Online crowdfunding site Patreon has been hit by a major cyber-attack, which saw nearly 15GB of data, including passwords, donation records and other user information leaked online.
The hackers even released the source code that Patreon’s website runs on, but the site says that user credit card numbers remain safe, as none of this information was stored on its servers.
The data has been posted on several locations online, with Patreon CEO Jack Conte recommending that all users should now change their password.
“Our engineering team has since blocked this access and taken immediate measures to prevent future breaches. I am so sorry to our creators and their patrons for this breach of trust. The Patreon team and I are working especially hard right now to ensure the safety of the community.”
The site, which says it attracts around 16 million view per month, was apparently breached via a test or “debug” version of the site – useful to developers but in this case also visible to the public, said Mr Conte.
The breach was revealed by security researcher Troy Hunt, who said the data published from the hack appears to be genuine, adding that 2.3m email addresses had been stolen, including his own.
“At the very least, it means mapping individuals with the Patreon campaigns they supported,” he told Ars Technica.
In a later upfate posted on Twitter, Hunt noted that, “Obviously all the campaigns, supporters and pledges are there too. You can determine how much those using Patreon are making. The dollar figure for the Patreon campaigns isn’t the issue, it’s supporters identities, messages, etc. Everything private now public.”
Patreon’s misfortune is the second major data breach in less than a week, after mobile operator T-Mobile revealed that the details of 15 million of its users had been stolen, due to a flaw in its data protection services.
Are you a data breach expert? Take our quiz to find out!
European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…
San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…
US Supreme Court says it will hear appeal of TikTok and parent ByteDance against ban…
Japanese start-up Space One destroys Kairos rocket for second time shortly after launch, as country…
World's biggest EV battery maker CATL aims to build 1,000 battery-swap stations next year, rising…
Facebook has 'severely restricted' news content from Palestinian outlets since October 2023 amidst bias concerns,…