Reddit Admits It Was Hacked in Phishing Attack


Image for article titled Reddit Says It Was Hacked But That You Don't Need to Worry About It. Probably.

Photo: Diego Thomazini (Shutterstock)

Reddit says that it was hacked earlier this month, in a security incident that compromised some company data. However, the company says that Redditors have no need to fear because user data was not impacted by the episode—at least, that the company knows of…“so far.”

In a thread posted to the official r/reddit community on Thursday, a company rep explained that a phishing attack had taken place on the evening of Feb. 5. “Based on our investigation so far, Reddit user passwords and accounts are safe, but on Sunday night (pacific time), Reddit systems were hacked as a result of a sophisticated and highly-targeted phishing attack,” the statement reads. “They gained access to some internal documents, code, and some internal business systems.”

The hacker, whoever they were, managed to trick a Reddit employee into clicking on a “plausible-sounding” prompt that forwarded them to a “website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens.” After the hacker nabbed the user’s login credentials, they used them to access “some internal docs, code, as well as some internal dashboards and business systems,” as the company puts it.

In its statement, Reddit stresses that it doesn’t think users were impacted by the digital intrusion. “Based on several days of initial investigation by security, engineering, and data science (and friends!), we have no evidence to suggest that any of your non-public data has been accessed, or that Reddit’s information has been published or distributed online,” the company says. Reddit used the opportunity to encourage Redditors to beef up their personal account security. “Since we’re talking about security and safety, this is a good time to remind you how to protect your Reddit account…Learn how to enable 2FA in Reddit Help.”

When it comes to minor data breaches, this isn’t Reddit’s first rodeo. In fact, approximately five years ago the platform posted a thread with an identical headline, announcing that it had been hacked in a somewhat similar way. It’s good that Reddit is being transparent and candid with users about this incident, although “we don’t think any of your data was stolen” has an unfortunate habit of being what a company says before a larger breach is announced. That said, there’s no indication that that’s the case here—you know, so far.



Source link: https://gizmodo.com/reddit-cyberattack-phishing-data-breach-cybersecurity-1850096804

Sponsors

spot_img

Latest

2024 New Zealand Super Rugby jerseys revealed

It’s out with the Adidas and in with the Classic Sportswear for New Zealand Super Rugby teams in 2024, and Wednesday provides...

Canoo made a cute trio of EVs to carry NASA’s Artemis 2 astronauts to the SLS

Electric vehicle startup Canoo has delivered its first shipment to NASA. This week, a trio of the company’s Crew Transportation Vehicles (CTVs) arrived...

Why Personal Branding Matters for Entrepreneurs

Opinions expressed by Entrepreneur contributors are their own. ...

Pere Riba recounts Rafael Nadal ‘dominating’ in juniors but still being ‘so humble’

Pere Riba recounts Rafael Nadal 'dominating' in juniors but still being 'so humble' © Getty Images Sport - Sarah Stier Pere Riba remembers Rafael...

Who played the most games for the Boston Celtics in their storied history?

The folks over at our sister site HoopsHype share our predilection for all things NBA history and put together all sorts of accounts...