Desk live·
ForensicPost
Breaches/Actors/File 23-0619

Reddit Says Phishing Took Source Code and Internal Documents, Not User Passwords

An employee was phished in February and the operators listed the company in June, demanding $4.5 million — and, unusually, a reversal of a product decision. Reddit stated no production systems, user passwords or accounts were compromised.

Constructed geometry · not a chart of case data
TargetReddit
ActorALPHV/BlackCat
S. Rosler10 min readConfidence: high2 sources reviewed

Reddit disclosed that on 5 February 2023 a targeted phishing attack captured an employee’s credentials and second-factor token, giving access to internal documents, dashboards, business systems, source code and contact information for current and former employees and some advertisers.

The company stated it had no evidence that production systems, user passwords or accounts were compromised. In June the ALPHV/BlackCat operation listed Reddit, claiming 80GB and demanding $4.5 million.

The Demand Included A Product Decision

Alongside the money, the operators demanded that Reddit reverse a change to its API pricing — a commercial decision then the subject of a public dispute with the site’s own users.

That is the only instance in this database of an extortion demand attaching a condition unrelated to payment or data deletion. It is worth recording precisely because it did not become a pattern: extortion converged on money, and this was an experiment nobody repeated.

A Second Factor Was Present And Phished

Reddit’s account describes both the credential and the second-factor token being captured. A one-time code entered into a convincing page is forwarded to the real site by the attacker within its validity window.

The corpus files the same defeat at 25-0813, 23-0913 and 23-0227. Multi-factor authentication raises the cost of phishing; it does not make a person immune to being convincingly asked.

Low Severity Is A Statement About Scope

This file is graded SEV 3 against 2023 files ten times its size. What was taken was largely the company’s own — source code, internal documents, employee contact details — rather than a population of users who had no involvement.

The corpus grades on harm to affected people, not on the profile of the organisation. A well-known name losing its own material scores lower than an unknown processor losing millions of other people’s records, and 26-0731 remains the clearest instance of the second.

How we reported this

Built on contemporaneous reporting of Reddit’s own disclosure and of the subsequent leak-site listing. The 5 February date, the phishing method including second-factor capture, the categories of data taken and the statement that user passwords and accounts were not compromised are Reddit’s own. The 80GB volume, the $4.5 million demand and the API pricing condition are the operators’ claims as reported; none is carried in the record. This desk records no evidence that data was published. Graded high on Reddit’s account. Corrections: corrections@forensicpost.com.

Sources
  1. Reddit hackers threaten to leak data stolen in February breachBleepingComputer
  2. Ransomware Gang Takes Credit for February Reddit HackSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary