Has PH had a password and email leak/breach?

Has PH had a password and email leak/breach?

Author
Discussion

Mont Blanc

Original Poster:

1,397 posts

50 months

Sunday 22nd September
quotequote all
I just got warned by Safari that my password used for PH has appeared in a data leak.

The password in question is unique to PH and I have not used it or anything similar anywhere else. This password is not stored electronically anywhere (apart from in my Apple keychain) and has never been emailed or anything like that.

I can only assume it has been leaked or hacked from PH somehow, unless anyone can suggest another method by which it has leaked?


bitchstewie

55,081 posts

217 months

Sunday 22nd September
quotequote all
Pretty sure Apple just flag passwords that have been seen on sites like https://haveibeenpwned.com but not necessarily against you.

Pop it in here.

https://haveibeenpwned.com

If it appears your password almost certainly isn't as strong and unique as you think it is.

Mont Blanc

Original Poster:

1,397 posts

50 months

Sunday 22nd September
quotequote all
bhstewie said:
Pretty sure Apple just flag passwords that have been seen on sites like https://haveibeenpwned.com but not necessarily against you.

Pop it in here.

https://haveibeenpwned.com

If it appears your password almost certainly isn't as strong and unique as you think it is.
You are correct, Apple do collate potentially leaked passwords in such a fashion.

There are only a finite number of passwords and combinations in the world, so I guess that someone else has had their password leaked, which just happens to be the same as mine. Statistically rare given the fact that the password is a combination of Uppercase/lowercase/letters/numbers, but I guess it can happen.

The password does come up as leaked on haveibeenpawned.

Don1

16,065 posts

215 months

Sunday 22nd September
quotequote all
Under which leak, they generally say such as Adobe.

OldGermanHeaps

4,202 posts

185 months

Sunday 22nd September
quotequote all
I just got a similar warning from chrome, but I have been using a lot of public wifis recently. Anything to be concerned about ?

Ben Lowden

6,509 posts

184 months

PH Marketing Bloke

PH TEAM

Tuesday 24th September
quotequote all
I can confirm we have had nothing in terms of data leaks from our own servers.

This looks more typical when someone uses public wifi without a VPN or has a security issue on their device which allows someone to potentially steal their data. So it's more about their own actions being exposed rather than any PistonHeads data internally.

OldGermanHeaps

4,202 posts

185 months

Tuesday 24th September
quotequote all
Oops.
Ran out of data on holidaybanghead
Changing passwords now.

Mont Blanc

Original Poster:

1,397 posts

50 months

Tuesday 24th September
quotequote all
Ben Lowden said:
I can confirm we have had nothing in terms of data leaks from our own servers.

This looks more typical when someone uses public wifi without a VPN or has a security issue on their device which allows someone to potentially steal their data. So it's more about their own actions being exposed rather than any PistonHeads data internally.
Thanks Ben.