Reddit disclosed that on 5 February 2023 a targeted phishing attack captured an employee’s credentials and second-factor token, giving access to internal documents, dashboards, business systems, source code and contact information for current and former employees and some advertisers.
The company stated it had no evidence that production systems, user passwords or accounts were compromised. In June the ALPHV/BlackCat operation listed Reddit, claiming 80GB and demanding $4.5 million.
The Demand Included A Product Decision
Alongside the money, the operators demanded that Reddit reverse a change to its API pricing — a commercial decision then the subject of a public dispute with the site’s own users.
That is the only instance in this database of an extortion demand attaching a condition unrelated to payment or data deletion. It is worth recording precisely because it did not become a pattern: extortion converged on money, and this was an experiment nobody repeated.
A Second Factor Was Present And Phished
Reddit’s account describes both the credential and the second-factor token being captured. A one-time code entered into a convincing page is forwarded to the real site by the attacker within its validity window.
The corpus files the same defeat at 25-0813, 23-0913 and 23-0227. Multi-factor authentication raises the cost of phishing; it does not make a person immune to being convincingly asked.
Low Severity Is A Statement About Scope
This file is graded SEV 3 against 2023 files ten times its size. What was taken was largely the company’s own — source code, internal documents, employee contact details — rather than a population of users who had no involvement.
The corpus grades on harm to affected people, not on the profile of the organisation. A well-known name losing its own material scores lower than an unknown processor losing millions of other people’s records, and 26-0731 remains the clearest instance of the second.
Built on contemporaneous reporting of Reddit’s own disclosure and of the subsequent leak-site listing. The 5 February date, the phishing method including second-factor capture, the categories of data taken and the statement that user passwords and accounts were not compromised are Reddit’s own. The 80GB volume, the $4.5 million demand and the API pricing condition are the operators’ claims as reported; none is carried in the record. This desk records no evidence that data was published. Graded high on Reddit’s account. Corrections: corrections@forensicpost.com.