← Stack Overflow

2019 Stack Overflow — production intrusion; source code and 184 users’ PII

2019 184 records affected Share on X

Data compromised

Email, name, IP for 184 accounts per company; source code segments per attacker dwell-time narratives

Technical writeup

Stack Overflow disclosed unauthorized activity beginning in late April 2019 with escalation on May 11, 2019. An attacker reached build/source-control paths, abused a misconfigured JetBrains TeamCity server to obtain broad privileges, and exfiltrated some repository content. A 2021 retrospective stated about 184 users had email address, display name, and IP address exposed, while the company emphasized that databases holding the public Q&A corpus and private Teams/Talent/Enterprise customer datasets were not exfiltrated in the incident as characterized.

Root cause

Build-pipeline / CI misconfiguration enabling privilege escalation from development-tier access

References