An invite-only group cofounded by billionaire investor Peter Thiel has suffered a data exposure affecting more than a hundred current and past participants — but the root cause appears to be a website misconfiguration, not a criminal hack, according to an analysis by WIRED.
Dialog, which operates exclusive summits and retreats for prominent figures in politics, intelligence, and technology, notified members and past event participants last week that a database containing their personal information had been breached by a well-known criminal. However, a WIRED investigation published on June 23, 2026, found that the files were readable to anyone who visited a landing page for the group’s app — what cybersecurity experts describe as a misconfiguration that effectively made the data publicly accessible.
How the Exposure Occurred
According to WIRED, a Dialog website set up to distribute a phone app for an August gathering outside Dublin, Ireland, let any visitor sign up using any email address. It did not request a password. After submitting an email, the visitor was taken to a near-empty holding page; the same page also loaded the internal files on some 200 people into their browser. Viewing the files required little more than inspecting the page with tools built into every major internet browser. Multiple reviews of the site's publicly accessible architecture, WIRED said, point to a misconfiguration, not a break-in.
Dialog's managing director, Juliette Levine, sent an email notification to affected individuals — a copy of which was provided to WIRED — asserting that the exposure “was a hack executed by a well-known criminal who is wanted in the United States.” Levine added that the group had acted “out of caution” to protect “the safety, privacy, and reputation of every Dialoger past and present.”
Data Exposed and Affected Individuals
The notification said that the names of 113 past participants had been exposed and, separately, “some” people registered for this summer's Dialog retreat had their information accessed. The list of 113 past participants includes, according to WIRED, a sitting NATO commander, two US senators, and the US treasury secretary. A separate, longer list of people registered for the August retreat included senior figures in national security and technology, both current and former:
- NATO officials
- A current White House intelligence official
- A retired general who held a senior role in US intelligence
- The heads of national security policy and partnerships at two leading AI firms
- A former British security minister
- A former Japanese defense minister
- A former Pakistani diplomat
For nearly all of these individuals, the exposed data was comprehensive, according to WIRED: from private contact information to active login tokens. The records also contained participant lists, schedules, and links to completed questionnaires hosted by Fillout, a service Dialog used to collect information from attendees and store it in Airtable databases. Loading one of those forms returned far more information than the Dialog page itself contained, including:
- Dates of birth
- Emergency contacts
- Cell phone numbers
- The political leanings Dialog assigns to its members
- Internal rankings and grading notes
- Digital keys that serve as members' logins
WIRED reported that much of that information appeared to come directly from Dialog's Airtable records. Airtable did not respond to requests for comment. Fillout, in a statement to WIRED, said it was “not aware of any compromise of Fillout systems or active platform vulnerability.” The company said customers configure their own forms, connected data sources, and workflows, and that “the behavior of a given form depends on that configuration.”
Implications for Secure Data Handling
The Dialog incident underscores the risks of improper configuration of third-party integrations. Security experts often warn that cloud-based platforms such as Airtable and Fillout, when not properly locked down, can expose sensitive data to unintended audiences. In this case, no sophisticated hacking tools were needed — only basic browser functionality.
| Data Type | Exposed Details |
|---|---|
| Personal information | Names, contact info, dates of birth, emergency contacts |
| Authentication | Active login tokens, digital access keys |
| Internal assessments | Political leanings, ranking scores, grading notes |
| Event logistics | Participant lists, schedules, questionnaire links |
WIRED first reported on the Dialog records earlier in June. The publication also reported on documents revealing how the group privately scores attendees, weighing their wealth and prominence in decisions about admission, seating, and pricing. The current exposure adds to the reputational risk for an organization that prides itself on selectivity and confidentiality.