Disney investigates leak of 1.1 TB of internal Slack data

Organization
The Walt Disney Company
Exploit
Hacking
Industry
Entertainment

In July 2024 an entity calling itself NullBulge posted around 1.1 terabytes of material it said had been taken from about 10,000 of The Walt Disney Company's internal Slack channels. The files went up on a hacking forum on 12 July 2024 and drew wide coverage over the following days.

The archive reportedly held messages, files and computer code, discussions of studio technology and of the management of Disney's corporate website, advertising campaign material, references to unreleased projects, and some login credentials and images, with conversations reaching back to at least 2019. NullBulge presented itself as a hacktivist collective concerned with artists' rights and fair compensation, and claimed an insider had provided access before getting cold feet.

Disney said it was investigating and did not confirm the authenticity of the material at the time. Security researchers quoted by CSO Online suggested the access more likely came from leaked or stolen Slack API keys, or from weaknesses in third-party integrations, rather than from any insider.

The account NullBulge gave of itself did not hold up. In May 2025 Ryan Mitchell Kramer, a 25-year-old from California, pleaded guilty to the theft. Prosecutors said he had distributed malware disguised as an AI image generation tool on GitHub and Hugging Face, which a Disney employee installed on a personal computer, exposing stored credentials including Slack access. Kramer had acted alone and invented the hacktivist group.

Sources