Critical Data Breach - Big Data for all domains
Medium
B
Basecamp
Submitted None
Team Summary
Official summary from Basecamp
This researcher provided an excel sheet that appeared to be a dump of a breach database. The origin of the data entries in the database is unclear. The vast majority of the sheet's 14,000+ entries were not relevant to any 37signals products. However, after cleaning and filtering the data and checking for valid passwords, we did find in the report: - a small number of HEY accounts mentioned with valid passwords, all of which had 2FA enabled, - and a slightly larger number of other product accounts with valid passwords. These accounts' passwords were immediately reset by 37signals staff.
Actions:
Reported by
shezxi
Report Details
Additional information and metadata
State
Closed
Substate
Resolved