0

Scripted botnet attack on 12/20/2017

Hey folks,

There was a botnet attack and we emailed the accounts (about 180 accounts) we saw suspicious activity on, putting this post here for the few folks to refer to if needed and to always have transparency with our customers and users:

Greetings,

On 12/20/2017 our web team detected a scripted botnet attack against our sign in form. It appeared to be using a list of emails and passwords from an unknown website or combination of sites which may have been compromised. Adafruit databases and backends have not been compromised to the best of our knowledge.

The attack ran through a list of email address and password combinations, then tried to sign in to our site with each one. The large majority of user/pass combinations failed and were not Adafruit customers or did not have shared passwords with these other websites.

Once we discovered that this attack had begun, we locked down our site as quickly as possible through various means including: additional throttling, requiring a captcha on sign in, DDOS protection (denial of service), and forcing password resets on those accounts that were affected.

We were able to determine that your account was in the list of email/password combinations. Your Adafruit account was accessed yesterday, 2017-12-20. This suspicious activity was the reason for an automated password reset.

We sent 40 password reset notifications while making sure your account and others were protected, and we are additionally sending this notification now.

You account password has been reset. Please use the ‘Forget your password?’ link at https://accounts.adafruit.com/users/sign_in to change it to a new, strong password, not used on other sites.

As a precaution, we suggest changing any passwords on other sites that may have used this email address or password in the past.

Adafruit databases and backends have not been compromised to the best of our knowledge, and we will continue to analyze this attack which appears to have been stopped.

Thanks web team and community support for taking care of this so fast.


Stop breadboarding and soldering – start making immediately! Adafruit’s Circuit Playground is jam-packed with LEDs, sensors, buttons, alligator clip pads and more. Build projects with Circuit Playground in a few minutes with the drag-and-drop MakeCode programming site, learn computer science using the CS Discoveries class on code.org, jump into CircuitPython to learn Python and hardware together, or even use Arduino IDE. Circuit Playground Express is the newest and best Circuit Playground board, with support for MakeCode, CircuitPython, and Arduino. It has a powerful processor, 10 NeoPixels, mini speaker, InfraRed receive and transmit, two buttons, a switch, 14 alligator clip pads, and lots of sensors: capacitive touch, IR proximity, temperature, light, motion and sound. A whole wide world of electronics and coding is waiting for you, and it fits in the palm of your hand.

Join 9,200+ makers on Adafruit’s Discord channels and be part of the community! http://adafru.it/discord

CircuitPython – Python on Microcontrollers is here!

Have an amazing project to share? Join the SHOW-AND-TELL every Wednesday night at 7:30pm ET on Google+ Hangouts.

Join us every Wednesday night at 8pm ET for Ask an Engineer!

Follow Adafruit on Instagram for top secret new products, behinds the scenes and more https://www.instagram.com/adafruit/


Maker Business — Japanese word working and more in December’s issue of HackSpace magazine!

Wearables — Solder-less magic

Electronics — = != ==.

Biohacking — Finding Bliss with Anandamide

Python for Microcontrollers — sysfs is dead! long live libgpiod! libgpiod for linux & Python running hardware @circuitpython @micropython @ThePSF #Python @Adafruit #Adafruit

Get the only spam-free daily newsletter about wearables, running a "maker business", electronic tips and more! Subscribe at AdafruitDaily.com !



No Comments

No comments yet.

Sorry, the comment form is closed at this time.