Security News Disqus Confirms 2012 Data Breach That Exposed Details for 17.5 Million Users

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Earlier today, on a late Friday evening, Disqus confirmed a data breach that appears to have taken place in the summer of 2012, and during which an unknown attacker(s) made off with details for at least 17.5 million user accounts.

The company found out about the breach from Aussie security researcher Troy Hunt, who come into the possession of a copy of the stolen data and informed Disqus yesterday afternoon.

According to one of Hunt's tweets, it took Disqus 23 hours and 42 minutes to investigate the data and confirm the breach.

Hack took place in July 2012
Disqus, the web's larger provider of hosted commenting systems, has already started notifying users included in the data provided by Hunt.

According to the company, hackers stole email addresses, Disqus usernames, sign-up dates, and last login dates in plain text. SHA-1 hashed passwords were only included for about a third of the 17.5 million details.

Disqus says the last entry in the exposed data is from July 2012, a good indicator of when the security breach took place.

Full Article. Disqus Confirms 2012 Data Breach That Exposed Details for 17.5 Million Users
 
L

Local Host

This is bothersome, this is the only way so far I've been exploited (third-parties with my accounts getting hacked), thankfully I use KeePass with long passwords and special characters.

I'm going to change my Disqus password regardless if I get notification or not :coffee:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top