Mozilla accidentally leaks 76,000 developers' email addresses, 4,000 passwords

Firefox
Leaky times for the Firefox maker

Firefox maker Mozilla has fallen foul to a security breach that exposed personal data relating to members of its Mozilla Developer Network (MDN).

In a co-authored blog post, Stormy Peters, head of Mozilla's developers unit, and Joe Stevenson, its head security honcho, wrote that a failed data sanitization process of the MDN's site database caused email addresses belonging to 76,000 users and encrypted passwords of around 4,000 users to be dumped onto a publicly viewable server.

The snafu went unnoticed for 30 days until being picked up by a web developer on July 23, according to Mozilla, which immediately removed the data dump from the server and disabled the offending process.

Safe move

The company wrote that it hasn't detected any malicious activity on the server in question but encouraged users to change their login details to be on the safe side.

"The encrypted passwords were salted hashes and they by themselves cannot be used to authenticate with the MDN website today," Peters and Stevenson wrote. "Still, it is possible that some MDN users could have reused their original MDN passwords on other non-Mozilla websites or authentication systems.

"We've sent notices to the users who were affected. For those that had both email and encrypted passwords disclosed, we recommended that they change any similar passwords they may be using."

Kane Fulton
Kane has been fascinated by the endless possibilities of computers since first getting his hands on an Amiga 500+ back in 1991. These days he mostly lives in realm of VR, where he's working his way into the world Paddleball rankings in Rec Room.
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Stress
Complexity of IT systems could be increasing security risks for businesses
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
CEOs think they might lose their jobs if they can't deliver on AI
Tony Hawk's Pro Skater 3+4
From Ace of Spades to Them Bones, Tony Hawk's Pro Skater 3+4's soundtrack is already looking excellent
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD describes its recent RDNA 4 GPU launch as 'unprecedented' and promises restocking the Radeon RX 9070 XT as 'priority number one'
The Google Gemini logo against a black background.
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's upcoming Flash 2.0 built-in image upgrade
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature