- Vector
- sms-2fa
- Severity
- moderate
- Records exposed
- Early adopters (2005-2007) and June 2018 email-digest recipients
- Data exposed
- Email addresses linked to usernames and old hashed passwords, raising deanonymization risk for early pseudonymous users
- Discovered
- 2018-06-19
- Disclosed
- 2018-08-01
- Date
- 2018-08-02
What happened
Beyond the technical 2FA failure, a notable harm from Reddit's 2018 breach was the threat to user anonymity. The stolen 2007 backup and the June 2018 email-digest logs both tied pseudonymous usernames to real email addresses, which for a platform built on anonymity could deanonymize early adopters and link long-lived accounts to identities. Reporters emphasized that, while passwords were salted and hashed and most early content was public, the username-to-email mapping was the more sensitive exposure. Reddit notified affected users, reset at-risk passwords and reported the matter to law enforcement. The incident illustrated that for pseudonymous communities, identity linkage can be a graver consequence than password leakage alone.