Reddit 2023 Breach: Employee Phishing, 80GB Exfiltrated, BlackCat/ALPHV Ransom Demand
February–June 2023
On February 5, 2023, a targeted phishing attack stole an employee's credentials and 2FA token, giving intruders access to internal documents, dashboards, source code, and employee and advertiser data. In June 2023 the BlackCat/ALPHV ransomware group publicly claimed it had taken roughly 80GB of data and demanded a $4.5 million ransom.
What happened
Late on February 5, 2023 (Pacific time), Reddit detected that it had been hit by what it described as a 'sophisticated and highly-targeted' spear-phishing campaign, and it disclosed the incident publicly on February 9. The phishing messages directed employees to a website that cloned the look and behavior of Reddit's intranet gateway. The fake site was engineered to harvest not only login credentials but also the second-factor tokens employees entered, defeating Reddit's 2FA at the human layer rather than by attacking the technology itself.
One employee was successfully phished. Using that single set of stolen credentials and tokens, the attacker reached internal Reddit systems and accessed internal documents, internal dashboards, business systems, and source code. The exposed data included limited contact information for hundreds of current and former employees and company contacts, and some advertiser information. Crucially, the phished employee self-reported the incident, which allowed Reddit's security team to lock out the intruder quickly. Reddit said it found no evidence that its production systems, users' non-public data, passwords, or accounts had been compromised.
The incident took a more public and coercive turn in June 2023. The BlackCat ransomware group — also tracked as ALPHV, a prominent ransomware-as-a-service operation — publicly claimed credit for the February intrusion, listing Reddit on its dark-web leak site and asserting that it held roughly 80GB of compressed data taken in the attack. Notably, no file-encrypting ransomware was deployed against Reddit; this was a data-theft extortion rather than a classic encrypt-and-ransom operation.
BlackCat said it had demanded $4.5 million for deletion of the stolen data, and it tied its public threat directly to Reddit's most contentious decision of that year. The group threatened to release the data unless Reddit both paid the ransom and reversed its controversial API pricing changes — an unusual fusion of a criminal extortion demand with the political grievance then animating much of Reddit's own user base over the API revolt. The pairing gave the threat a performative dimension, aligning the attackers rhetorically with protesting developers and moderators.
Reddit did not publicly confirm paying any ransom, and indicated it would not pay. The threatened wholesale public dump did not materialize as a mass release in the immediate aftermath, though the attackers' continued possession of the data left an open risk. Reddit said it had engaged security experts, notified affected staff and contacts, and reinforced its defenses.
The 2023 breach underscored a hard lesson that the 2018 incident had foreshadowed: even a security-conscious platform remains exposed to credential-phishing that defeats both passwords and two-factor authentication by exploiting people rather than systems. A convincing replica of an internal login page, sent to the right employee, was sufficient to reach source code and sensitive corporate data — and the human decision of that employee to self-report was what limited the damage.
Impact
Internal corporate data was exfiltrated: documents, dashboards, source code, and personal contact information on hundreds of current and former employees and contacts, plus limited advertiser data — an estimated 80GB compressed, per the attackers. Reddit maintained that user passwords, accounts, and production data were not breached. The episode demonstrated the effectiveness of intranet-spoofing phishing against employee 2FA, and BlackCat's demand notably sought both $4.5 million and a reversal of Reddit's API pricing.
Sources
- 01
- 02
- 03
- 04
- 05
What this led to
The documented consequences of this issue — the convictions, lawsuits, regulatory actions, policy changes, and bans it triggered.
Related context
People, quotes, research, and reference entries linked to this issue.