Flipboard resets passwords after data breach exposed users' details

What you need to know

  • Flipboard says hackers gain unauthorized access to its databases containing user details.
  • The databases in question included users' names, encrypted passwords and email addresses.
  • Flipboard is resetting passwords for millions of users as a precautionary measure.
  • Third-party accounts aren't affected, but Flipboard is also resetting tokens.

News aggregator Flipboard is the latest to succumb to a data breach, with the service noting that hackers gained unauthorized access to its databases containing users' account information. The breach occurred between June 2, 2018 and March 23, 2019 and April 21 – 22, 2019, with hackers making copies of users' name, Flipboard usernames, cryptographically protected passwords and email addresses.

Thankfully, Flipboard doesn't collect sensitive information like credit card details or government-issued IDs. The service set up an FAQ page to provide more information about the breach:

We recently identified unauthorized access to some of our databases containing certain Flipboard users' account information, including account credentials. In response to this discovery, we immediately launched an investigation and an external security firm was engaged to assist.Findings from the investigation indicate an unauthorized person accessed and potentially obtained copies of certain databases containing Flipboard user information between June 2, 2018 and March 23, 2019 and April 21 – 22, 2019.The databases involved contained some of our users' account information, including name, Flipboard username, cryptographically protected password and email address.

Flipboard says it switched to salted hashing to store all user passwords created or changed after March 14, 2012, which should make it extremely hard for the hackers to crack the passwords. The service also noted that it swithced out digital tokens for third-party accounts even though it didn't see any unauthorized access.

Flipboard is still "identifying the accounts involved," but the service is resetting all users' passwords as a precautionary measure:

As a precaution, we have reset all users' passwords, even though the passwords were cryptographically protected and not all users' account information was involved. You can continue to use Flipboard on devices from which you are already logged in. When you access your Flipboard account from a new device, or the next time you log into Flipboard after logging out of your account, you will be asked to create a new password.As another precautionary step, we disconnected tokens used to connect to all third-party accounts, and in collaboration with our partners, we replaced all digital tokens or deleted them where applicable.

Flipboard also says it implemented "enhanced security measures" to prevent a further breach in the future. If you're a Flipboard user, you should reset your password. For what it's worth, Flipboard handled this situation with aplomb, resetting passwords and tokens and adding safeguards to make sure this doesn't occur again.

Harish Jonnalagadda
Senior Editor - Asia

Harish Jonnalagadda is Android Central's Senior Editor of Asia. In his current role, he oversees the site's coverage of Chinese phone brands, networking products, and AV gear. He has been testing phones for over a decade, and has extensive experience in mobile hardware and the global semiconductor industry. Contact him on Twitter at @chunkynerd.