All incidents
credential-stuffingmoderate
January 2019 Account Lockouts and Forced Resets Over Credential Stuffing
- Vector
- credential-stuffing
- Severity
- moderate
- Records exposed
- A large group of accounts locked and forced to reset passwords (count not disclosed)
- Data exposed
- No new Reddit breach; attackers attempted logins using credentials reused from other sites
- Discovered
- 2019-01-09
- Disclosed
- 2019-01-10
- Date
- 2019-01-10
What happened
In January 2019 Reddit again locked a large group of accounts and triggered forced password resets after spotting unusual login activity consistent with credential stuffing. An admin (Sporkicide) explained that the most common cause was very simple passwords or reused credentials harvested from other sites' breaches, rather than any compromise of Reddit itself. Users with poor password hygiene were temporarily locked out and asked to reset before regaining access. Reddit urged affected users to pick strong, unique passwords and to enable two-factor authentication. The episode echoed the company's 2016 credential-stuffing response and followed its 2018 breach disclosure.