Slack, the company that initially introduced the world to collaboration tools as we know them today, recently announced that it would be resetting thousands of passwords for some of its users. The decision to reset passwords has been made after new information came to light about a security breach that happened all the way back in 2015!
According to Slack, anyone currently using the software that created their account before this date and haven't changed their passwords since will potentially have their password reset automatically. According to Slack, only 1% of its users overall will require a security update - which equates to about 65,000 users overall.
The 2015 Password Hack
Slack announced that it had chosen to start resetting passwords in a disclosure notice posted on the 18th of July this year. According to the document, Slack has recently revealed details of possibly compromised user credentials, sent through it's "bug bounty" program. This program essentially asks the hacker community to "do their worst" on the Slack platform and see whether they can access any personal details or data.
The company linked the issues outlined in the Bug Bounty report to a hack that had occurred back in 2015, where hackers had been able to insert code for keylogging into the software. This code meant that the hackers could potentially read user passwords when they entered them. The hackers also had access to lists of usernames and hashed passwords too.
The discovery has led to the passwords for all of the user accounts active during the time of this breach is instantly reset. However, you won't have had your password reset if you use a single sign-on solution, or you already changed your password sometime after March 2015.




