BlackCat threatened to leak 80GB of Reddit data taken in a February breach

Organization
Reddit
Exploit
Phishing
Industry
Social Media

The ALPHV ransomware group, also known as BlackCat, claimed in June 2023 that it held 80GB of compressed data taken from Reddit and threatened to publish it.

The data came from an intrusion Reddit had already disclosed. On February 5, 2023, an employee fell for what the company described as a sophisticated phishing campaign that imitated an internal portal, giving an attacker access to internal systems. Reddit said at the time that the material accessed may have included limited internal code, limited contact information for a small number of current and former employees and company contacts, and limited advertiser information.

Reddit said its production systems were not breached and that no user passwords, accounts or credit card details were affected. A spokesperson confirmed to The Record that the extortion post related to the February incident but declined to comment further.

BlackCat said it had contacted Reddit on April 13 and again on June 16 without receiving a response, and demanded $4.5 million. The group attached an unusual second condition: that Reddit abandon its planned charges for third-party access to its API, a change that had triggered widespread protest across the site that month. No publication deadline was given, and Reddit did not say whether it would pay.

Sources