Reddit says a few employees had their work accounts hacked via 2FA SMS intercepts, leading to a few systems being compromised and some user data leaking
TL;DR: A hacker broke into a few of Reddit's systems and managed to access some user data, including some current email addresses …
Context & Ripple Effects
Reddit's disclosure that attackers intercepted SMS two-factor codes to get into employee work accounts is an early entry in what has become a recurring pattern for the company: hackers reached documents, code, and business systems again in its February 2023 cyberattack, and in between, attackers defaced more than a dozen subreddits with millions of subscribers in August 2020.
The mechanism matters more than the headline number of accounts. Two years later, a coordinated social engineering attack against Twitter employees showed how productive insider-access compromise is for attackers, while Cloudflare's experience with the same SMS phishing vector — where hardware MFA keys stopped hackers at the door — points to the fix the industry is converging on.
First-order effects
- Affected Reddit users learn their current email addresses were exposed, and Reddit must notify them and audit which internal systems the compromised employee accounts could reach.
Second-order effects
- The SMS-intercept vector puts pressure on every platform still relying on texted codes for staff authentication; Cloudflare's outcome shows hardware keys are the differentiator competitors will be measured against.
Third-order effects
- If the pattern holds — Reddit breached repeatedly across 2018, 2020, and 2023, Twitter's staff targeted directly — the industry's defensive center of gravity shifts from protecting user passwords to hardening employee access, with SMS 2FA treated as a liability rather than a control.
The trend: Attackers increasingly target employee authentication rather than user credentials, pushing major platforms to replace SMS-based two-factor authentication with hardware-backed MFA.