{"id":5122,"date":"2023-02-10T10:27:24","date_gmt":"2023-02-10T10:27:24","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/02\/10\/reddit-says-hackers-accessed-internal-data-following-employee-phishing-attack\/"},"modified":"2023-02-10T10:27:24","modified_gmt":"2023-02-10T10:27:24","slug":"reddit-says-hackers-accessed-internal-data-following-employee-phishing-attack","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/02\/10\/reddit-says-hackers-accessed-internal-data-following-employee-phishing-attack\/","title":{"rendered":"Reddit says hackers accessed internal data following employee phishing attack"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<div class=\"article__featured-image-wrapper breakout\">\n\t\t\t\n\t\t<\/div>\n<\/p><\/div>\n<div>\n<p id=\"speakable-summary\">Reddit has confirmed hackers accessed internal documents and source code following a \u201chighly-targeted\u201d <a href=\"https:\/\/techcrunch.com\/tag\/phishing\/\" target=\"_blank\" rel=\"noopener\">phishing<\/a> attack.<\/p>\n<p>A <a href=\"https:\/\/www.reddit.com\/r\/redditsecurity\/comments\/10y44g0\/we_had_a_security_incident_heres_what_we_know\/\" target=\"_blank\" rel=\"noopener\">post by Reddit CTO Christopher Slowe<\/a>, or KeyserSosa, explained that the company became aware of the \u201csophisticated\u201d attack targeting <a href=\"https:\/\/techcrunch.com\/tag\/reddit\/\" target=\"_blank\" rel=\"noopener\">Reddit<\/a> employees on February 5.\u00a0He says that an as-yet-unidentified attacker sent \u201cplausible-sounding prompts\u201d\u00a0that redirected employees to a website masquerading as Reddit\u2019s intranet portal in an attempt to steal credentials and\u00a0<a href=\"https:\/\/techcrunch.com\/tag\/two-factor-authentication\/\" target=\"_blank\" rel=\"noopener\">two-factor authentication<\/a>\u00a0tokens.<\/p>\n<p>Slowe said that \u201csimilar phishing attempts\u201d have been reported recently, without naming specific examples. However, he likened the breach to the recent <a href=\"https:\/\/techcrunch.com\/2023\/01\/24\/riot-games-hack-cheaters\/\" target=\"_blank\" rel=\"noopener\">Riot Games hack<\/a>, which saw attackers use social engineering tactics to access source code for the company\u2019s legacy anticheat system.<\/p>\n<p>Reddit said that hackers successfully obtained a single employee\u2019s credentials, enabling them to gain access to gained access internal documents and source code as well as some internal dashboards and business systems.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>Slowe said the company learned of the breach after the phished employee self-reported the incident to Reddit\u2019s security team, enabling it quickly cut off the infiltrators\u2019 access and commence an internal investigation.<\/p>\n<p>Reddit, which has more than 50 million daily uses, said its investigation has concluded that limited contact information for \u201chundreds\u201d of current and former employees, as well as some advertiser information, was also accessed.\u00a0However, the company says it has \u201cno evidence\u201d to suggest that personal user data and other non-public data has been stolen, published, or distributed online.<\/p>\n<p>Regardless, Reddit has recommended that all users set up 2FA on their accounts and use a <a href=\"https:\/\/techcrunch.com\/2018\/12\/25\/cybersecurity-101-guide-password-manager\/\" target=\"_blank\" rel=\"noopener\">password manager<\/a>.<span class=\"Apple-converted-space\">\u00a0\u201cBesides providing great complicated passwords, they provide an extra layer of security by warning you before you use your password on a phishing site,\u201d Slowe says.\u00a0<\/span><\/p>\n<p>\u201cWe\u2019re continuing to investigate and monitor the situation closely and working with our employees to fortify our security skills,\u201d he added. \u201cAs we all know, humans are often the weakest part of the security chain.\u201d<\/p>\n<p>Reddit suffered <a href=\"https:\/\/techcrunch.com\/2018\/08\/01\/reddit-breach-exposes-user-data-but-not-much\/\" target=\"_blank\" rel=\"noopener\">a more serious data breach in 2018<\/a> that saw attackers access a<span class=\"Apple-converted-space\">\u00a0<\/span>complete copy of Reddit data from 2007, comprising the first two years of the site\u2019s operations. This includes usernames, hashed passwords, emails, public posts and private messages.<\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2023\/02\/10\/reddit-says-hackers-accessed-internal-data-following-employee-phishing-attack\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Reddit has confirmed hackers accessed internal documents and source code following a \u201chighly-targeted\u201d phishing attack. A post by Reddit CTO Christopher Slowe, or KeyserSosa, explained that the company became aware of the \u201csophisticated\u201d attack targeting Reddit employees on February 5.\u00a0He says that an as-yet-unidentified attacker sent \u201cplausible-sounding prompts\u201d\u00a0that redirected employees to a website masquerading as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5123,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-5122","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/5122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=5122"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/5122\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/5123"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=5122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=5122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=5122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}