Reddit was hacked via phishing campaign that yielded employee login credentials

Spread the love

Reddit has suffered a hack of its systems. According to the company, a phishing campaign was conducted targeting Reddit employees. The login details of an employee were obtained, after which the attacker gained access to the systems.

Reddit writes that it became aware on February 5 that a “sophisticated phishing campaign” was underway, sending “credible prompts” to employees. They redirected to a website that “cloned the behavior of our intranet gateway.”

Ultimately, the attacker managed to get hold of an employee’s data, gaining access to “some internal documents, code, and some internal dashboards and business systems.” The attacker also gained access to hundreds of company contacts and the details of former and current employees, in addition to “limited advertiser information,” Reddit reports.

Based on an investigation that took several days, Reddit says there is no evidence that non-public user data has been accessed, nor has any Reddit information been published or distributed.

Reddit writes that users’ passwords and accounts are safe. The discussion platform also reports that there are no indications that primary systems have been accessed. This concerns the systems that Reddit partly runs on and where the majority of the data is stored.

You might also like