According to Reddit’s findings post on February 9, 2023, the company became aware around February 5 of a sophisticated phishing campaign targeting employees. After obtaining one employee’s credentials, the attacker reached some internal documents and internal business information. The employee self-reported. Security removed the infiltrator’s access, notified law enforcement, and opened an investigation. Public reporting does not establish a named threat actor, exact record counts, or kit-level phishing-page details in Reddit’s own post. Contemporaneous secondary reporting characterized the campaign as AiTM-class capture of credentials and second-factor tokens in real time; Reddit’s disclosure itself confirms sophisticated phishing and credential theft without naming 2FA-token capture.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did attackers get into Reddit in February 2023?
Attackers got into Reddit through a sophisticated phishing campaign that obtained one employee’s credentials. According to Reddit’s February 9, 2023 findings post, after those credentials were obtained the attacker gained access to some internal documents and internal business information. Contemporaneous secondary reporting described the campaign as AiTM-class, meaning a live proxy that can capture password plus second-factor tokens and complete login. Reddit’s official post does not itself state 2FA-token capture or name the phishing kit.
Was the Reddit 2023 incident a consumer account breach?
No. The Reddit February 2023 incident was a workforce identity compromise, not a consumer Reddit login takeover. The attacker used one employee’s credentials against internal company systems. According to Reddit, production systems including the Reddit Ads platform were not impacted and continued to operate normally.
What data did the Reddit attacker actually reach?
After the employee credential compromise, the attacker accessed limited Reddit code, limited contact information for a small number of company contacts and employees (current and former), and limited advertiser information. Reddit stated no high-risk data such as credit card details, company financial information, account passwords, or campaign strategy or performance was accessed. Based on Reddit’s investigation at the time of the post, there was no evidence any Reddit information had been published or distributed online. Public reporting does not establish exact record counts.
Did MFA fail in the Reddit employee phishing attack?
Public reporting does not establish that Reddit’s official disclosure named MFA, 2FA, or second-factor token capture. The confirmed fact is credential theft via sophisticated phishing, after which internal access followed. Contemporaneous secondary reporting framed that campaign as AiTM-class live capture of credentials and second-factor tokens, a pattern that defeats phishable login factors. A fix for that login path exists; this post does not walk the cryptography. Use the companion prevention article for that angle.
Why didn’t killing the session undo the whole Reddit incident?
Killing the session stopped further live use of that employee access. Reddit said the employee self-reported and the security team responded quickly to remove the infiltrator’s access. Documents and systems already reached under a valid post-login session are not rewound by a stronger factor on the original phishing page. Closing the phishable login stops this path upstream. Malware after a legitimate login is a harder, separate problem.