Reddit Confirms It Was Hacked—Recommends Users Set Up 2FA

Reddit confirms it has been hacked

NurPhoto via Getty Images

Reddit, the social news and discussion site with 50 million daily users, has confirmed that it has been hacked. In a February 9 security incident posting on the site itself, Reddit said it first became aware of the successful breach of its systems late on February 5. In what it refers to as a ” sophisticated phishing campaign that targeted Reddit employees,” the incident alert confirmed that the attacker gained access to internal documents and coder, as well as internal dashboards and business systems. However, Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Furthermore, the ongoing incident investigation has found no evidence that user passwords or accounts were accessed, the report stated.

Targeted employee phishing attack behind Reddit breach

As with all such security incidents, information is currently sparse as the breach investigation continues. However, what we do know is that, also like many such security incidents, the attackers used a targeted phishing campaign to gain access.

MORE FROM FORBESThousands Of PayPal Accounts Breached-Is Yours One Of Them?By Davey Winder

“As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway,” the Reddit statement reads, “in an attempt to steal credentials and second-factor tokens.” It would appear that one employee was convinced, but soon realized what had happened and ‘self-reported’ to the Reddit security teams, which sprang into action immediately.

In the days that followed, Reddit stated that the investigation has concluded that limited contact information for current and former employees, as well as some advertiser information, was exposed. “We have no evidence to suggest that any of your non-public data has been accessed,” Reddit stated, “or that Reddit’s information has been published or distributed online.”

Reddit recommends users set up 2FA to protect accounts

Nonetheless, Reddit has recommended that users take the “important and simple” measure of setting up two-factor authentication (2FA) on their accounts. While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that’s not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. Indeed, I’d recommend that you use a password manager to create a random and strong password or pass-phrase, 1Password makes this process very easy indeed, for example.

MORE FROM FORBESThis Is How Hackers Accessed 34,942 PayPal AccountsBy Davey Winder

I would, however, also recommend changing your Reddit account password despite there being no evidence that these have been compromised in this particular incident. As recent high-profile breaches have taught us, new evidence can come to light weeks or months after the initial attack and investigation, so a better safe than sorry approach harms nobody.

I have reached out to Reddit for further comment and will update this developing story in due course.

Updated February 10 at 04.40 ET

Javvad Malik, lead security awareness advocate at KnowBe4, said: “We see in this incident that despite apparently having multi-factor authentication, a user was still phished, serving as a timely reminder that no single layer of protection will be completely fool proof. Perhaps the biggest takeaway for organisations from this incident is that the user that was phished realised their error and reported the issue which allowed Reddit’s security team to quickly investigate the issue. This is why user training is so important, so that people can not only identify a phishing email, but know how to report it.”

Follow me on Twitter or LinkedInCheck out my website or some of my other work here

Read More
Davey Winder

Latest

Moog Technology Successfully Steers Artemis II Launch

You have been rate-limited for making too many requests in a short time frame. Website owner? If you think you have reached this message in error, please contact support.

Ex-Turnstile Member Brady Ebert Faces Serious Legal Trouble with Attempted Murder Charge

Brady Ebert, a foundational figure in the Grammy Award-winning band Turnstile, has been arrested on charges of attempted second-degree murder. According to police records accessed by the Daily Mail, the 33-year-old guitarist was apprehended on Tuesday, March 31, in Montgomery County, Maryland. Beyond the attempted murder charge, Ebert faces an additional count of assault in

Paraguay ends quiniela monopoly as two suitors advance to final stage

Time to read: 3 min Paraguay ends quiniela monopoly as two suitors advance to final stage April 2, 2026 ShutterStock_Paraguay Paraguay’s quiniela tender has entered its final phase, with the domestic incumbents of Technologies Development of Paraguay (TDP) SA and the Daruma Sam Alliance confirmed as the remaining bidders of the lotto games franchise. Launched

Unraveling the Fate of Peter Parker: Could ‘Brand New Day’ Spell His End?

The conclusion of “Spider-Man: No Way Home” shakes up the narrative in a dramatic way. Following a whirlwind of multiverse chaos, Spider-Man, played by Tom Holland, turns to Doctor Strange, portrayed by Benedict Cumberbatch, with a desperate plea to erase the world’s memory of Peter Parker. The spell succeeds, sending the villains back to their

Newsletter

Don't miss

Moog Technology Successfully Steers Artemis II Launch

You have been rate-limited for making too many requests in a short time frame. Website owner? If you think you have reached this message in error, please contact support.

Ex-Turnstile Member Brady Ebert Faces Serious Legal Trouble with Attempted Murder Charge

Brady Ebert, a foundational figure in the Grammy Award-winning band Turnstile, has been arrested on charges of attempted second-degree murder. According to police records accessed by the Daily Mail, the 33-year-old guitarist was apprehended on Tuesday, March 31, in Montgomery County, Maryland. Beyond the attempted murder charge, Ebert faces an additional count of assault in

Paraguay ends quiniela monopoly as two suitors advance to final stage

Time to read: 3 min Paraguay ends quiniela monopoly as two suitors advance to final stage April 2, 2026 ShutterStock_Paraguay Paraguay’s quiniela tender has entered its final phase, with the domestic incumbents of Technologies Development of Paraguay (TDP) SA and the Daruma Sam Alliance confirmed as the remaining bidders of the lotto games franchise. Launched

Unraveling the Fate of Peter Parker: Could ‘Brand New Day’ Spell His End?

The conclusion of “Spider-Man: No Way Home” shakes up the narrative in a dramatic way. Following a whirlwind of multiverse chaos, Spider-Man, played by Tom Holland, turns to Doctor Strange, portrayed by Benedict Cumberbatch, with a desperate plea to erase the world’s memory of Peter Parker. The spell succeeds, sending the villains back to their

Marvel Studios Plans SDCC Return After Years, Does It Mean a 3 Month Wait for the Doomsday Trailer?

Though they’re known for absolutely bringing the house down at the event, Marvel Studios doesn’t have a consistent track record when it comes to actually attending San Diego Comic-Con. Over the years, they’ve managed to become the highlight of the event, forcing attendees to camp out days ahead of time in order to just be

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business