Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

HipChat hacked, users' account information potentially compromised

by The Gurus
April 26, 2017
in Editor's News
data breach
Share on FacebookShare on Twitter

Atlassian’s group chat platform for business was hacked over the weekend. The service, HipChat, has reset all of it’s users’ passwords after a security incident was flagged due to a vulnerability in a third-party library used by HipChat.com.
A security notice was released on Monday (24 April), with the company saying hackers could potentially have accessed a significant amount of personal data. Users’ account information such as names, email addresses, hashed passwords as well as the room metadata are thought to have been accessed in the breach.
The attack is thought to have affected less than 0.05% where hackers may have infiltrated private messages and content within rooms on one of the servers on the HipChat Cloud web tier.
Although Atlassian have claimed they have isolated the incident and that was no evidence that the breach impacted other Atlassian systems, the breach of personal information is of extreme significance and concern, which was highlighted by Robert Capps, VP of business development at NuData Security. He says “With just a name and email address, there is an outsized risk to consumers from targeted phishing and malware attacks. Stolen consumer data can be combined with other personally identifiable information (PII) from other hacks and breaches, to amass even more detailed profiles of users that are traded and sold to other hackers and fraudsters. These bundles of data contain much more complete information about specific individuals providing greater opportunities for fraud to take place.”
Many infosecurity experts were quick to praise HipChat’s rapid and efficient response to the breach. Javvad Malik, Security Advocate at AlienVault said “they have done a good job of communicating the breach to customers in a timely manner, indicating that they had monitoring controls in place to look for breaches. The company also provided reassurance on the security of its systems with passwords being hashed with bcrypt. It also followed up with the good step and advice to customers to reset their passwords.
Javvid also advised that “customers should also be sure to change their passwords on other systems if they were reusing the same one. “While HipChat has apparently covered all the bases and should be commended for their swift and appropriate response. There is the small issue of other data that could have been potentially accessed by attackers.”
Paul Edon, Director at Tripwire noted that the leaked data was “hashed and salted”, making it difficult to crack adding “it sounds as though HipChat take their cyber security seriously.” Paul did, however, have one concern regarding whether the breach came from a known vulnerability. “If “unknown” well done HipChat for the speed at which they identified the breach and took the necessary action to remediate further loss or damage. However, if the vulnerability was “known” then this is another case where security best practise – vulnerability and patch management would have almost certainly prevented the breach.”
As a precaution, HipChat have invalidated passwords on all potentially affected HipChat-connected user accounts and sent those users instructions on how to reset their passwords. In response to the attack, the company are also preparing a server update.
ESET IT security specialist, Mark James also noted to how quick HipChat were to reacting saying “password resets are good and notifying affected users quickly is a major plus. We often hear about these types of breaches months if not years after they have happened, but in this case we have seen a good description of events with plenty of information about who, what and when.”
 

Tags: BreachCyberdatasecurityTechnology
ShareTweet
Previous Post

77% Of All Ransomware Detected in 4 Industries

Next Post

Why sharing is not always caring in the public sector

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol