I just got this email regarding this issue and was hoping to get some additional info on the situation, but I don't see anything about it in the forums.
You've been pwned!
You signed up for notifications when your account was pwned in a data breach and unfortunately, it's happened. Here's what's known about the breach:
Breach: | Acne.org |
Date of breach: | 25 Nov 2014 |
Number of accounts: | 432,943 |
Compromised data: | Dates of birth, Email addresses, IP addresses, Passwords, Usernames |
Description: | In November 2014, the acne websiteacne.orgsuffered a data breach that exposed over 430k forum members' accounts. The data was being actively traded on underground forums and included email addresses, birth dates and passwords. |
You can also run a search for breaches of your email address again at any time to get a complete list of sites where your account has been compromised.
I got the same email. An announcement and automatic reset of all user passwords would be appropriate. Yes, people will be a bit upset and a bit inconvenienced, but not as much as if they find out the hard way that their details are being used by hackers.
Users should be aware that there is no such as thing as 100% secure on the internet, only more secure and less secure, easier targets and harder targets.
Hey guys. We've been on top of this and these reports are not true.
We use a 2 step, 1-way encryption and top security protocol for all sensitive information including your passwords and therefore no passwords were compromised. There is no need for anyone to reset passwords or be concerned that their account or personal information could be in any way taken or used by a third party.
Regarding email addresses, we are still verifying if in fact email addresses were visible to outside parties and if so, how.But keep in mind that in the event that they were somehow shared, in a worst case scenario, you would simply get a bit of spam.
Hi all,
Ihave had it verified that my data was breached and from this site.Site owners are required to submit details of breached data onto sites like haveIbeenpwned.- as I rarely visit acne.org- please could you remove my account. I have tried to permanently delete my account and cannot seem to do this -- you have breached your side of your contract when I signed up:
"We implement a variety of security measures to maintain the safety of your personal information. Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential."
Please offer deletion of accounts to those who would like to be removed and who have had their personal data breached!!