2013-07-21: UbuntuForums Hacked; 1.8 Million Passwords Compromised
Level Three Attack
Usernames, passwords, and email addresses of all users registered on UbuntuForums.org have been exposed in a large security breach.
The initial phase of the attack appears to have been a site defacement, observed at 20:11 UTC on 2013-07-20. Within five minutes, the site was taken down and the maintenance notice was put up to indicate that an investigation was in progress.
The forums are still down for repairs, presumably to ensure that no traces of potential watering hole attacks are left in place - as well as to isolate and fix whatever vulnerability may have been exploited to grant unauthorized access to the system.
Related Links
- ZDNet: Ubuntu forums hacked; 1.82M logins, email addresses stolen
- UbuntuForums (currently displaying a notice of the event): UbuntuForums is down for maintenance