Antivirus firm Avast! has 'fessed up to a breach.
The small upside is that the mess only impacts the company's forums. As the company's CEO Vincent Steckler has blogged “Less than 0.2% of our 200 million users were affected. No payment, license, or financial systems or other data was compromised”:
https://blog.avast.com/2014/05/26/avast-forum-offline-due-to-attack/ Don't click away to another story yet: user names, email addresses and hashed passwords were compromised, so Steckler says “If you use the same password and user names to log into any other sites, please change those passwords immediately.”
The CEO goes on to say Avast! has no idea how the breach occurred, but that “we do believe that the attack just occurred and we detected it essentially immediately.” The company plans to rebuild the forum on a different software platform.
(ElReg)
At the moment, if you follow official link to Avast's forum: https://forum.avast.com you'll get this message:AVAST forum offline due to attack
The AVAST forum is currently offline and will remain so for a brief period. It was hacked over this past weekend and user nicknames, user names, email addresses and hashed (one-way encrypted) passwords were compromised. Even though the passwords were hashed, it could be possible for a sophisticated thief to derive many of the passwords. If you use the same password and user names to log into any other sites, please change those passwords immediately. Once our forum is back online, all users will be required to set new passwords as the compromised passwords will no longer work.
This issue only affects our community-support forum. No payment, license, or financial systems or other data were compromised.
We are now rebuilding the forum and moving it to a different software platform. When it returns, it will be faster and more secure. This forum for many years has been hosted on a third-party software platform and how the attacker breached the forum is not yet known. However, we do believe that the attack just occurred and we detected it essentially immediately.
We realize that it is serious to have these usernames stolen and regret the concern and inconvenience it causes you. However, this is an isolated third-party system and your sensitive data remains secure.
All the best,
Ondrej Vlcek
COO AVAST Software