August 2020 Coordinated Pro-Trump Defacement via Hijacked Moderator Accounts
- Vector
- credential-stuffing
- Severity
- moderate
- Records exposed
- More than 50 subreddits defaced through compromised moderator accounts
- Data exposed
- Subreddit control (CSS, wikis, moderator removals); no user database accessed
- Attacker
- Unidentified actor(s); a Twitter account claimed responsibility
- Discovered
- 2020-08-07
- Disclosed
- 2020-08-07
- Date
- 2020-08-07
What happened
On August 7, 2020, attackers hijacked moderator accounts to deface more than 50 subreddits, including r/space, r/NFL and r/BlackPeopleTwitter, plastering them with pro-Trump messaging such as 'We Stand With Donald Trump #MIGA2020.' After seizing accounts, the intruders changed subreddit CSS, edited wikis and removed lower-permission moderators. Reddit confirmed the source was compromised moderator accounts and said the attackers exploited weak, guessable passwords on accounts that lacked two-factor authentication. Admins urged moderators to enable 2FA and change passwords while they reverted the changes and locked out the bad actors. The episode underscored how unprotected moderator accounts could be weaponized at scale.