]> jfr.im git - irc/freenode/web-7.0.git/blame - content/news/2018-06-29-security-update-rpa.md
2021-06-05: update people
[irc/freenode/web-7.0.git] / content / news / 2018-06-29-security-update-rpa.md
CommitLineData
767e3927
CD
1---
2author: christel
9d74faa0 3date: 2018-06-29 08:08:00+00:00
767e3927
CD
4slug: security-update-rpa
5title: freenode Security Update: Reused Password Attack
6category: general
7category: freenode
8category: community
9category: security
10category: announcements
11---
9d74faa0 12
767e3927
CD
13In the very early hours of today (Friday 29 June 2018), we became aware of unauthorised attempts to access a substantial number of freenode accounts. This appears to be the result of an attacker using lists of usernames and passwords from other online services that have previously been compromised, and trying these combinations on freenode accounts.
14
15Our investigations commenced immediately and we found that the attacker had been able to log in to a number of freenode accounts.
16
17freenode has not been hacked or compromised.
18
19### Affected information
20For the affected accounts, usernames (nicknames) and passwords are affected. Additionally, for some accounts, other information including channel access and channel lists may be affected.
21
22### What we are doing
23We are committed to protecting your data and, as a precaution, we have frozen the affected accounts and are in the process of sending individual notifications to affected users.
24
25### What you can do
26If your account was affected, we are in the process of contacting you directly with information to reset your password and restore access to your account.
27
28We encourage all users to practice good password hygiene, even if your account has not been affected at this time.
29
30Attacks such as these have a tendency to escalate and cause a domino effect and we will continue to investigate and monitor for new attack vectors.
31
32Password reuse means that once one account is compromised, all of the accounts that share that password become compromised.
33