Avast support forums (third party hosted) hacked

B Trevathan

Member
Reaction score
17
Location
Tennessee, USA
Just wanted to pass this along in case anybody missed the Avast message in their junk mail.

It seems like everybody is getting hacked, just checked my junk mail and had a message (below) that looked to be from Avast about their support forums being hacked, being in my junk mail before I opened it I first checked the message source and it was from Avast so I then Googled "Avast forum hacked" to find more information but most everything is just a repeat of the email. Upon going to the Avast support forum it is either still down or down again.

Seeing as the Avast support forums are/was hosted by a third party, I'm guessing that the hackers only got usernames, email addresses and passwords only for the support forum itself, so it would seem to me that the worst thing that could come from this is the hackers later emailing you and pretending to be from Avast and asking for your credit card information.


============================================


Avast Anti-Virus Phone Support 1-866-951-7679
Avast: http://www.avast.com/
Avast Anti-Virus Support: http://www.avast.com/en-us/support
Support Forums: https://forum.avast.com/


============================================


Avast email May 26, 2014

The AVAST forum is currently offline and will remain so for a brief period. It was hacked over this past weekend and user nicknames, user names, email addresses and hashed (one-way encrypted) passwords were compromised. Even though the passwords were hashed, it could be possible for a sophisticated thief to derive many of the passwords. If you use the same password and user names to log into any other sites, please change those passwords immediately. Once our forum is back online, all users will be required to set new passwords as the compromised passwords will no longer work.

This issue only affects our community-support forum. No payment, license, or financial systems or other data were compromised.

We are now rebuilding the forum and moving it to a different software platform. When it returns, it will be faster and more secure. This forum for many years has been hosted on a third-party software platform and how the attacker breached the forum is not yet known. However, we do believe that the attack just occurred and we detected it essentially immediately.

We realize that it is serious to have these usernames stolen and regret the concern and inconvenience it causes you. However, this is an isolated third-party system and your sensitive data remains secure.

All the best,

Ondrej Vlcek
COO AVAST Software
 
Does anyone know if the email address and password you use to activate your Avast is the same one as in their forum ? I could have sworn that when you register the software you become "logged in" to them somehow.
 
I could have sworn that when you register the software you become "logged in" to them somehow.
I think the registering and "logged in" are two different things. I think with the Avast AV you have to still manually associate or "logged in" the program with an account (just an email address) after registering the AV program and that preregistered account is held with Avast itself not the support forum.

I guess some people (end users) might use some of the same information for both the activation and the support forums, but I can't see any of my customers (residential) even using the Avast support forum.

With the Avast free AV it just ask for your first and last name and email address and sometimes a country. It doesn't ask for a password.

If I remember right the support forum asked for your first and last name, a nickname, email, country and for a password. I think the main risk is just the email address, I guess a hacker could pretend to be from Avast and send the user an attachment and tell the user it was a important patch and in actuality be malware targeted to disable Avast AV and disable security and give the hacker access to the users computer. But we all know that an EU would never fall for that and windoze is too secure to even let that happen, right
 
Just had the same from ESET:

we have been informed by our third-party forum provider that user login details of ESET Security Forum members have been compromised. At this time we have confirmed that login data (user name/email and hashed forum passwords) have been accessed. We have requested details about the incident from our provider and have launched a full-scale investigation with them. ESET Security Forum has around 2,700 registered users and the only information stored are login details: no financial or other sensitive data are affected. ESET-operated infrastructure and ESET software users were not affected in any way by this incident.

We recommend that all ESET Security Forum users change their passwords. Having different passwords for different services is a good practice: if you used your ESET Security Forum password for other services, we recommend that you also change those passwords immediately too. Some useful tips on how to create strong passwords can be found at ESET WeLiveSecurity website: http://www.welivesecurity.com/2013/...trong-passwords-without-driving-yourself-mad/

We apologize for any inconvenience.
 
I guess if you are planning something big, go after the big AV companies that you feel might stop what you are going to use.
 
Just had the same from ESET:

we have been informed by our third-party forum provider that user login details of ESET Security Forum members have been compromised. At this time we have confirmed that login data (user name/email and hashed forum passwords) have been accessed. We have requested details about the incident from our provider and have launched a full-scale investigation with them. ESET Security Forum has around 2,700 registered users and the only information stored are login details: no financial or other sensitive data are affected. ESET-operated infrastructure and ESET software users were not affected in any way by this incident.

We recommend that all ESET Security Forum users change their passwords. Having different passwords for different services is a good practice: if you used your ESET Security Forum password for other services, we recommend that you also change those passwords immediately too. Some useful tips on how to create strong passwords can be found at ESET WeLiveSecurity website: http://www.welivesecurity.com/2013/...trong-passwords-without-driving-yourself-mad/

We apologize for any inconvenience.

OUch! I have Eset but I never did sign up for their forums.
 
Back
Top