Reddit 2016 Mass Password Reset After Credential-Stuffing Surge
May 2016
In May 2016, after the 2012 LinkedIn breach was revealed to have exposed roughly 117 million credentials, Reddit detected a surge in account takeovers driven by password reuse and forced password resets on about 100,000 accounts.
What happened
In late May 2016, Reddit founding engineer Christopher Slowe announced that the site had detected what he described as 'a general uptick in account takeovers (ATOs) by malicious (or at best spammy) third parties.' Over roughly the preceding two weeks, Reddit had observed a surge in compromised accounts being used for spam and abuse, and it responded by force-resetting the passwords on approximately 100,000 affected accounts.
Crucially, Reddit was clear that its own systems had not been breached. The mechanism was credential stuffing: attackers took username-and-password pairs leaked from breaches at other, unrelated services and replayed them at scale against Reddit's login system, exploiting the large number of users who reused the same email-and-password combinations across multiple sites. When a stolen pair matched a Reddit account, the attacker gained access without ever touching Reddit's infrastructure.
The timing tied the surge directly to one of the most consequential credential leaks of the era. The 2012 LinkedIn breach, long believed to have affected a relatively contained set of accounts, was revealed in May 2016 to be far larger than previously understood — approximately 117 million email-and-password combinations from that breach surfaced for sale on criminal markets. That flood of credentials powered credential-stuffing campaigns across countless platforms simultaneously, and Reddit was one of many sites that saw a corresponding spike in account takeovers as attackers tested the LinkedIn dump against other services.
In response, Reddit improved its account-takeover detection systems, completed the roughly 100,000 forced password resets, and indicated it would disable long-dormant accounts that posed elevated risk. The company also said it was weighing a broader rollout of two-factor authentication and urged users to adopt strong, unique passwords rather than reusing them across sites. The 2016 incident also coincided with a string of subreddit takeovers and defacements earlier that month, which prompted Reddit to tighten security more broadly.
The episode stands as an early, well-documented example of how a breach at a completely separate company cascades into account-takeover waves on Reddit because of the persistent problem of password reuse. It illustrated a category of harm that is not a breach of the platform itself but is nonetheless experienced by its users as one, and it foreshadowed the recurring pattern — seen again in 2019 — of Reddit using mass forced resets as a credential-stuffing mitigation while urging better password hygiene on its users.
Impact
Around 100,000 Reddit accounts were force-reset, and an unknown number had already been taken over and used for spam or abuse before detection. The episode illustrated Reddit's exposure to credential-stuffing fallout from third-party breaches such as the expanded 2012 LinkedIn leak — which exposed roughly 117 million credentials — and the limits of any single platform's defenses against attacks fueled by widespread password reuse.
Sources
- 01
- 02
- 03
- 04Wikipedia — 2012 LinkedIn hackOther2016
What this led to
The documented consequences of this issue — the convictions, lawsuits, regulatory actions, policy changes, and bans it triggered.