Reddit has confirmed it was hacked by threat actors that gained access to its internal documents and source code that was a result of a “highly-targeted” phishing attack. According to Reddit CTO Christopher Slowe's post, the company became aware of the “sophisticated” attack targeting Reddit employees on February 5.


The company employees had been receiving "plausible-sounding prompts," which lead to a website that mimic the looks and behaviour of its intranet gateway, designed as such to steal people's logins and second-factor tokens, a report said. A Reddit staffer did fall for the scheme, but they had self-reported. 


Also read: OnePlus Is Killing Its Pro Series Smartphones. Know Why


The threat actors then gained access to some internal docs, codes, dashboards and business systems. However, there has been no reported breach in the primary production systems where a majority of its data is stored, thus, ensuring user passwords and accounts data were not leaked, the company noted.


"On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens," read a post by Christopher Slowe, CTO of Reddit.


Also read: Netflix Ends Password Sharing In 4 Countries. Is India Next?


According to the online discussion platform, the website is "continuing to investigate and monitor the situation closely." The company also noted that lessons it learned from a security breach five years ago continue to be useful. If the attackers were only truly able to steal some non-user information this time, the 2018 breach was a much more serious incident.


To recall, in a bid to make it easier for its users to find exactly what they are looking for, Reddit announced bringing a change to its search-related features and the ability to search for comments on the platform.