to the ACP, they attempted to download user data, and XenForo provides a way to export user lists with information that is precise: email, username, last activity, register date, user state (banned/unverified), post count, and if they are staff."

However, the hackers requests  "did not appear to go through because they requested too many records at once" according to the administrator. 

Moon admitted that his own admin account "was compromised through this mechanism".

Kiwi Farms' statement on the matter said all users should assume their passwords have been stolen

In addition, users should assume that their email addresses have been leaked and they should also assume any IP they have used on their Kiwi Farms account in the last month has been leaked.

  • Want to keep your organization safe and secure? Check out our guide to the best firewalls

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
Data leak
Details of over 15,000 FortiGate devices leaked online, so be on your guard
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
A computer being guarded by cybersecurity.
Zacks Investment hit in data breach - 12 million users potentially at risk
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring