DevKitPro has been pwned – change your credentials

The forum database of DevKitPro has been stolen, and it is being spread on dumps which can be found on PasteBin and AnonFiles.

DevKitPro shared their news of being compromised on the 4th of February 2019. In this message they shared the following:


The devkitPro forums were compromised this evening and the phpbb3 database was stolen & vandalised. If you have a forum account please check you haven’t reused passwords elsewhere. Sadly only working db backup is from 2017. Forums currently disabled.

DevKitPro

On the 8th of February they shared that they were able to recover the forum database. This again allowed DevKitPro to re-enable their forum service.


We have managed to recover the forum database and re-enable the forums. More information at https://devkitpro.org/viewtopic.php?f=13&t=8846 … Apologies for not getting email out sooner.

DevKitPro

On the 9th of February 2019, DevKitPro shared on their Twitter account that the stolen database is being shared on the web. DevKitPro urges all her users to change their credentials, and to verify if they are not using those credentials on any other website.


The stolen database has turned up in dumps on http://pastebin.com  and anonfiles. Please change your passwords and spread the word. https://devkitpro.org/viewtopic.php?f=13&t=8846&p=16273#p16273 …

DevKitPro