HackingStolen CredentialsDelayed DiscoveryCREDENTIALSPIILowResolved
REDDIT, INC.
bd_2849fc4adc933721 · schema v1 · pii pii-v1
Full breach record for REDDIT, INC. →Reddit, Inc. reported a 2018 security incident where an attacker accessed account credentials (usernames and salted password hashes) from 2007. The company notified affected users to reset passwords. The breach was discovered in June 2018.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-139569
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2018
- Raw hash
- f472cd76d13313084048a4b8281b46e6fcc01ab7a7c4e81abc54045bc77cfe31
Reporting entity
- Name
- REDDIT, INC.norm: reddit
- Domain
- reddit.com
Victim entity
- Name
- REDDIT, INC.norm: reddit
- Domain
- reddit.com
Incident
- Discovered
- Jun 19, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.