Hackers calling themselves Gnosis breached Gawker Media, publisher of sites including Gizmodo and Lifehacker, and released a database of around 1.3 million user accounts. The dump was shared publicly via a torrent file, making it easy for anyone to download.
What happened
- The leaked data included commenters’ usernames, email addresses, and hashed passwords.
- The attackers also published internal chat logs and some staff credentials, and said they had targeted Gawker in retaliation for its comments about 4chan.
- Gawker apologised and urged users to change their passwords on Gawker and on any other sites where they had reused them.
- Hijacked accounts on other services were soon used to spread spam, illustrating the risk of password reuse.
Why it mattered
The breach became a widely cited case study in weak password storage and reuse, and many sites forced password resets after checking the leaked list against their own users.
Lessons for organisations
Store passwords with modern, salted hashing algorithms, enforce MFA for staff tools, and encourage users to avoid reusing passwords. Monitoring for leaked credentials, and forcing resets when matches appear, helps catch reuse before attackers exploit it.
Sources: Help Net Security, Forbes
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.