Data breach?

Author
Discussion

Lord Flashheart

Original Poster:

3,767 posts

193 months

Tuesday 11th February 2020
quotequote all
When I try signing into PH today, Chrome tells me there has been a data breach on a site that has exposed my password and that I should create a new password. It's not happening to other sites that I sign into, so is there a breach at PH?

AJB88

12,421 posts

171 months

Tuesday 11th February 2020
quotequote all
Doubt it, you can check on haveibeenpwned its probably detecting that your password for here is listed.

BenLowden

6,035 posts

177 months

PH Marketing Bloke

Wednesday 12th February 2020
quotequote all
This seems to be standard across most websites following an update from Google that will essentially flag up a warning on any site you use your email address to log in. Some more details here: https://support.google.com/chrome/thread/23534509?...

As above you can use this site to see if your email address has been compromised and if so where: https://haveibeenpwned.com/

afrere_ph

48 posts

61 months

PH TEAM

Wednesday 12th February 2020
quotequote all
Hi Lord Flashheart,

As BenLowden and AJB88 have said, what you're seeing is a built in Google Chrome feature which lets you know when it detects that the username/password combination you are using is in its known list of breached user info.

What this basically means is that either, some site that you use this username/password with has been breached, or at some point you may have been phished into entering it on a malicious site, and Google is aware of this and is recommending you change this password on all sites you use it on.

So to confirm, this isn't a PistonHeads breach, however you should probably change this password on here, and other sites you use this on. Also suggest checking https://haveibeenpwned.com/ as suggested ^

More info can be found here around the Chrome security feature - https://security.googleblog.com/2019/12/better-pas...

Cheers!

Lord Flashheart

Original Poster:

3,767 posts

193 months

Wednesday 12th February 2020
quotequote all
Thank you people. Just been told my details have been compromised in 7 sites including Dropbox and LinkedIn.
Time for a change me thinks!

dhutch

14,388 posts

197 months

Thursday 20th February 2020
quotequote all
Also worth not using the same PW for all sites.

Even if you use the same core PW, with a small site specific tweak, you are much more secure.


Daniel