Compromised Moderator Login; your data is safe though

The_J

Say No 2 Net Validations
Administrator
Supporter
Joined
Oct 22, 2008
Messages
41,874
Location
DE/NL/FR
The short version of today's events:
What happened: A moderator's account was compromised
Did I get hacked? No, your data is safe and not at risk.
Have you fixed everything? No, not yet.
How long will it take to fix everything? We TBH don't know.

The long version of what happened today:
Today's events were triggered that a single moderator account got compormised. This was a targeted attack at that moderator, although we don't understand why it was him specifically. Nobody else seems to have been targeted. The moderator probably had a weak password, which allowed the hacker to come in. This means that your data is safe, you do not need to change your password, or be worried about anything. Unless you have a weak password, but that is an issue which is not limited to CFC.
We do know more about the nature of this targeted attack. We recently had to permanently ban a senior member of the forum, as he alleged that the forum was used to groom children. Obviously nothing like pizzagate is happening here, and he failed to produce any evidence. He still went mental afterwards, and harrassed us multiple times here in the forum and on social media (some people might recall events related to this). Today's attack was most likely him, as he banned multiple members with the accusation that they might be grooming children.
This background luckily tells us that this was targeted at specific members, and that the data of everyone else is safe.
We are still considering what we are doing right now with the fallout.
The hacker did mainly 3 things:
- He banned a couple of members. This has been reversed
- He deleted and locked a bigger bunch of threads. This has been reversed.
- He took all the threads where someone most recently had posted in (that is in total 35, which corresponds to one forum page) and merged them into a single thread. This were threads which together have a couple of 10.000 posts, as e.g. the movie thread from OT or the permaban thread from the moderators forum were included. Lymond seems to have reconstructed 5 of these smaller threads (if I see that right), but the rest we cannot do manually, at least not fully, although we will certainly be able to recover the OPs. This has also affected a couple of download database resources which were connected to these threads. Thunderfall has asked Xenforo if there is a solution for this, which does not include using a backup of the database. A database backup is run every 12h, and the last one was affected by the hack. Xenforo support will most likely only be available tomorrow morning, at which point a database rollback will mean losing 36h of posts. We do not know if there is a good solution for this. The more time passes, the more unlikely this gets, and we definitely prefer another solution.

We will keep you updated what is going to happen.
We are sorry for this situation, please bear with us.
 
Last edited by a moderator:
That's pretty bad. Are there any solutions under consideration to improve the security on mod accounts in the future?
 
Sorry you're going through this. Thank you for your work in getting on top of it and for your transparency about the situation.
 
That's pretty bad. Are there any solutions under consideration to improve the security on mod accounts in the future?
Many moderators have now activated 2-factor authentication.

If 36 hours of posts might be lost, will this affect private messages?
Everything in the forum, including private messages, profile messages, any changes to settings, avatars, etc.
But as said, it is not clear if there is a better solution for this, and if we might not let some of the affected threads just stay where they are. It really depends, we cannot say yet.
 
Many moderators have now activated 2-factor authentication.


Everything in the forum, including private messages, profile messages, any changes to settings, avatars, etc.
But as said, it is not clear if there is a better solution for this, and if we might not let some of the affected threads just stay where they are. It really depends, we cannot say yet.

36 hours backwards from when, though - tomorrow morning?

I've had a very active PM situation, and would not like to lose this conversation. Should we put it on hold now and save everything from the past couple of days?
 
Glad to know, my entire thread in release mods for the ai mod for civ 7 is gone. If it's lost, I guess I just add it back.
 
36 hours backwards from when, though - tomorrow morning?

I've had a very active PM situation, and would not like to lose this conversation. Should we put it on hold now and save everything from the past couple of days?
Yes, 36h from tomorrow morning (CEST), or approx 24h from the current time.
If you want to be really safe about this, then yes, I would recommend.
More updates to come within the next 24h, but right now we don't know what is going to happen.
Glad to know, my entire thread in release mods for the ai mod for civ 7 is gone. If it's lost, I guess I just add it back.
The thread is not lost, as all the posts are in a giant thread in the moderators forum.
Be ensured we will find at least the opening posts of your thread and put them back into the forum, but we can't be sure to find all the posts.
Also here, more info to come within 24h.
 
Back
Top Bottom