Categories: Technology

Reddit in trouble: dangerous hacker gang threatens with massive data breach

The Russian cybercriminals behind the ALPHV/BlackCat ransomware operation are taking on Reddit, claiming that they are posting 80 gigabytes of looted data on the dark web.
Daniel Schurter

Things are getting difficult for the operators of the social media platform Reddit: the ransomware gang ALPHV (“BlackCat”) threatens them with a huge data breach. The cyber criminals allegedly stole 80 gigabytes (GB) in a hack last February.

The blackmail happens at the worst possible time. Reddit, which plans to go public in 2023, is currently hit by massive user protests (more on that below).

Because those responsible did not want to negotiate with them, the extortionists are now announcing that the captured data will be published on the Darknet. A similar message is dated last Saturday (June 17).

The threat must be taken seriously: ALPHV is one of the most powerful gangs that exploit ransomware-as-a-service (RaaS). The unknown criminals are known to “exfiltrate” large amounts of data and put enormous pressure on victims who are unwilling to pay.

ALPHV was responsible, among other things, for hacker attacks against Swiss airport service provider Swissport and financial services provider Finaport. And the group paralyzed the Austrian state of Carinthia.

The gang has repeatedly been active on Russian-language hacker forums. Some members are said to have worked for the notorious Russian hacker and extortion gang REvil (later BlackMatter and DarkSide) in previous years.

$4.5 million ransom

On February 9, Reddit informed of a hacker attack detected on February 5. At the time, an employee would have fallen victim to a phishing attack.

The hacker or hackers allegedly gained access to the Reddit systems unnoticed and “internal documents, source code, employee data and limited data about the company’s advertisers” were stolen.

Reddit’s chief technology officer (CTO), Christopher Slowe, tried to put the attack into perspective in a post: The “primary production systems” were not affected.

“After a multi-day investigation by security, engineering, and data scientists (and friends!), we have no indication that your non-public data has been accessed or that the information was published or distributed online by Reddit.”

The ALPHV extortionists claim they tried to contact Reddit twice, on April 13 and June 16, demanding $4.5 million for data deletion, but received no response.

The subreddit blackout

The alleged data theft and extortion come at a particularly opportune time for Reddit: the company is currently undergoing an unusual strike.

Since last Monday (June 12), some of the most well-known Reddit discussion forums (called subreddits) have shut down or massively scaled back their activities. More than 8,000 subreddits took part in the so-called “blackout”, including those with millions of users.

The protest is supported by thousands of volunteers who are active as (unpaid) content moderators on the platform. They are protesting a controversial plan by Reddit management.

From July 1 the Accessing the Reddit programming interfaces (APIs) is vastly more expensive become. Providers of popular Reddit apps like Apollo publicly warned that they couldn’t afford the extra charges.

Apollo developer Christian Selig estimated, according to a report by the AP news agency, that the additional costs would amount to about $20 million per year.

If third-party apps become unavailable, it would make the job of the so-called “mods” much more difficult. And thus complicate the fight against the spread of disinformation and hate on the platform.

But third-party Reddit apps are also important for their screen reader functionality. The official Reddit app is not accessible to people with visual impairments.

Reddit CEO Steve Huffman said over the weekend that the company is sticking to announced API price increases and will not respond to demands from subreddit moderators.

Founded in 2005, the social media platform is expected to go public in the second half of 2023.

Sources

  • bloodcomputer.com: Reddit hackers threaten to leak data stolen in February
  • apnews.com: Thousands of Reddit Communities Go in the Dark to Boycott Third-Party App Fees (June 14)
  • reddit.com: We had a security incident. Here’s What We Know (February 9 post)

Daniel Schurter

Source: Watson

Share
Published by
Ella

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago