IOTW: Source code stolen in Reddit phishing attack

The social media site suffered a targeted phishing attack against its employees

Add bookmark
Source code stolen in Reddit phishing attack

A “highly targeted” phishing attack against social media site Reddit’s internal network has seen malicious actors steal the company’s source code and internal documents.

The breach occurred on February 5, after a phishing attack was launched at Reddit employees. The site said the attack contained “plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens”. 

After obtaining an employee’s credentials, the malicious actors were then able to gain access to Reddit’s internal systems. This meant that the hacker accessed Reddit’s internal business systems, dashboard, documents and source code

After being alerted to the phishing attack by the employee whose account was accessed, Reddit said it “removed the infiltrator’s access” and launched an investigation into the breach. The site noted that “similar phishing attacks” have been reported recently.

The data accessed in the breach included “limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information”, but Reddit confirmed that “user passwords and accounts are safe”.

The site also reported that there was “no evidence” any of its primary production systems being accessed, or that any of its users’ “non-public data” had been accessed or posted online.

Reddit has launched an internal investigation into the breach, as well as enhancing its security systems. Additionally, it urged users to enable multi-factor authentication and use a password manager both to set up complex passwords and to prevent themselves from being phished.

GitHub source code stole in phishing attack

On September 16, 2022, GitHub reported a phishing attack that involved a malicious actor posing as code integration and delivery platform CircleCI in order to harvest login credentials and authentication codes from employees and gain access to various user accounts.

The phishing site used by the hacker relayed time-based-one-time-passwords (TOTP) two-factor-authentication codes to the hacker in real time, allowing them to gain access to accounts protected by TOTP two-factor authentication. Accounts protected by hardware security keys were not vulnerable to this attack.

Throughout the cyber attack, the malicious actor was able to gain access to and download multiple private code repositories and use techniques to preserve their access to the account even in the event that the compromised user or organization changed their password.

Mailchimp targeted in phishing attack

On January 11 of this year, marketing automation company Mailchimp reported that it was the victim of a social engineering attack-related data breach. 

According to Mailchimp, the breach involved an “unauthorized actor accessing one of [the] tools used by Mailchimp customer-facing teams for customer support and account administration”.  

Following this, the malicious actor launched social engineering attacks on Mailchimp employees and contractors used by the company. Through these attacks, the hacker was able to steal employee credentials and then used this login information to gain access to “select Mailchimp accounts”. 
Mailchimp reported that the attack was targeted and limited to 133 accounts.

In the wake of the attack, Mailchimp suspended access for those accounts compromised in the attack to protect users’ data, and notified the account owners of the suspicious activity. All those affected were notified by Mailchimp by January 12, and the company has been working with them to safely reinstate their accounts. 


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"63934ace4aac423e0549f5e2","name":"The biggest data breaches and leaks of 2022","description":"The data breaches that had the biggest impact in the cyber security world over the past 12 months","file":null,"url":"\/attacks\/articles\/the-biggest-data-breaches-and-leaks-of-2022"},{"id":"62ed24f7d60adf7be879dbd3","name":"Social engineering \u201cmost dangerous\u201d threat, say 75% of security professionals","description":"Research by CS Hub has revealed that social engineering and phishing attacks are the top threat to cyber security","file":null,"url":"\/attacks\/news\/social-engineering-most-dangerous-threat-say-75-of-security-professionals"},{"id":"63877874ddf8b342e21eadee","name":"The top 10 hacks and cyber security threats of 2022","description":"Discover the top 10 news stories from the cyber security space of the last 12 months","file":null,"url":"\/attacks\/articles\/the-top-10-hacks-and-cyber-security-threats-of-2022"},{"id":"62e3beef6ceab07f824156af","name":"What is social engineering?","description":"A guide to social engineering and how to guard against this attack vector","file":null,"url":"\/threat-defense\/articles\/what-is-social-engineering"},{"id":"63a1a9a82bae49245b51a94f","name":"The most dangerous cyber security threats of 2023","description":"Cyber security experts share their prediction for the most impactful threat vectors and cyber risks of 2023","file":null,"url":"\/attacks\/articles\/the-most-dangerous-cyber-security-threats-of-2023"}],"featured_content_portal_embedded":null}" >