May 2016 Defacement of 70+ Subreddits via Hijacked Moderator Accounts (TehBVM)
- Vector
- credential-stuffing
- Severity
- moderate
- Records exposed
- More than 70 subreddits defaced through compromised moderator accounts
- Data exposed
- Subreddit control (CSS, wikis, moderator lists); no user database accessed
- Attacker
- Individual using the handle TehBVM
- Discovered
- 2016-05-04
- Disclosed
- 2016-05-10
- Date
- 2016-05-10
What happened
In May 2016 a person operating under the handle TehBVM hijacked moderator accounts to deface more than 70 subreddits, including large communities such as r/pics, r/books and r/StarWars. The intruder altered subreddit stylesheets and wikis and toyed with the communities, saying it was done out of boredom and denying the use of brute force, which suggested replayed or reused passwords against accounts that lacked strong protection. Reddit, which then did not offer broad two-factor authentication for ordinary users, said it took user and moderator security seriously and would build features to bolster account safety. Real moderators regained control, and users were advised to change passwords. The incident foreshadowed the larger 2020 moderator-account takeover.