Report: Cam Network Exposed Sex Workers, Fans' Personal Data

Report: Cam Network Exposed Sex Workers, Fans' Personal Data

LOS ANGELES — A recent report declaring that “millions” of live cam fans and models have had their personal data exposed is being countered by the company involved.

Claiming “a network of ‘camgirl’ sites exposed millions of users and sex workers,” TechCrunch’s Zack Whittaker reported that an unencrypted database was found to contain months of “daily logs of the site activities [and] left without a password for weeks.”

The security breach is said to have taken place between May 24 and September 4.

The cam network, Barcelona-based VTS Media, serves its global audience through several popular live chat sites, including Amateur.tv, WebcamPornoxxx.net and PlacerCams.com.

Besides user data, some account and personal information about the network’s cam performers was also reportedly revealed, creating concerns for cammers and their fans alike over issues of security and social stigma.

“Those logs included detailed records of when users logged in — including [their] usernames and sometimes their user-agents and IP addresses, which can be used to identify users. The logs also included users’ private chat messages with other users, as well as promotional emails they were receiving from the various sites,” Whittaker said. “The logs even included failed login attempts, storing usernames and passwords in plaintext.”

Cybersecurity firm Condition:Black was credited with exposing the open database, which has since been locked.

“This was a serious failure from a technical and compliance perspective,” said Condition:Black’s John Wethington. “After reviewing the sites’ data privacy policy and terms and conditions, it’s clear that users likely had no idea that their activities being monitored to this level of detail.”

“Users should always take into consideration the implications of their data leaking but especially where the implications could be life altering,” Wethington added.

While data leaks are nothing new, and little seems to come from them, Whittaker noted that VTS Media and its European-based servers are subject to the GDPR — a strict law where sexual preferences are a “special category” of data requiring more stringent protections, with violations incurring fines of up to four percent of the company’s annual gross income.

XBIZ and industry stakeholders have warned website owners about the General Data Protection Regulation and the near-impossibility of compliance; the need to make a good-faith effort; and the stiff penalties for not doing so. Indeed, last year’s XBIZ Show and FSC Leadership Conference hosted a special session detailing the complexities and seriousness of the GDPR requirements.

VTS Media issued a statement clarifying the situation and asserting its compliance with the GDPR. The company thanked Condition:Black for the warning and vowed to work with the Spanish Data Protection Agency to resolve the issue.

Among the statement’s revelations is a counter to the claim of “millions of users” being exposed with a more manageable number of “about 330,000 users.”

“[All] of the data stored in our main database is encrypted and unreachable. There are no payment, billing, card or password data compromised. Card payments are processed by an external provider specialized in handling this type of sensitive data,” a company representative stated. “Users’ passwords have not been compromised and are not kept as plain text; therefore, they do not need to be changed by the users.”

The rep explained that the data that has been exposed consists of technical logs, which are automatically erased after six months, and “exclusively used for technical reviews, quality controls and to solve our users’ requests.”

“For these users, the only potentially exposed data are their email and IP address, not the password. Even though this data has been exposed, it does not mean that it has reached anyone else’s hands, because as of today we are not aware that anybody, except the security company that discovered the breach, has accessed these data,” the rep revealed, underscoring that no passwords appeared in plain text in the logs. “What has been reported as a leak of private passwords actually consists of failed attempts to access the site and these have always been encrypted, thus never appearing in plain text.”

The company had to temporarily use additional servers to store its support logs “due to a global technical issue,” and revealed that human error resulted in incorrect firewall policies being implemented on these servers.

The rep also noted that less than one-half of one percent of the network’s models had any data exposed and that these models would be contacted by the company.

“As far as we are aware,” the rep concluded, “no one aside from those who discovered the breach had access to the data nor [have] those technical logs been downloaded or published on the internet.”

Those who have concerns over their potential exposure can email privacy@vtsmedia.com for more information.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Congressional Republicans, Democrats Renew Attack on Section 230

The ranking members from both parties in the U.S. House of Representatives Communications and Technology Subcommittee have teamed up to propose an end to current liability protections under Section 230, known to digital rights activists as “the First Amendment of the internet.”

UK Tory Minister Blames Joblessness Crisis on Pornography, Video Games

The U.K. Tory government’s Work and Pensions Secretary this week blamed “pornography and video games” for what he called “a mental health crisis among young men” that he claims has resulted in them leaving the workforce.

Sexologist Dr. Susan Block Reports Legal Action Against Meta for Deplatforming

Sexologist Dr. Susan Block has reported that she has filed a complaint against Meta seeking arbitration for “wrongful business practices,” including lack of accountability, algorithmic discrimination and deactivation of her sex advice accounts.

Democratic Senator Dick Durbin Joins Press Conference Alongside Anti-Porn Crusading Group NCOSE

Democratic U.S. Senator for Illinois Dick Durbin participated in a joint press conference Wednesday organized by Republican Sen. Lindsey Graham to marshal support for the controversial Eliminating Abusive and Rampant Neglect of Interactive Technologies Act (EARN IT), alongside crusading anti-porn group NCOSE (formerly Morality in Media).

YouPay, Layers Accountancy Partner to Offer Financial Advice to UK Creators

Gifting platform YouPay has partnered with accounting firm Layers Accountancy to offer U.K.-based creators financial and tax advice to operate their businesses successfully.

U of Wisconsin Professor Pens Essay About Crusade to Get Him Fired for Creating Adult Content

A veteran University of Wisconsin professor, who was removed from his post as chancellor last year due to creating and appearing in adult content, has penned a piece for The Chronicle of Higher Education detailing his ordeal and ongoing attempts to fire him from his tenured position.

Fans Utopia Launches Fans Utopia+

Creator merch platform Fans Utopia has launched a new website, Fans Utopia+, designed to support up-and-coming performers who seek to connect with their fans and sell merchandise without committing to the full-service model offered by the flagship service.

AEBN Trends Article Probes Threesomes

AEBN has published a report on threesomes, comparing theory with practice, and fantasy with reality.

Centrobill Now Offering Fully Licensed PIX Payments in Brazil

Centrobill has integrated PIX payments into its services for the Brazilian market.

Spain's Government Fails in Attempt to Recriminalize, 'Abolish' Sex Work

Spain’s Socialist Party (PSOE) suffered a sound defeat on Tuesday in its attempt to recriminalize sex work in Spain, as a controversial bill promoted by Prime Minister Pedro Sánchez’s government failed to gain parliamentary support among the party’s ruling coalition allies.

Show More