HipChat Hackers May Have Nabbed User Info, Chat Content

hipchat-hackers-may-have-nabbed-user-info-chat-content photo 1

Do you use HipChat at work? Sorry to report, but the communication platform has been breached.

HipChat maker Atlassian on Monday said its Security Intelligence Team discovered the intrusion over the weekend. Hackers leveraged a vulnerability in a "popular third-party library used by HipChat.com" to access content from the service, Atlassian Chief Security Officer Ganesh Krishnan wrote in blog post.

The hackers may have accessed and made away with user account information including names, email addresses, and hashed passwords, along with metadata like the room name and topic.

In a smaller number of cases, the hackers may have also stolen the messages and other content in rooms — a potential worst-case scenario for businesses. Krishnan said HipChat is contacting and plans to "work closely" with customers who had their internal communications breached.

"For the vast majority of instances (more than 99.95 percent), we have found no evidence that messages or content in rooms have been accessed," Krishnan wrote. "Additionally, we have found no evidence of unauthorized access to financial and/or credit card information."

Related

  • The Best Online Collaboration Software of 2017The Best Online Collaboration Software of 2017

HipChat issued a password reset for affected users. If you use HipChat.com, watch out for an email from the company's security team with instructions on resetting your password. HipChat is only sending these messages to impacted customers; if you don't get an email it's because the company found "no evidence" that you're affected by the breach, Krishnan wrote.

Atlassian is also currently working with law enforcement to investigate the incident. The company is readying an update for the HipChat server that will roll out via the standard update channel.

"We are confident we have isolated the affected systems and closed any unauthorized access," Krishnan wrote. "We have found no evidence of other Atlassian systems or products being affected."

Recommended stories

The Drone User Experience and Design

DRONE ENTHUSIASM Drones have been taking the nation by the rage. In the last few years, drones have been used to take photos for news publications. Recently, th...

Relax HipChat Hackers May Have Nabbed User Info, Chat Content stories

Chrome Blocks Crafty URL Phishing Method

By using non-Latin Unicode characters, it's theoretically possible to register a domain name for a phishing website that looks nearly identical to the one it's trying to spoof.

How to Hack Wi-Fi Passwords

Your intensions when cracking a Wi-Fi password are no doubt noble—we trust you—so here's how to do it.

More stories