500px global network for photographers and the platform managing around 16 million users who get paid for their work and skills.
In this case, Intruder accessed the user’s sensitive information including
first and last name, username, email address, hashed password, Date of birth, city, state/province, country, and gender.
500px Engineering team already deployed to mitigate
The company said that users who have opt-in prior to July 5, 2018, are potential victims of this data breach and the company notify to all users via email as well as onsite and with mobile notifications, however, given the volume of users affected.
According to 500px, following Steps are taken to protect their customer from future attacks.
- Given the nature of the personal data involved, we have already forced a reset of all MD5-encrypted passwords, and a system-wide password reset is underway.
- We have vetted access to our servers, databases, and other sensitive data-storage services.
- We have and are continuing to monitor our source code, both public-facing and internal, to protect against security issues.
- We are partnering with leading experts in cyber security to further secure our website, mobile apps, internal systems, and security processes.
- We are modifying our internal software development process.
- We are continuing to upgrade our network infrastructure.
The company also states that it’s alerted the enforcement and has retained a private security firm to investigate the issue.