Reddit hacked in sophisticated, highly-targeted phishing attack


New Delhi, Feb 10 (IANS): Online discussion forum Reddit on Friday confirmed that its systems were hacked as a result of a sophisticated and highly-targeted phishing attack.

According to Reddit CTO Christopher Slowe, or KeyserSosa, the company became aware of the "sophisticated" attack targeting its employees on February 5.

"As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behaviour of our intranet gateway, in an attempt to steal credentials and second-factor tokens," Slowe said.

After successfully obtaining a single employee's credentials, the attacker gained access to some internal documents, code, as well as some internal dashboards and business systems.

"We show no indications of breach of our primary production systems (the parts of our stack that run Reddit and store the majority of our data)," said the CTO.

Exposure included limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information.

"We have no evidence to suggest that any of your non-public data has been accessed, or that Reddit's information has been published or distributed online," Slowe wrote in a post.

The company is continuing to investigate and monitor the situation closely and working with its employees to fortify security skills.

"The most important (and simple) measure you can take is to set up 2FA (two-factor authentication) which adds an extra layer of security when you access your Reddit account," said Reddit.

 

  

Top Stories


Leave a Comment

Title: Reddit hacked in sophisticated, highly-targeted phishing attack



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.