Reddit Hackers Threaten to Leak 80 GB of Stolen Data

The popular social media site, Reddit, suffered a cybersecurity breach in February of this year resulting in the theft of 80GB of data, including internal documents, source code, employee data, and some information about the company’s advertisers. The attack was allegedly carried out by the ALPHV ransomware operation, also known as BlackCat, according to cybersecurity expert Dominic Alvieri.

Phishing Attempt Used to Gain Access

The hackers were able to gain access to Reddit’s systems through a phishing attempt. Fortunately, user passwords, accounts, and credit card details were not compromised, and production systems were not affected. However, the stolen data contains sensitive information that could be damaging to Reddit and its users if it were to be leaked.

Demand for Money to Keep Stolen Data Secret

The situation worsened when the hackers responsible for the breach demanded $10 million from Riot during the attack in exchange for keeping the stolen data a secret. When their demand went unanswered, the hackers found another target to exploit. They made two attempts to contact Reddit on April 13th and June 16th, demanding $4.5 million for the content to be deleted, but once again, they received no response.

Identification of BlackCat as responsible for the attack

Dominic Alvieri reportedly discovered the involvement of BlackCat in the attack on Reddit. Although BlackCat is known as a ransomware group, they did not encrypt any devices during this attack. It is unclear why they chose to steal and potentially leak the data rather than hold it for ransom.

Confirmation of cyber attack reported by Cyber Security News

The Cyber Security News confirmed that this is the same attack that Reddit announced in February. The stolen data includes sensitive information about Reddit’s advertisers, which, if leaked, could harm the company’s revenue stream. The stolen source code could also be used to exploit vulnerabilities in Reddit’s system.

The Dangers of Data Breaches

This incident serves as a reminder of the potential dangers of data breaches and the importance of ensuring the security of valuable information. Companies must take measures to protect their users’ and their own sensitive information. These measures should include implementing secure password practices and utilizing multifactor authentication for all employees who have access to sensitive information.

Reddit, like other large companies, must take necessary steps to protect its valuable data from hackers who will stop at nothing to gain access and steal valuable information. This incident serves as a wakeup call to companies and individuals to take all necessary steps to protect their online information and understand the importance of utilizing cybersecurity measures.

Explore more

How Does CryptoBandits Steal Your Crypto via USB?

The seemingly innocuous act of inserting a flash drive into a workstation often serves as the silent catalyst for a devastating breach that can drain a digital wallet in seconds without triggering traditional antivirus alarms. This physical threat vector, utilized by the group known as CryptoBandits, exploits the inherent trust users place in hardware devices. While most cybersecurity discussions in

How Does the Klue Breach Expose Supply Chain Risks?

Introduction Modern digital ecosystems rely on a delicate web of trust that, when broken by a single compromised credential, can trigger a domino effect across the world’s most sophisticated cybersecurity firms. This reality became starkly evident when Klue, a prominent business intelligence provider, experienced a significant security failure within its integration architecture. The event serves as a masterclass in how

Trend Analysis: EDR Evasion in Ransomware

Digital adversaries have abandoned simple stealth in favor of an aggressive scorched-earth policy that systematically dismantles security defenses before a single byte of data is encrypted. This tactical evolution marks a significant departure from traditional malware behavior. As organizations deploy robust Endpoint Detection and Response (EDR) systems, operators have responded with security-killer frameworks operating within the system kernel. The significance

Is Traditional IAM Enough for the New Era of Agentic AI?

Dominic Jainy is a seasoned IT architect who has spent the better part of two decades navigating the complex intersection of artificial intelligence, machine learning, and blockchain technology. As organizations rush to integrate autonomous systems into their daily operations, Jainy has emerged as a vital voice in the conversation regarding how we secure these “digital employees.” His expertise is not

Data Centers Adopt New Strategies to Address Public Backlash

The unprecedented acceleration of global digital infrastructure has forced data center developers to confront a significant barrier of community opposition that technical expertise alone cannot overcome. For several decades, these facilities operated largely in the shadows, serving as the invisible architecture of the internet while hidden away in industrial parks or rural outskirts. However, the surge in generative artificial intelligence