Jump to content

Locked Password Reset Precaution


Unleashed2k

Recommended Posts

  • Administrator

There is a new forum spam attack happening that is using compromised accounts from previously hacked accounts on other websites. Out of precaution and to prevent old accounts from being used we've reset all passwords for accounts not logged in for over a year. We always recommend all users update their passwords (unique passwords recommended!) and use two-factor authentication for security. You can always check to see if your account has been compromised on another service by using this website: https://haveibeenpwned.com/.

Our forum software was trying to send a notification to all users that have been reset but that caused our IP to be blacklisted for spamming... Ironic lol so I've canceled those emails and requested a delisting. However, that may mean that sending a new password reset request or account validation emails may not be sent. I apologize for the inconvenience we will happily help you in the support channel of our Discord: https://discord.gg/cf

 

 

Additional Links:

Update your password: https://customsforge.com/index.php?/settings/password/

Enable Two Factor: https://customsforge.com/index.php?/settings/account-security/

Request to Delete Your Account: https://customsforge.com/index.php?/settings/deletemyaccount/

 

  • Like 5
  • Thanks 4

"Just remember: when something breaks, kick it as hard as you fucking can"

-Trent Reznor
Support Me (Via Patreon)

Link to comment
Share on other sites

  • 7 months later...
  • Administrator

I just wanted to provide an important update to the community. A data leak was reported to me through Discord. After investigating and finding said leak, I can confirm that this list was scraped data from preexisting leaks from other websites, matching usernames or emails from these other databases to CF. This is the same leak mentioned in Jan, just reuploaded to another site.

I can also confirm the accounts affected were only ones created in 2014-2018. As a precaution, I have forced a reset and cleared those hashes from our database. I also applied additional protections on the backend just in case. If you created an account between 2014-2018 and you're unable to login, most likely you are an account that has been affected. 
You can always search your email here as well: https://haveibeenpwned.com/

If you're having login issues and you are unable to reset your password, please use this Discord Forum thread: https://discord.com/channels/133319143339327488/1144904202531897396

  • Thanks 2

"Just remember: when something breaks, kick it as hard as you fucking can"

-Trent Reznor
Support Me (Via Patreon)

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

By using this site, you agree to our Guidelines. We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. - Privacy Policy