An attacker broke into Reddit systems and accessed user data, email addresses, and a database of hashed passwords from 2007.

Dark Reading Staff, Dark Reading

August 2, 2018

1 Min Read

If you haven't changed your Reddit password since 2007, now would be a good time.

Reddit today disclosed a security incident discovered on June 19, 2018. The company reports that between June 14 and 18, 2018, an attacker compromised employee accounts held with its cloud and source code hosting providers. It reports two-factor authentication was in place.

"Already having our primary access points for code and infrastructure behind strong authentication requiring two factor authentication (2FA), we learned that SMS-based authentication is not nearly as secure as we would hope, and the main attack was via SMS intercept," Reddit reports in a blog post, encouraging token-based 2FA.

The attacker did not gain write access to Reddit systems, the report continues, but did manage to infiltrate two key areas of user data: all Reddit data from 2007 and before, including account credentials and email addresses, as well as email digests Reddit sent in June 2018.

Because the attacker also had read access to Reddit's storage systems, he or she could reach other data including Reddit source code, internal logs, configuration files, and other employee workspace files. Reddit has reported the breach to law enforcement and is alerting affected users to change their passwords, whether or not they're currently using the site.

Read more details here.

Horizontal-334031_BH_US18_banners_468x60_non_1.png

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights