Connect with us

Hi, what are you looking for?

Tech & Science

Imgur announces historical data breach impacting 1.7m users

The stolen data was sent to security researcher Troy Hunt, operator of the Have I Been Pwned data breach alert website. Hunt notified Imgur on November 23, explaining he had been handed a dataset that suggested Imgur had been compromised. The company said its Chief Operating Officer “immediately” engaged with Hunt after receiving the notice.
Over the next few hours, Imgur’s CEO and Vice President of Engineering were informed of the incident. The company verified Hunt’s authenticity and arranged to collect the data from him. Technical teams began to verify that the stolen credentials are from genuine Imgur user accounts. On November 24, Imgur made a public statement confirming the breach took place in 2014 and impacted around 1.7 million accounts.
In a tweet, Hunt described Imgur’s response to the incident as “exemplary.” In less than 26 hours, Imgur managed to mobilise staff back from Thanksgiving, obtain the data from Hunt and verify it as being part of a genuine breach. The company has already begun resetting the passwords of affected users. People whose email address is contained in the dataset will be required to set a new password.
READ NEXT: Firefox to issue warnings when a website has been hacked
Imgur said it’s still unsure how its database was compromised. The company said it may have been a “brute force” attack against its older account information infrastructure. In 2014, Imgur encrypted passwords using the SHA-256 algorithm. The attackers may have successfully cracked the encryption because the algorithm is weaker than newer alternatives. Imgur started using bcrypt instead of SHA-256 earlier this year.
“We take protection of your information very seriously and will be conducting an internal security review of our system and processes,” said Imgur. “We apologize that this breach occurred and the inconvenience it has caused you.”
Imgur users who use the same password on other sites should update their credentials across all the services with the same credentials. The breach follows a string of similar historical security incidents disclosed this year, including attacks against LinkedIn, MySpace and Uber. The data should be searchable in Have I Been Pwned once Imgur’s completed its investigation.

Written By

You may also like:

World

US President Joe Biden delivers remarks after signing legislation authorizing aid for Ukraine, Israel and Taiwan at the White House on April 24, 2024...

Business

Tony Fernandes bought AirAsia for a token one ringgitt after the September 11 attacks on the United States - Copyright AFP Arif KartonoMalaysia’s Tony...

World

AfD leaders Alice Weidel and Tino Chrupalla face damaging allegations about an EU parliamentarian's aide accused of spying for China - Copyright AFP Odd...

Business

Meta's growth is due in particular to its sophisticated advertising tools and the success of "Reels" - Copyright AFP SEBASTIEN BOZONJulie JAMMOTFacebook-owner Meta on...