Webdev Tutorials Site SitePoint Discloses Data Breach

SitePoint
Image: SitePoint, ZDNet, Florian Olivo

SitePoint, a website that provides access to a wealth of web development tutorials and books, has disclosed a security breach this week in emails sent to some of its users.

The company has formally admitted to a breach after a hacker put up for sale a collection of one million SitePoint user details on a cybercrime forum in December 2020.

In a data breach notification this week, SitePoint confirmed an intrusion into its systems sometime last year.

"At this point, we believe the accessed information mainly relates to your name, email address, hashed password, username, and IP address," the company said.

SitePoint has now initiated a password reset on all accounts and is asking users to choose new ones that are at least ten characters long.

The tutorials and books publisher believes that the stolen passwords are currently safe, as they have been hashed with the bcrypt algorithm and salted, which should make cracking the password strings to its plaintext version a pretty lengthy process for the time being.

"We recommend that you change passwords from any other websites that may be a duplicate of your SitePoint password, just as a precaution," the company added.

The WayDev connection

SitePoint said that based on current evidence, the breach occurred after the attackers gained access to "a third party tool [they] used to monitor [their] GitHub account."

"This allowed access through our codebase into our systems. This tool has since been removed, all of our API keys rotated and passwords changed," the company said.

While SitePoint doesn't mention this tool by name, it is most likely referring to a tool from Git analytics service Waydev, which disclosed a security breach last summer.

This same tool was also used to breach custom apparel vendor Teespring, whose data was also sold by the same hacker, in the same package, at the same time as the SitePoint data.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more