Reddit discloses security breach: what you need to know
#1
Exclamation 
Quote:Reddit disclosed a security breach today on the site stating that a malicious actor managed to gain access to internal servers.


[Image: reddit-security-incident-phishing.png]

The company became aware of a phishing campaign that targeted Reddit employees specifically on February 5, 2023. The campaign used "plausible sounding prompts" to get employees of the site to a phishing website that looked like the company's intranet gateway.

Employees who entered their login credentials on that fake website would provide the attackers with the credentials and also second-factor tokens.

At least one employee of the site feel for the phishing ruse, giving the attacker access to "some internal docs, code, as well as some internal dashboards and business systems". Investigators of the incident found no evidence that the attacker managed to gain access to "primary production systems", which hold the majority of data, including Reddit user data. No evidence has been found up to this point that suggests that the attacker managed to gain access to non-public user data, such as email addresses, saved posts or conversations, or the "Reddit information has been published or distributed".

The employee who fell for the phishing attack reported the incident to the Security team, according to Reddit "soon after being phished". Reddit's security team changed the status of the account, removing access to systems. The attacker could no longer access Reddit systems after the change was made.

The investigation is still ongoing and Reddit did not provide details on the information that the attacker managed to obtain while having access to company servers.

Reddit suggests that users of the site enable two-factor authentication, if they have not done so already. The post links to a support article that explains how Reddit users may enable the extra layer of protection on the site.

It needs to be noted that two-factor authentication did not prevent the phishing attack against the Reddit employee. If specifically targeted, two-factor authentication does not provide 100% protection. The security feature helps, however, when user databases with passwords are copied by attackers, as the attackers would need to obtain two-factor authentication codes from particular users if they manage to break the passwords of the database.

Closing Words

It remains to be seen if Reddit's initial assessment of the security breach holds. The company analyzed the security incident for several days already, but there is always a chance that additional evidence is found at a later stage in the investigation.

Now You: do you use Reddit?
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Revo Registry Cleaner
Revo Registry Cleane...jasonX — 18:11
GFYI [Official] Master PDF Editor Mothe...
It lets me edit, com...zevish — 09:52
XYplorer
What's new in Rele...Kool — 07:35
AMD releases updated FidelityFX SDK feat...
FidelityFX SDK 1.1...harlan4096 — 06:44
AnyDesk 9.5.2 for Windows
AnyDesk 9.5.2 for ...harlan4096 — 06:42

[-]
Birthdays
Today's Birthdays
avatar (38)omapek
avatar (47)Geraldtuh
Upcoming Birthdays
avatar (27)akiratoriyama
avatar (47)Jerrycix
avatar (39)awedoli
avatar (81)WinRARHowTo
avatar (37)owysykan
avatar (48)beautgok
avatar (38)axuben
avatar (44)talsmanthago
avatar (30)mocetor
avatar (45)piomaibhaict
avatar (50)kingbfef
avatar (37)izenesiq
avatar (39)ihijudu
avatar (44)tiojusop
avatar (41)Damiennug
avatar (39)acoraxe
avatar (48)contjrat
avatar (40)axylisyb
avatar (43)tukrublape
avatar (43)knigiJow
avatar (45)1stOnecal
avatar (49)Mirzojap
avatar (35)idilysaju
avatar (39)GregoryRog
avatar (44)mediumog
avatar (39)odukoromu
avatar (45)Joanna4589

[-]
Online Staff
jasonX's profile jasonX
Administrator
zevish's profile zevish

>