BuddyDev

Search

Security Alert: BuddyDev account access disabled for some of the users

  • Keymaster
    (BuddyDev Team)
    Posts: 24766
    Brajesh Singh on #53644

    Hi All,
    Hope you are doing well.

    This is a notice about the security incident we were subjected to today.

    In the morning today( 11:30 AM IST), we noticed several unusual logins and multiple failed attempts. A look at our log suggested brute force dictionary attack against BuddyDev accounts.

    Overall, there were 26 accounts that were recently compromised during this brute-force login attack. The attacker utilized a dictionary attack method to gain access to the account by repeatedly attempting to log in with guessed passwords.

    To protect these accounts, we have taken the following actions:

    – Temporarily disabled these accounts.
    – Changed their password.
    – Reset their API key for accessing automatic updates.

    We have mailed all of these users with the details and the steps to re-enable the account.

    If you were one of the victims of this attack(You should have received an email from us by now), Please reset your password by following the link below:-

    Reset Password: https://buddydev.com/resetpass

    Please note that no financial details were breached. At BuddyDev we do not store billing information or payment details other than transaction id. The attacker gained limited access to BuddyDev username, full name, email address, and API key for these breached accounts.

    To enhance the security of your account, we recommend using a strong password. Additionally, we will be implementing two-factor authentication within the next 30 days to mitigate the risk of similar attacks in the future.

    Best regards,
    Brajesh

  • Participant
    Level: Enlightened
    Posts: 41
    Rudder on #54513

    Thank you for letting us know Brajesh,
    Were the user accounts encrypted?

    By the way, I hope you’re doing okay. Oh Happy New Year!

    Ben

  • Keymaster
    (BuddyDev Team)
    Posts: 24766
    Brajesh Singh on #54534

    Hi Ben,
    Happy New Year!
    Hope you are doing well.
    I am doing great and have some amazing news coming at the end of this month 🙂

    It was a brute force dictionary attack with username/text password. Except the email address, username, displayname on BuddyDev, there was nothing else compromised for these accounts. Activating a basic firewalll has stopped and there has been no new issue in last 3 weeks now.

    Regards
    Brajesh

You must be logged in to reply to this topic.

This topic is: not resolved