{"id":607042,"date":"2023-02-11T23:49:19","date_gmt":"2023-02-12T05:49:19","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/02\/11\/reddit-confirms-it-was-hacked-recommends-users-set-up-2fa\/"},"modified":"2023-02-11T23:49:19","modified_gmt":"2023-02-12T05:49:19","slug":"reddit-confirms-it-was-hacked-recommends-users-set-up-2fa","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/02\/11\/reddit-confirms-it-was-hacked-recommends-users-set-up-2fa\/","title":{"rendered":"Reddit Confirms It Was Hacked\u2014Recommends Users Set Up 2FA"},"content":{"rendered":"<div>\n<figure role=\"presentation\"><figcaption><fbs-accordion><\/p>\n<p>Reddit confirms it has been hacked<\/p>\n<p><\/fbs-accordion><small>NurPhoto via Getty Images<\/small><\/figcaption><\/figure>\n<p>Reddit, the social news and discussion site with 50 million daily users, has <a href=\"https:\/\/www.reddit.com\/r\/reddit\/comments\/10y427y\/we_had_a_security_incident_heres_what_we_know\/\" target=\"_blank\" title=\"https:\/\/www.reddit.com\/r\/reddit\/comments\/10y427y\/we_had_a_security_incident_heres_what_we_know\/\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.reddit.com\/r\/reddit\/comments\/10y427y\/we_had_a_security_incident_heres_what_we_know\/\" aria-label=\"confirmed that it has been hacked\">confirmed that it has been hacked<\/a>. In a February 9 security incident posting on the site itself, Reddit said it first became aware of the successful breach of its systems late on February 5. In what it refers to as a &#8221; sophisticated phishing campaign that targeted Reddit employees,&#8221; the incident alert confirmed that the attacker gained access to internal documents and coder, as well as internal dashboards and business systems. However, Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Furthermore, the ongoing incident investigation has found no evidence that user passwords or accounts were accessed, the report stated.<\/p>\n<h2>Targeted employee phishing attack behind Reddit breach<\/h2>\n<p>As with all such security incidents, information is currently sparse as the breach investigation continues. However, what we do know is that, also like many such security incidents, the attackers used a targeted phishing campaign to gain access.<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2023\/01\/19\/thousands-of-paypal-accounts-hacked-is-yours-one-of-them\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2023\/01\/19\/thousands-of-paypal-accounts-hacked-is-yours-one-of-them\/\" aria-label=\"Thousands Of PayPal Accounts Breached-Is Yours One Of Them?\"><span><span>MORE FROM FORBES<\/span><span>Thousands Of PayPal Accounts Breached-Is Yours One Of Them?<\/span><small>By <span>Davey Winder<\/span><\/small><\/span><span><span><\/span><\/span><\/a><\/p>\n<p>&#8220;As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway,&#8221; the Reddit statement reads, &#8220;in an attempt to steal credentials and second-factor tokens.&#8221; It would appear that one employee was convinced, but soon realized what had happened and &#8216;self-reported&#8217; to the Reddit security teams, which sprang into action immediately.<\/p>\n<p>In the days that followed, Reddit stated that the investigation has concluded that limited contact information for current and former employees, as well as some advertiser information, was exposed. &#8220;We have no evidence to suggest that any of your non-public data has been accessed,&#8221; Reddit stated, &#8220;or that Reddit\u2019s information has been published or distributed online.&#8221;<\/p>\n<h2>Reddit recommends users set up 2FA to protect accounts<\/h2>\n<p>Nonetheless, Reddit has recommended that users take the &#8220;important and simple&#8221; measure of <a href=\"https:\/\/reddithelp.com\/hc\/en-us\/articles\/360043470031-What-is-two-factor-authentication-and-how-do-I-set-it-up-\" target=\"_blank\" title=\"https:\/\/reddithelp.com\/hc\/en-us\/articles\/360043470031-What-is-two-factor-authentication-and-how-do-I-set-it-up-\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/reddithelp.com\/hc\/en-us\/articles\/360043470031-What-is-two-factor-authentication-and-how-do-I-set-it-up-\" aria-label=\"setting up two-factor authentication\">setting up two-factor authentication<\/a> (2FA) on their accounts. While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that&#8217;s not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. Indeed, I&#8217;d recommend that you use a password manager to create a random and strong password or pass-phrase, 1Password makes this process very easy indeed, for example.<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2023\/01\/21\/no-paypal-hasnt-been-hacked-yet-almost-35000-accounts-were-breached\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2023\/01\/21\/no-paypal-hasnt-been-hacked-yet-almost-35000-accounts-were-breached\/\" aria-label=\"This Is How Hackers Accessed 34,942 PayPal Accounts\"><span><span>MORE FROM FORBES<\/span><span>This Is How Hackers Accessed 34,942 PayPal Accounts<\/span><small>By <span>Davey Winder<\/span><\/small><\/span><span><span><\/span><\/span><\/a><\/p>\n<p>I would, however, also recommend changing your Reddit account password despite there being no evidence that these have been compromised in this particular incident. As recent high-profile breaches have taught us, <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2022\/12\/23\/lastpass-password-vaults-stolen-by-hackers-change-your-master-password-now\/\" target=\"_self\" title=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2022\/12\/23\/lastpass-password-vaults-stolen-by-hackers-change-your-master-password-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2022\/12\/23\/lastpass-password-vaults-stolen-by-hackers-change-your-master-password-now\/\" aria-label=\"new evidence can come to light weeks or months after the initial attack\" rel=\"noopener\">new evidence can come to light weeks or months after the initial attack<\/a> and investigation, so a better safe than sorry approach harms nobody.<\/p>\n<p>I have reached out to Reddit for further comment and will update this developing story in due course.<\/p>\n<p><em>Updated February 10 at 04.40 ET <\/em><\/p>\n<p><em>Javvad Malik, lead security awareness advocate at KnowBe4, said: &#8220;We see in this incident that despite apparently having multi-factor authentication, a user was still phished, serving as a timely reminder that no single layer of protection will be completely fool proof. Perhaps the biggest takeaway for organisations from this incident is that the user that was phished realised their error and reported the issue which allowed Reddit&#8217;s security team to quickly investigate the issue. This is why user training is so important, so that people can not only identify a phishing email, but know how to report it.&#8221;<\/em><\/p>\n<\/div>\n<div>\n<p><span>Follow me on\u00a0<\/span><a href=\"https:\/\/www.twitter.com\/happygeek\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Twitter<\/a>\u00a0or\u00a0<a href=\"https:\/\/www.linkedin.com\/in\/happygeek\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">LinkedIn<\/a>.\u00a0<span>Check out\u00a0<\/span>my\u00a0<a href=\"https:\/\/www.happygeek.com\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">website<\/a>\u00a0or\u00a0some of my other work\u00a0<a href=\"https:\/\/authory.com\/DaveyWinder\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">here<\/a>.\u00a0<\/p>\n<\/div>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2023\/02\/10\/reddit-confirms-it-was-hacked-recommends-users-set-up-2fa\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Davey Winder<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Reddit confirms it has been hackedNurPhoto via Getty Images Reddit, the social news and discussion site with 50 million daily users, has confirmed that it has been hacked. In a February 9 security incident posting on the site itself, Reddit said it first became aware of the successful breach of its systems late on February<\/p>\n","protected":false},"author":1,"featured_media":607043,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2548,239],"tags":[],"class_list":{"0":"post-607042","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-confirms","8":"category-reddit"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/607042","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=607042"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/607042\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/607043"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=607042"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=607042"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=607042"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}