Search issues, trackers, people, glossary, and more
Category
Hacks, account compromises, data theft, and privacy failures affecting Reddit and its users.
As one of the world's largest websites, Reddit holds account credentials, private messages, email addresses, and behavioral data on hundreds of millions of users — making it a target. This section documents the platform's notable security incidents and privacy failures: the 2018 breach in which an attacker bypassed SMS-based two-factor authentication to access internal systems and an old 2007 database backup containing early users' credentials; the 2023 incident in which the BlackCat/ALPHV ransomware group claimed to have stolen roughly 80 gigabytes of data after a successful phishing attack on an employee; and recurring problems such as credential-stuffing account takeovers, large-scale scraping, and disputes over how Reddit collects, retains, and now licenses user data.
These entries focus on what was actually compromised, how Reddit responded and disclosed, and what the incidents reveal about the platform's security posture and its custody of user data — an area of growing importance as Reddit monetizes that data through AI-licensing deals.
A 2021 Reddit bug that printed internal removal reasons — published in a 2026 teardown — revealed the machinery behind Reddit's silent removals: an internal system called 'spamurai,' Google's Perspective API scoring private messages, TLS and browser fingerprinting, and ISP-level profiling of users.
The Netherlands' data-protection authority opened a GDPR investigation into Reddit's licensing of user content to AI developers; after Reddit allegedly stopped cooperating, it lost a court challenge in The Hague in early 2026 over the regulator's handling of privileged material.
Alan Bill, a Slovakian national, admitted helping run the Kingdom Market darknet marketplace and creating its promotional forum pages on sites including Reddit and Dread; charged in 2023, he pleaded guilty in 2026 and was sentenced to 200 months in prison.
From 10 December 2025 Australia required Reddit and nine other platforms to take reasonable steps to prevent under-16s from holding accounts, backed by penalties up to A$49.5 million and overseen by the eSafety Commissioner.
Reddit was knocked offline by two major 2025 internet-infrastructure failures: a roughly 15-hour outage on October 20, 2025 caused by an AWS US-East-1 failure, and the November 18, 2025 Cloudflare outage that triggered widespread errors across the web.
At Cannes Lions in June 2025, Reddit launched AI advertising tools under the 'Reddit Community Intelligence' brand, including features that surface users' own posts beneath brand ads and mine community conversations for marketers, reviving debate over monetizing user-generated content.
On 25 July 2025 Reddit began requiring UK users to verify their age with government ID or a face scan to view adult and other 'mature' content, triggering a backlash over privacy and over-blocking of support communities.
Around Taiwan's January 2024 election, Google's threat researchers reported that the pro-Beijing Dragonbridge network flooded platforms — Reddit among them — with pro-PRC and anti-US narratives, including AI-generated material.
Reddit's 'delete' is a soft delete: removed posts and comments vanish from public view but persist in Reddit's systems, in third-party archives that captured them at posting time, and in users' own GDPR data exports — a gap between user expectation and reality that became a documented privacy concern.
Reddit was one of nine companies ordered by the FTC to disclose its data practices for a sweeping 6(b) study; the 2024 staff report found pervasive surveillance of users and weak protections for children and teens across the industry.
As Reddit signed AI data-licensing deals worth over $200 million ahead of its March 2024 IPO, the FTC opened a non-public inquiry into Reddit's sale and licensing of user-generated content to train AI models, amid a broader backlash over monetizing users' posts without compensation or meaningful consent.
A recurring Reddit-specific scam sees criminals impersonate moderators or the 'admin team' via private messages and chat, sending fake 'verification' or 'suspension appeal' links to phishing pages that harvest credentials and 2FA codes for account takeover — and sometimes payment.
By July 2024 Reddit's robots.txt changes had blocked Bing, DuckDuckGo, Mojeek, Qwant and other engines from indexing recent Reddit content, while Google retained access under a reported $60 million annual AI-data deal — making Google effectively the only search engine able to surface fresh Reddit results.
In August 2023 Meta disclosed the largest covert influence operation it had ever found — the China-origin 'Spamouflage' network — and named Reddit among more than 50 platforms where operators seeded pro-Beijing content.
On February 5, 2023, a targeted phishing attack stole an employee's credentials and 2FA token, giving intruders access to internal documents, dashboards, source code, and employee and advertiser data. In June 2023 the BlackCat/ALPHV ransomware group publicly claimed it had taken roughly 80GB of data and demanded a $4.5 million ransom.
In 2023 Reddit terminated Pushshift's bulk data access as part of its paid-API crackdown, breaking the historical archive that powered research and the tools (Reveddit, Removeddit, Unddit) used to view deleted or removed content — reshaping who controls retained Reddit data.
Security researchers documented that the handwritten verification selfies users post to NSFW subreddits such as r/GoneWild were being scraped and manipulated by fraudsters to defeat identity-verification (KYC) systems and build synthetic identities.
A security researcher earned a $10,000 Reddit bug bounty for an OAuth flaw in Reddit's 'Sign in with Apple' flow that let an attacker hijack the account of any user who used Apple sign-in with a single click, by abusing the OAuth state parameter to steal the victim's authorization code.
In August 2020 attackers hijacked moderator accounts to deface more than 70 subreddits — including r/space, r/NFL, and r/food — with pro-Trump messaging. Reddit confirmed that none of the compromised accounts had two-factor authentication enabled.
In January 2019 Reddit locked a large group of accounts after detecting unusual activity it attributed to credential stuffing, forcing affected users to reset passwords. Some users disputed the explanation, suspecting a direct compromise.
In 2019 BuzzFeed News reported that Reddit users were observing apparently coordinated pro-China activity, with new accounts swarming threads on Tiananmen, Huawei, and Falun Gong, amid heightened scrutiny after Tencent's investment.
Between June 14–18, 2018, an attacker intercepted SMS-based two-factor authentication codes for several Reddit employees and used the access to download a complete 2007 site backup containing early users' usernames, salted-and-hashed passwords, email addresses, and all of their public and private content.
In August 2018 Reddit removed roughly 143 accounts linked to an Iran-aligned inauthentic news network exposed as 'Liberty Front Press,' which had seeded Iran-friendly content into political subreddits.
Federal prosecutors convicted four men — Ryan Collins, Edward Majerczyk, George Garofano and Emilio Herrera — for phishing schemes that compromised celebrities' iCloud and Gmail accounts; the stolen nude photos were mass-distributed on Reddit's r/TheFappening in 2014.
In May 2016 an attacker using the handle 'TehBVM' hijacked the moderator accounts behind dozens of large subreddits — including r/pics, r/gameofthrones, and r/books — and defaced them by altering CSS and banners, demonstrating how reused passwords and absent 2FA let one person seize control of major communities.
In May 2016, after the 2012 LinkedIn breach was revealed to have exposed roughly 117 million credentials, Reddit detected a surge in account takeovers driven by password reuse and forced password resets on about 100,000 accounts.
Reddit's 2015 transparency report quietly dropped its 'warrant canary' — a standing statement that it had never received a National Security Letter or other classified surveillance demand. The canary's removal signaled that Reddit had likely been served a secret government request it was legally gagged from disclosing.
Reddit hosted a cluster of communities built around sharing images of women obtained without consent — including r/photoplunder, which scraped private photos from Photobucket, and r/CandidFashionPolice — curbed largely by outside legal pressure rather than Reddit policy.
In December 2014, after the Guardians of Peace breach of Sony Pictures, Redditors used r/SonyGOP to index and link the leaked emails, scripts, salaries, and employee data — until Reddit removed the subreddit and banned its lone moderator following DMCA pressure from Sony.