← Hootsuite

2013 OAuth compromise — 7,000 accounts

2013 7.0K records affected Share on X

Data compromised

Account access; spam posting

Technical writeup

Approximately 7,000 Hootsuite accounts compromised via credential stuffing through a third-party OAuth application. Attackers used credentials from other sources to log in and tweet spam. Hootsuite's own software was not hacked.

Root cause

Credential stuffing; OAuth third-party application.

References