Social news aggregation platform Reddit suffered a security breach in which the threat actors gained unauthorized access to internal documents, code, and some business systems.
Reddit announced that a sophisticated and highly-targeted phishing attack hit the employees of the company. However, the Reddit user passwords and accounts were not compromised.
The spear-phishing messages redirected users to a website imitating the company’s intranet gateway, and the landing page was designed to trick victims into providing credentials and second-factor tokens.
After one employee fell victim to the phishing attack, the threat actors gained access to some internal docs, code, as well as some internal dashboards and business systems. The primary production systems of the company were not compromised.
The company became aware of the attack on February 5th when the phished employee self-reported. They immediately launched an internal investigation to determine the extent of the incident.
Based on several days of initial investigation by security, engineering, and data science, the company found no evidence to suggest that any of the non-public data has been accessed, or that Reddit’s information has been published or distributed online.
Reddit has also set up a 2FA (two-factor authentication) to increase the security of users’ accounts.















Comments