Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet data breach - please read

868 replies

JustineMumsnet · 07/02/2019 12:40

As some of you know, we're very sorry to say that we’ve become aware of a data breach which affected some Mumsnet user accounts

What happened?
There was a problem affecting Mumsnet user logins between 2pm of Tuesday 5 February and 9am on Thursday 7 February 2019. During this time, it appears that a user logging into their account at the same time as another user logged in, could have had their account info switched.

Why has this happened?
We believe that a software change, as part of moving our services to the cloud, that was put in place on Tuesday pm was the cause of this issue. We reversed that change this morning. Since then there have been no further incidents.

How did Mumsnet find out this was happening?
Late last night, a Mumsnet user alerted us to the fact that they were able to log in to and view the details of another user’s account.

What information could have been affected?
If someone other than you logs into your account, they can see:
your email address
your account details
your posting history
your personal messages

They would NOT have been able to see your password because that data is encrypted and they would not have been able to change your password because you need to input a password to do that.

How many people are affected?
At the moment, we don’t know for sure but we are investigating the logs and hope to know definitively very soon. We do know that approximately 4000 user accounts were logged into in the period in question but we don’t as yet know which of those were actually breached (ie also affected by a mismatched login), although we know for sure it wasn’t every account. We have been made aware by users of 14 incidents when this occurred and have contacted the individuals that we know were affected. We are working hard to establish if there were more.

What have you done about it so far?
We’ve reversed the software change that was made on Tuesday pm, and this morning we forced a log out, requiring users to log in again before they can post. This ensures that anyone who had inadvertently logged in as someone else will no longer be logged in to the wrong account.

Where can I get updates?
We’re posting about the situation on this thread, and will update as and when we have further relevant info.

What happens next?
When we have any further substantial information affecting the security of Mumsnet user accounts we will send another email and post on the site.

We’re very sorry.
You’ve every right to expect your Mumsnet account to be secure and private. We are working urgently to discover exactly how this breach happened and to learn and improve our processes. We will also keep you informed about what is happening. We know some of you will be very worried by the possibility that your account has been breached - please mail us on [email protected] if you’d like to discuss your individual account details. We will of course be reporting this incident to the Information Commissioner.

Thanks to all who brought this to our attention.

Justine

OP posts:
Thread gallery
5
Smotheroffive · 12/02/2019 21:31

@redtoothbrush have you not received either? There were two. Two different versions of the OP. The original one, which has never come through for many, and then the updated one arrived for many yesterday/sunday

LyingWitchInTheWardrobe2726 · 12/02/2019 13:01

RedToothbrush, I'm the same, no e-mail. I mentioned it to them as I think these threads get so long that it's difficult to pick out ongoing issues.

Xenia · 12/02/2019 10:34

Samme here, RTB. They obviously have my email address as when someone mentions me in a post I get a MN email to that email address of mine. so perhaps something went wrong with the 1m emails going out. It doesn't matter to me as I read about it on here.

RedToothBrush · 12/02/2019 09:08

I never did get an email from MN over this. I thought one went out to all users?

I don't need one as such, but MN should be aware that however they mailed people it seems to have failed.

And nope nothing in my spam and I regularly get MN emails.

Zapped into cyberspace oblivion.

Smotheroffive · 11/02/2019 16:26

I think you have it wrong again! Stop telling ME what I can and can't do, i.e. shutting me down! Leave off and mind yer own business. You came on here and had a go at me, your post, it wasn't the other way around so don't try to make it so.

LyingWitchInTheWardrobe2726 · 11/02/2019 15:54

Smother, you do you and I'll do me. Don't tell me what I can and cant post. You're welcome to your opinion and I'm glad I made that point in my previous post to you because you're doing exactly that.

I don't want to get into any more debate with you, I have better things to do. Let's leave it there.

Smotheroffive · 11/02/2019 15:42

Incorrect Lying as I said, two generic emails. One specific, and to what degree I am or not affected is irrelevant. Don't be shutting other users down, and no, its not 'the important^ thing, other users are suffering other issues, so again, don't be shutting down other users.

LyingWitchInTheWardrobe2726 · 11/02/2019 15:37

QwertyLou, I don't think we're disagreeing, no. My understanding was:

  1. E-mail to everybody registered saying exactly what's in the first post;
and
  1. Direct e-mail to anybody affected by the breach, ie. the 46 users.

I think the only mistake MNHQ really made was to promise the first (I haven't had one and really don't need one). The important contact, once the thread was posted, was with the users who were actually affected, ie. the 46.

We're not party to what's going on behind the scenes. Do we really need to be? I personally think not. I'd rather that MNHQ be busy 'pulling up the drawbridge' to prevent a recurrence than keep posting on the thread to keep users updated with the same status. Tell us all when it's done and everything's safeguarded, answer questions then if there are any.

I'm just very glad that it's not my job to look after it... we'd really be up shit creek!

Smotheroffive · 11/02/2019 13:10

There were 2 emails, not the email. Thanks qwerty

QwertyLou · 11/02/2019 12:29

Yes I thought the email was sent to everyone registered with the site. I.e. anyone who has signed up with an email address and username. I understand it was sent to 1 million addresses. So LyinwitchInWardrobe I don’t think we are in disagreement?

C8H10N4O2 · 11/02/2019 09:45

p.s. ALL data should have been encrypted not just passwords

Er so if someone sends me a pm with their email on, it should be encrypted. Just how do I read it then?

The same way you do now. Data is encrypted whether stored or in transit between points but as a user logged in through the authentication process you can read it.

This is standard practice and increasingly industry regulators are looking to encrypt all data not just sensitive data. There are a whole range of reasons for this, some legal, some technical but its perferctly possible to encrypt all data whilst making it available to users.

That is a seperate issue from whether it should be encrypted.

LyingWitchInTheWardrobe2726 · 11/02/2019 08:33

QwertyLou, the e-mail though was only going out to those registered. Anybody who was signed in or would have tried to access Mumsnet would have been forced to sign in again because the system was re--set.

QwertyLou · 11/02/2019 03:48

PS also smother I have appreciated your posts and those of others with insight into how it all works... so thanks to everyone who has taken the time to share insights.

QwertyLou · 11/02/2019 03:42

does it really still warrant this constant reminding about an e-mail that won't inform anybody of anything they don't already know

But not everyone does know about it. Yes, anyone who has read this thread or the FAQ one does. And some people in the UK might have seen it in the news.

But others have no idea. Which means they cannot take protective steps in response - like setting up a burner email address or whatever(which I hadn't realised we are supposed to - I only found out in response to this).

That is why the email send-out is important - not for any of us, but for others.

On a positive note.. I have now received the email! So hopefully others now have too.

Smotheroffive · 10/02/2019 17:32

Yes of course I am free to post and you are free to continually misconstrue my intent, don't need your statement telling us all we are free to post and reply, we all know this. You are, however, wrong about your nasty accusations of shit stirring. I am telling you you are wrong, and only I can know that, despite what you think. There is enough on this thread without any nastiness to derail.

LyingWitchInTheWardrobe2726 · 10/02/2019 17:23

Smother, I haven't read every post on this thread but days later your last one isn't in support or helpful to anybody, just casting more doubt when you don't know (none of us does). If not drama then just plain old stirring.

You're still free to post it though and so are others to respond.

Smotheroffive · 10/02/2019 17:15

You'd be wrong in that lying. If you look properly you will also see that I have posted in support of MN and helped them, and been acknowledged for that, so frankly have no idea what youre on about with your made up drama!

Downtroddenhousingass · 10/02/2019 17:12

Only the sensitive data needs to be encrypted.

I agree there's more at play here.

MN took years just to switch over to Https - such a simple change that only happened after they were hacked. It's always been quite amateur and not at the level you would expect for such a profitable site.

LyingWitchInTheWardrobe2726 · 10/02/2019 16:58

Smother, were you personally affected? Actually had the issue that Worra did? Or something else that actually happened to your account?

Why do you keep on about having this generic e-mail when it's already been stated that it will contain only what's already in the very first post of this thread? Is it just so that you can say that you've had it? I haven't had one, wasn't affected, assume that as it hasn't arrived that the sheer volume has caused a blockage and truly don't see the point.

As long as those 46 account holders - and anybody else who was actually affected - have been contacted by MNHQ then does it really still warrant this constant reminding about an e-mail that won't inform anybody of anything they don't already know.

If you really feel aggrieved then why not get in touch with MN directly instead of repetitively posting this very petty gripe here? It's starting to smack of rabble-rousing rather than anything genuine. You can't sensibly say that "Something a lot more gone on than being stated here", because you don't know that. It's speculating, nothing more. If you really believed what you're saying - and were concerned, you'd get in touch with MNHQ.

I absolutely think that for some posters, this is the most exciting thing to have happened for them since the last time when the sky didn't fall in.

RedToothBrush · 09/02/2019 19:31

p.s. ALL data should have been encrypted not just passwords.

Er so if someone sends me a pm with their email on, it should be encrypted. Just how do I read it then?

Or if I'm reading my own profile it should be encrypted to prevent the issue incase someone else is accidentally logged into my account.

Your entire family might work in system analytics for years, but I think you might have missed a bit of the issue here.

You know about users being able to use MN.

I thought user functionality was a pretty important feature of the Internet in addition to security. But my mistake.

Smotheroffive · 09/02/2019 19:04

Something a lot more gone on than being stated here, specifically wrt all the other unanswered issues also being encountered and ignored.

Not least that something's s a simple email has failed so abysmally. Still not received the promised email from two (or was it three) days ago now. The updated email blat clearly has worked. Its just not as simple as what it s being portrayed as.

PennyandVince · 09/02/2019 18:59

p.s. ALL data should have been encrypted not just passwords.

entire family have worked in Systems Analysis for years. No excuse.

PennyandVince · 09/02/2019 18:56

@MNHQ

deleting my account now.

Smotheroffive · 09/02/2019 16:51

Dox comes from the file format of word documents .doc and .dox its used to portray the way that online documents/data is taken and spread to a wider audience, often to discover and reveal to the world who an online user really is, so revealing their personal data from info taken from online dox.

Does that make sense? Its malicious data breaching to out people/info

AskingQuestionsAllTheTime · 09/02/2019 15:04

Thank you for all the effort you have put in, and for this very clear explanation of what happened.

For what it is worth, I got an email from you today, datestamped Sat, 9 Feb 2019 13:44:13 +0000 (UTC), in which dates and days of the week are given. It seems entirely clear, non-alarmist and reasonable to me.... But then, so did the original post in this thread.

Swipe left for the next trending thread