GitHub has admitted a number of user accounts have been compromised by an attacker who used previously published account credentials from previous breaches of other online services.
The attacker took these account credentials, such as email addresses and passwords, from other online data breaches and tried them on GitHub accounts.
GitHub said that the attacker had been able to log in to “a number” of GitHub accounts.
“We immediately began investigating,” said GitHub today, but added: “GitHub has not been hacked or compromised.”
GitHub has now reset passwords on all affected accounts, and is in the process of sending individual notifications to users who were affected.
“We encourage all users to practice good password hygiene and enable two-factor authentication to protect your account.”
Read more: GitHub Is Relying On Developers To Crack The Business Market
In May it was revealed that 117 million LinkedIn account credentials were up for sale on the dark web. A hacker, known as “Peace,” contacted technology site Motherboard this to offer the details, which are up for sale for five Bitcoins (around £1,564) on dark web site The Real Deal.
Peace claims that that the data was stolen during a breach of LinkedIn back in 2012, in which around 6.5 million encrypted passwords were posted online. The compromised GitHub credentials may well be from the fallout of this breach.
Earlier in June, Facebook founder Mark Zuckerberg’s Twitter and Pinterest accounts were accessed by hackers who noticed that Zuckerberg used the same password across several different sites.
Take our data breach quiz here!
RESEARCH: Who will benefit most from the Internet of Things (IoT)?
Welcome to Silicon UK: AI for Your Business Podcast. Today, we explore how AI can…
Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…
Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…
Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…
Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…
Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…