Reddit 2019 Account Lockouts and Forced Resets Over Credential Stuffing
January 2019
In January 2019 Reddit locked a large group of accounts after detecting unusual activity it attributed to credential stuffing, forcing affected users to reset passwords. Some users disputed the explanation, suspecting a direct compromise.
What happened
On January 10, 2019, Reddit locked out a large batch of accounts after its security team flagged anomalous sign-in activity, which the company characterized as a 'security concern.' Affected users found themselves unable to access their accounts and were required to reset their passwords — through account notifications or by filing support tickets — before access could be restored.
A Reddit administrator attributed the lockouts to credential stuffing: the same mechanism behind the 2016 incident, in which attackers replay passwords leaked from breaches at other sites against Reddit accounts, succeeding wherever users had chosen weak passwords or reused credentials across services. In effect, Reddit framed the event as a protective measure triggered by attackers testing stolen credentials, and it pointed to poor password hygiene — particularly password reuse — as the underlying vulnerability. The company advised affected users to choose strong, unique passwords and to enable two-factor authentication.
The explanation drew notable skepticism from a portion of the affected user base. Some users argued that their Reddit passwords were unique, strong, and in some cases protected by 2FA, and that such accounts should not have been exposed to credential stuffing at all. That mismatch led a number of users to suspect a more direct compromise of Reddit's systems rather than a wave of reused-credential attacks. Reporting at the time, including The Register's contemporaneous coverage, noted that no definitive public evidence settled whether the lockouts were purely the result of credential stuffing or involved some other vector, and Reddit characterized the situation only as a 'security concern' without disclosing detailed forensic evidence.
The context heightened user wariness. The lockouts came roughly five months after Reddit's confirmed August 2018 breach, in which an attacker had bypassed SMS-based 2FA and exfiltrated an old database backup. With that incident fresh in users' minds, an unexplained mass lockout attributed to user behavior rather than platform failure landed in an atmosphere of reduced trust, and the absence of detailed evidence left room for doubt about the official account.
The episode is a documented instance of Reddit using mass forced password resets as an account-takeover mitigation, and an illustration of the trust friction that arises when a platform attributes a disruptive security event to its users' password habits without publishing evidence to substantiate the explanation. Whether or not credential stuffing was the complete story, the communications dynamic — assertion without disclosure — became part of the episode's significance, showing how the framing of a security incident can be nearly as consequential to user trust as its underlying cause.
Impact
A large but unspecified number of accounts were locked and forced to reset passwords, disrupting access. The incident generated user distrust because Reddit's credential-stuffing explanation could not be independently verified, some users with strong, unique passwords reported being affected, and it arrived only about five months after the confirmed August 2018 breach — illustrating how a platform's framing of a security event, absent disclosed evidence, can itself erode trust.
Sources
- 01
- 02
- 03
What this led to
The documented consequences of this issue — the convictions, lawsuits, regulatory actions, policy changes, and bans it triggered.