Just curious if I could get a PM with a mod/admin to talk about exactly what happened.
Account security breach.
Forum Index > Tech Support |
Starwind87
United States1 Post
Just curious if I could get a PM with a mod/admin to talk about exactly what happened. | ||
riotjune
United States3357 Posts
| ||
FO-nTTaX
Johto4736 Posts
On August 16 2017 05:54 Starwind87 wrote: Had to reset my password due to someone trying to hijack my account. Just curious if I could get a PM with a mod/admin to talk about exactly what happened. PMd you | ||
R1CH
Netherlands10340 Posts
We saw a large amount of IPs (most likely a botnet) repeatedly trying to log in to TL accounts using usernames and passwords that were stolen (hacked) from an unrelated website / service. This website has a large intersection of TL users due to similar interests, and many TL users used the same username and password on their account there as they did for TL. By monitoring the pattern of usernames the IPs were trying to log in as, I was able to determine which stolen database was being used and cross-checked that DB against our own, disabling any accounts that had a matching username / password. While many accounts were successfully accessed by this attack, I believe they were only recorded as being valid logins for some future purpose as our access logs only showed login attempts from the attacking IPs. We locked the accounts while the attack was still ongoing, so it's unlikely whoever was behind it had time to make use of the results. I recommend using a site like https://haveibeenpwned.com/ to find other services that may have leaked personal data, and using strong, unique passwords for every different website through a password manager like Lastpass or Keepass. | ||
| ||