Hacker Stole Reddit User Data from 2007 and Earlier

Hacker Stole Reddit User Data from 2007 and Earlier

A bad actor was able to gain access to Reddit's systems through intercepting the two-factor SMS verification system.

Reddit, a popular aggregator of user rated content,  informed its users that a hacker broke into some of its systems and accessed user data, including email addresses and a 2007 database that contained usernames and passwords that were already "salted and hashed" or scrambled for protection.

Reddit sent emails to all its affected users - mostly people who joined Reddit in 2007 or earlier. The hacker was able to read the email digests Reddit sent out in June 2018 as well, so they could see the users' email addresses and relevant, safe-for-work subreddits they followed.

Reddit is recommending users who may still be using passwords similar to the ones they had in 2007 to change their password on Reddit and other websites.

The company is also encouraging users to enable token-based two-factor authentication through a service like Authy or Google's Authenticator, as the hacker gained access to Reddit's systems through an SMS intercept attack.

Between June 14th and June 18th, the hackers compromised several Reddit employee's accounts through the company's cloud provider and source cost hosts. Reddit had required two-factor authentication on its accounts but the hacker intercepted the SMS verification and was able to gain access.

The hacker could see backup data, source code and other employee logs in Reddit systems, but did not have access to changing any of it.

By June 19, Reddit discovered the attack and began investigating the extent of the damage, while ramping up security measures. Reddit contacted law enforcement and is cooperating with their investigation.

Below is the message Reddit posted for its users:

We had a security incident. Here's what you need to know. from r/announcements

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.