Data leak

CPO Magazine / CSHub / SecurityWeek

πŸ“… 2023-02-05 🏒 Reddit internal systems
Primary Source β†—

Incident Details

Attacker sent convincing phishing email mimicking Reddit IT, tricked employee into entering credentials and TOTP codes in real time on fake login page. Accessed internal documents, dashboards, business systems, Jira, source code, employee/contractor contact info, advertiser data. ALPHV/BlackCat claimed responsibility June 2023, claimed 80GB stolen, demanded $4.5M ransom plus withdrawal of API pricing changes. Reddit refused to pay. No evidence production systems or user passwords compromised.

Technical Details

Initial Attack Vector
CWE-1021: Improper Restriction of Rendered UI (targeted spear-phishing with real-time TOTP relay against single employee)
Vendor / Product
Reddit internal systems

Timeline

  1. 2023-02-05 Breach occurred
  2. 2023-02-09 Publicly disclosed
  3. 2023-02-09 Customers notified