Reddit security incident

A targeted phishing site copied Reddit’s intranet gateway and captured one employee’s credentials and second-factor token. The attacker accessed internal documents, code, dashboards, business systems, and limited contact information for employees and company contacts.

Last modified

Summary

  • Environment: Social media
  • Operational impact: The attacker accessed internal documents, code, dashboards, business systems, and limited contact information for employees and company contacts.
  • Financial impact: No financial figure is established by the reviewed source evidence
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2023, Reddit experienced an incident in its social media environment. The retained source describes the attack path as follows: A targeted phishing site copied Reddit’s intranet gateway and captured one employee’s credentials and second-factor token. [1]

The documented consequence was: The attacker accessed internal documents, code, dashboards, business systems, and limited contact information for employees and company contacts. [1]

Impact

  • Documented impact: The attacker accessed internal documents, code, dashboards, business systems, and limited contact information for employees and company contacts. [1]
  • No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.

Timeline

  1. Documented public update

    The We had a security incident. Here’s what we know. records the incident facts used in this briefing.

    [1]
  2. Briefing updated

    This briefing was last reviewed and updated on September 19, 2026.

Threat Group & Attack Vector

The retained source describes the attack path as follows: A targeted phishing site copied Reddit’s intranet gateway and captured one employee’s credentials and second-factor token. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

The employee self-reported the phishing event; Reddit removed the attacker’s access and began an internal investigation. [1]

This account is bounded to We had a security incident. Here’s what we know.. Details absent from that evidence are left unresolved rather than inferred. [1]