bit.ly urges users to change account details after hackers break in

Bit.ly pufferfish
Bit.ly's security defenses have been overrun

Link-shortening service bit.ly has issued a warning to its users that account information may have been compromised. The firm says there is no indication that any accounts have been accessed, but that it has taken proactive steps to ensure that accounts have been secured.

In order to help protect users, Facebook and Twitter accounts that were linked to bit.ly accounts have been disconnected. bit.ly has advised users to change their API key and OAuth tokens, reset their passwords and reconnect any Facebook and Twitter accounts that may have been disconnected.

Security guidance

The following guidance has been issued to users to ensure the security of accounts:

  • Log in to your account and click on 'Your Settings,' then the 'Advanced' tab.
  • At the bottom of the 'Advanced' tab, select 'Reset' next to 'Legacy API key.'
  • Copy down your new API key and change it in all applications. These can include social publishers, share buttons and mobile apps.
  • Go to the 'Profile' tab and reset your password.
  • Disconnect and reconnect any applications that use Bitly. You can check which accounts are connected under the 'Connected Accounts' tab in 'Your Settings.'

No specific details of how the suspected attack was carried out have been provided, but bit.ly's CEO Mark Josephson said in a blog post, "We have already taken proactive measures to secure all paths that led to the compromise and ensure the security of all account credentials going forward."

As part of his blog post, Josephson apologized to bit.ly users and advised that further updates would be announced on the company's Twitter account.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras