Page 1 of 1

Hacked accounts?

Posted: Mon Jan 16, 2023 2:41 pm
by Vephriel
There's been a recent trend of what look to be hacked accounts posting spam lately, from known or long-time users here. It's a little worrying and I'm wondering how they got access to those accounts. Is there anything we can do on our end to prevent this happening? I'm not sure if we should be changing passwords, or if there's any way the server people can pin down a source for the infiltration?

Just thought I'd make a thread to draw attention to it, thanks for any insight Wain!

Re: Hacked accounts?

Posted: Mon Jan 16, 2023 2:48 pm
by Ana
Thanks for making this Vephriel. I am quite worried too ..

Re: Hacked accounts?

Posted: Tue Jan 17, 2023 10:28 am
by Wain
Thanks for your reports! 🤍

It is a bit worrying! But unless I missed some, we've only had two long-term accounts hacked, I think. Or have there been more?

If they hacked our database I would have expected signs of many more accounts compromised. Assuming it's just been the two, it could be a situation where a virus or phishing tool is going around that (among other things) looks for your phpbb board account info. It's also possible a password list has been leaked, perhaps specifically related to boards, so if you use the same password for multiple boards I really, really suggest you change it now. But it's safest to change it regardless :)

I've let our sysadmin know, just to be safe, but I'm so far not worried that the hack is on our end.

Oh, and it looks like one of the two accounts hasn't been active here since 2021, so I deactivated her account. Not deleted or banned - it just means she needs to go through an activation process before she can use it again.

Re: Hacked accounts?

Posted: Tue Jan 17, 2023 12:53 pm
by Ana
Only two yeah... but one of them had multiple posts..And im not sure they know about it? Saw them comment normally afterwards
Good to know you keep an eye out :hug: