Flipboard Resets Passwords After Long Undetected Hacker Breach
Flipboard forces password resets for millions of users following a series of system breaches over nine months. Hackers accessed user credentials and third-party tokens, though abuse of connected accounts remains unconfirmed.
Flipboard resets millions of user passwords after hackers repeatedly access its systems over a nine-month period. The company confirms that unauthorized intrusions occur between June 2018 and April 2019, but staff only detect the breach a day after the final incident. Attackers successfully steal usernames, email addresses, passwords, and digital tokens that connect Flipboard to external services.
The news aggregator scrambles older passwords using the weak SHA-1 algorithm, making those specific credentials vulnerable to cracking. However, passwords changed after March 2012 use a much stronger hashing algorithm that remains difficult for hackers to decode. Because of this security discrepancy, Flipboard proactively resets all user passwords as a precautionary measure.
The breach also exposes digital tokens that grant Flipboard access to connected third-party accounts like Google, Facebook, and Samsung. Although the company finds no evidence that attackers actually abused these connected accounts, it completely deletes or replaces all digital tokens to ensure safety. This incident makes Flipboard the latest major tech company to suffer a significant data breach alongside recent victims like Canva and Stack Overflow.