I recently published a couple of stories about a now deceased SEO expert that Ashley Madison initially suspected of being involved in their 2015 hack. However, I seemed to have overlooked one very interesting Ashley Madison hire in late 2014: Jordan Evan Bloom, a Canadian man arrested and charged in 2018 for running LeakedSource, a site that sold access to hacked passwords and other data.
According to emails stolen from then CEO Noel Biderman, Bloom was hired in Dec. 2014 to do PHP development for AM. He left the company ~ two weeks *before* the hack, citing health reasons.
Bloom would launch LeakedSource just a few months later. Here's what AM's director of human resources said about him before his hiring:
"In his previous experience he had been doing RMT (Real Money Trading). This is the practice of selling virtual goods in games for real world money. This is a grey market, which is usually against the terms and services of the game companies.
RMT sellers traditionally have a lot of problems with chargebacks, and payment processor compliance. During my interview with him, I spent some time focusing in on this. He had to demonstrate to the processor, Paypal, at the time he had a business and technical strategy to address his charge back rate.
He ran this company himself, and did all the coding, including the integration with the processors. Eventually he was squeezed out by chinese gold farmers, and their ability to market with much more investment than he could. In addition the cost of 'farming' the virtual goods was cheaper in China to do than in North America.
Unlike a lot of the developers we interview, he has a good understanding of the challenges an online business faces, and I believe he would bring a different perspective to the team, as well as being able to work on day to day things."
His departure notice from the same HR person said: "Please note that Jordan Bloom has resigned from his position as PHP Developer with Avid. He is leaving for personal reasons. He has a neck issue that will require surgery in the upcoming months and because of his medical appointment schedule and the pain he is experiencing he can no longer to commit to a full-time schedule. He may pick up contract work until he is back to 100%. Note that he has disclosed that he is independently wealthy so he can get by without FT work until he is on the mend. He has signed the Exit Acknowledgement Form already without issue. He also says he would consider reapplying to Avid in the future if we have opportunities available at that time."
The gold farming business mention is very interesting. In 2017, I published a lengthy investigation into the proprietors of LeakedSource, which found the admin or one of the admins was heavily into hacking Runescape accounts for their virtual currency. https://krebsonsecurity.com/2017/02/who-ran-leakedsource-
@briankrebs so THAT'S what "abusewith.us" is. I've noticed that name when I've looked up various email addresses of mine on haveyoubeenpwned. Guess someone tried to create an account with my email 🤔