Skip to main content

Attacker stole user data from Reddit through employee accounts

GongTo/Shutterstock

An official update posted by Reddit reveals that an attacker broke into a few systems on the company’s network and stole user data. The theft consisted of a 2007 database backup containing salted hashed passwords along with “some” current email addresses. Reddit is currently working with law enforcement as they investigate the breach.

According to Reddit, the leaked database backup includes usernames and salted hashed passwords used between the site’s launch in 2005 through May 2007. It also includes email addresses, public content and private messages. Reddit users with data contained in this backup will be notified to reset their passwords. Those who created a Reddit account after May 2007 are not affected in this specific portion of the breach.

If you’re not familiar with the “hash” term, hashing converts a password into a value with a fixed length that cannot be reversed without lots of computing power. “Salting” means throwing an additional, random secret value into a password so that hackers can’t use dictionary attacks. Servers create a new randomly-generated salt for each password and hashes them together using cryptography.

Image used with permission by copyright holder

Reddit also said the attacker gained access to email digests from noreply@redditmail.com sent between June 3 and June 17, 2018. As shown above, the digests connect usernames to email addresses and also highlights subscribed subreddits. Those who don’t associate their email address to their Reddit account and/or unchecked the “email digests” option in their account are not affected.

Still, that’s not all. Because the hacker had read access to Reddit’s storage systems, the attacker obtained source code, internal logs, configuration files and employee workspace files. On the end-user side, the 2007 database and email digests were the source of the attacker’s treasure trove.

How did the attacker infiltrate Reddit? Through “a few” compromised employee accounts tied to Reddit’s cloud and source code hosting providers. These accounts were protected by two-factor authentication through SMS messaging, which isn’t the most secure form of credential verification. Reddit suggests everyone move to token-based two-factor authentication like facial recognition, fingerprint scanning, and USB-based keys.

“Although this was a serious attack, the attacker did not gain write access to Reddit systems; they gained read-only access to some systems that contained backup data, source code and other logs,” the company reports. “They were not able to alter Reddit information, and we have taken steps since the event to further lock down and rotate all production secrets and API keys, and to enhance our logging and monitoring systems.”

Reddit discovered the breach on June 19, which took place between June 14 and June 18. After discovering the breach, Reddit worked with its cloud and source code hosting partners to understand what the attacker accessed. The company also reported the hack to law enforcement and began messaging user accounts. Reddit took additional steps to better secure its network as well.

Reddit suggests that users reconsider their passwords if they’ve been in use for years on the site and/or elsewhere. Reddit also suggests using strong, unique passwords and authenticator apps to take advantage of the site’s two-factor authentication feature.

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
One of Lenovo’s best-selling ThinkPad laptops is 45% off today
Lenovo ThinkPad X1 Carbon Gen 12 front angled view showing display and keyboard.

If you're on browsing through laptop deals for a machine that will immensely help in boosting your productivity, you may want to check out Lenovo's offer for the popular Lenovo ThinkPad X1 Carbon Gen 11. It's a powerful device so its original price is $3,319, but a 45% discount from Lenovo brings it down to a more reasonable $1,825. That's $1,494 in savings that you'll be able to spend on software and accessories, but you're going to have to proceed with the purchase right now if you want to make sure that you get it because this is a clearance sale, so there's no guarantee that stocks will still be available tomorrow.

Why you should buy the Lenovo ThinkPad X1 Carbon
The Lenovo ThinkPad X1 Carbon Gen 11 challenges the performance of the best laptops with its 13th-generation Intel Core i7 processor, integrated Intel Iris Xe Graphics, and 16GB of RAM that our guide on how much RAM do you need says is similar to what you'll find in top-tier machines. The device comes with a 14-inch touchscreen with WUXGA resolution for sharp details and bright colors, a 1TB SSD for ample storage space for your files, and Windows 11 Pro pre-installed so that you can access the more advanced capabilities of the operating system.

Read more
The world’s first 8K mini-LED monitor has arrived
The Asus ProArt PA32KCX 8K mini-LED professional monitor placed on a desk next to a workstation PC.

When it comes to the best professional-grade monitors, resolution, brightness, and color accuracy are all paramount. Asus is aiming to ace all three (and a lot more) with its newly announced ProArt PA32KCX, which is also the world’s first 8K mini-LED professional monitor.

The 8K resolution is the standout spec, of course. The monitor has a resolution of 7680 x 4320 across its 32-inch screen. One of the only other 8K monitors available that you actually buy is the Dell UltraSharp UP3218K, which came out in 2017.

Read more
This new VR headset beats the Vision Pro in one key way and is half the price
Pimax Crystal Super and Light VR headsets appear on a dark background.

While the Apple Vision Pro offers ultra-high-resolution displays with 23 million pixels, the staggering $3,500 price might inspire you to look for Vision Pro alternatives.

Good news: Pimax just announced two new VR headsets, including a budget model that costs as low as $799 and a more advanced version starting at $1,799. Both are based on the design of one of the best VR headsets currently available -- the Pimax Crystal that launched in May 2023 for $1,599 -- but come with a serious upgrade in terms of resolution.
Pimax Crystal Super

Read more