Reddit Hit By Phishing Attack, Source Code Stolen

Reddit suffered a cyberattack on February 5, 2005 after its internal systems were compromised. This was due to a “sophisticated” and “targeted” phishing attack that led to the exposure of employee credentials.

“In an attempt to steal credentials and second-factor tokens, attackers sent plausible-sounding prompts directing employees to a website that replicated the behavior of our intranet gateway,” the company said. . I have written on thursday.

“After obtaining the credentials of one employee, the attackers gained access to internal documents, code, and internal dashboards and business systems.”

But Reddit says there were “no indications” that the company’s main production system, where most of its data is stored, was compromised.

“The exposure included limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information,” the disclosure reads. .

“Based on several days of initial research by security, engineering and data science (and friends), there is evidence to suggest that your non-public data has been accessed or information on Reddit has been published or distributed online. there is no. “

according to cyber smart According to CEO Jamie Akhtar, the breach is a perfect example of the adage, “Employees are your most valuable security asset.”

“Even though Reddit had good technical security controls, cybercriminals were able to breach its defenses simply by targeting its staff,” Akhtar said. Information security on mail.

“Training helps employees become better aware and understand the threats they face and, more importantly, learn how to avoid them in the first place.”

Erfan Shadabi, Cybersecurity Expert, Data Security Specialist Comfort AGagreed with Akhtar’s point, adding that a culture of data security and privacy must be sponsored from the top down.

“[This], together with a corporate culture that encourages employees to analyze requests for sensitive data, can turn this ever-present phishing attack trend. “

The Reddit breach comes months after security firm Cerby published a report suggesting security shortcomings on Reddit and other social media sites. It can lead to misinformation.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *