Reddit has confirmed hackers accessed internal documents and source code following a “highly-targeted” phishing attack. From a report: A post by Reddit CTO Christopher Slowe, or KeyserSosa, explained that the company became aware of the “sophisticated” attack targeting Reddit employees on February 5. He says that an as-yet-unidentified attacker sent “plausible-sounding prompts,” which redirected employees to a website masquerading as Reddit’s intranet portal in an attempt to steal credentials and two-factor authentication tokens.

Slowe said that “similar phishing attempts” have been reported recently, without naming specific examples, but likened the breach to the recent Riot Games hack, which saw attackers use social engineering tactics to access source code for the company’s legacy anti-cheat system. Reddit said that hackers successfully obtained an employee’s credentials, allowing them to gain access to internal documents and source code, as well as some internal dashboards and business systems. Slowe said the company learned of the

Link to original post https://it.slashdot.org/story/23/02/10/1425236/reddit-says-hackers-accessed-employee-data-following-phishing-attack?utm_source=rss1.0mainlinkanon&utm_medium=feed from Teknoids News

Read the original story