BreachExchange mailing list archives

Fwd: Information on your DreamHost account - please change your passwords


From: Steve Darrall <steve () darrall com>
Date: Mon, 23 Jan 2012 09:11:08 +1030

---------- Forwarded message ----------
From: <do.not.reply () dreamhost com>
Date: 22 January 2012 02:15
Subject: Information on your DreamHost account - please change your
passwords
To: user () domain com


IMPORTANT INFORMATION: We are writing to let you know that there may have
been illegal and unauthorized access to some of your passwords at DreamHost
today. Our security systems detected the potential breach this morning and
we immediately took the defensive precaution of expiring and resetting all
FTP/shell access passwords for all DreamHost customers and their users.
There are three different types of passwords at DreamHost: a web panel
password (for logging into the panel), email passwords, and FTP/shell
access passwords. Only the FTP/shell access passwords appear to have been
compromised by the illegal access. Web panel passwords, email passwords and
billing information for DreamHost customers were not affected or accessed.
Refer to the following DreamHost status post for details:
<http://www.dreamhoststatus.com/2012/01/20/changing-ftpshell-passwords-due-to-security-issue/>
http://www.dreamhoststatus.com/2012/01/20/changing-ftpshell-passwords-due-to-security-issue/
.

IMPORTANT ACTION REQUIRED:

   1. To create a new FTP/shell access password for your DreamHost account,
   please login to your DreamHost web panel (https://panel.dreamhost.com/),
   select "Manage Users" in the top left, then select "Edit" next to each user
   and type in a new password. Make sure you click "Save Changes" at the
   bottom of the page.
   2. We are also requesting that you change your email password. We are
   not enforcing this change at this time as we do not believe that email p
   asswords were compromised. However we strongly recommend that you change
   your email password as a precaution. To change the passwords for your email
   users or yourself, log into the DreamHost panel at (
   https://panel.dreamhost.com/), select "Manage Email" in the top left,
   select "Edit" next to each email user address, and choose a new password
   for each. Make sure you click "Save Changes" at the bottom of the page.

We sincerely apologize for any inconvenience this may cause. If you have
any additional questions about this process, please contact us through the
support page in the panel.

Note that DreamHost will never ask you for personal or account information
in an email. Please exercise caution if you receive any other emails that
ask for personal information or direct you to a web site where you are
asked to provide personal information.

Sincerely,

The DreamHost Team
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Small, inexpensive USB drives pose huge threats to organizations left unprotected. 
Download Chapter 1 of CREDANT Technologies eBook
Data Protection to the Rescue
http://www.credant.com/campaigns/external_media_ebook/chapter1/lp/

Current thread: