# Hack/break-in: New login from

**URL:** https://meta.discourse.org/t/hack-break-in-new-login-from/176286
**Category:** Support
**Created:** [January 16, 2021, 3:00pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286 "2021-01-16T15:00:33Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![richb-hanover](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@richb-hanover](https://meta.discourse.org/u/richb-hanover)
#### Post date: [January 16, 2021, 3:00pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/1 "2021-01-16T15:00:33Z")

</div>

Hi folks, I’m an admin on another Discourse system, and this morning I awoke to four email messages, which indicated an unauthorized login (see sample below).

I live in NH, US, so it is correct for Discourse to have flagged this log-in from Germany. I have always used a good password (15 letter, random, which I have now changed). I am in possession of the two computers which I ever used to log in.

A few questions:

1. Any idea how this might have happened?
2. My profile page showed another login (also “from Germany…”) in the 24 hours prior to the message below. But I did not receive a notification for that login - either in my inbox or my spam folder. How might that have happened?
3. It appears that the attacker may have exported the user list. Is it possible to tell if it was ever downloaded?
4. Do you have a standard playbook/procedure for notifying users?
5. What other information could I provide to diagnose or investigate this?

Many thanks.

[Sorry if this isn’t the right category. [@moderators](https://meta.discourse.org/groups/moderators) - please move to the right place. Thanks.]

> [@](#):
>
> ====== Note received overnight =======
> 
> > Begin forwarded message:  
> > **From:** XXX Forum \<[mail@xxx-forum](mailto:mail@xxx-forum)\>  
> > **Subject:** **[xxx Forum] New Login from Germany**  
> > **Date:** January 15, 2021 at 11:04:14 PM EST  
> > **To:** [my-email](mailto:my-email@gmail.com)  
> > **Reply-To:** xxx Forum \<[mail@xxx-forum](mailto:mail@xxx-forum)\>
> > 
> > Hello,
> > 
> > We noticed a login from a device or location you don’t usually use. Was this you?
> > 
> > - Location: Germany (2a0b:f4c2:2::1)
> > - Browser: Firefox
> > - Device: Windows Computer – Microsoft Windows
> > 
> > If this was you, great! There’s nothing else you need to do.
> > 
> > If this was not you, please [review your existing sessions](https://xxx-forum/my/preferences/account) and consider changing your password.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [January 16, 2021, 3:39pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/2 "2021-01-16T15:39:24Z")

</div>

Do you have 2FA activated? If not get that added ASAP

---

<div class="post-metadata">

### Author: ![richb-hanover](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@richb-hanover](https://meta.discourse.org/u/richb-hanover)
#### Post date: [January 16, 2021, 3:43pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/3 "2021-01-16T15:43:17Z")

</div>

I don’t, but will activate 2FA. Any thoughts on the other questions? Thanks.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [January 16, 2021, 6:54pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/4 "2021-01-16T18:54:44Z")

</div>

> [@richb-hanover](#):
>
> Any idea how this might have happened?

Password reuse, weak passwords, keyloggers, shared wifi networks, etc

> [@richb-hanover](#):
>
> It appears that the attacker may have exported the user list. Is it possible to tell if it was ever downloaded?

Nginx logs.

> [@richb-hanover](#):
>
> Do you have a standard playbook/procedure for notifying users?

If the attacked may have obtained a backup, which needs email access too, there is [What to do if your Discourse is compromised](https://meta.discourse.org/t/what-to-do-if-your-discourse-is-compromised/40129)

If not, a banner topic or a topic in a category everyone is notified may suffice.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [January 16, 2021, 11:04pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/5 "2021-01-16T23:04:04Z")

</div>

And that was while you were asleep? It’s not possible that you got a new Ipv6 address that maxmind just had the wrong location for?

---

<div class="post-metadata">

### Author: ![richb-hanover](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@richb-hanover](https://meta.discourse.org/u/richb-hanover)
#### Post date: [January 16, 2021, 11:24pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/6 "2021-01-16T23:24:52Z")

</div>

Thanks for the note.

- Yes, I was asleep

- That IPv6 address is not from my range (I take from Hurricane Electric, in the 2001:470:… range)

- We have evidence that the intruder attempted to add their email to an admin account, download the user list, and get the database backup. No access was granted to the new email address; we assume they retrieved the user list; but that they could not get the latter (the database) because they had not yet got email address.

So we assume emails and handles have been compromised, but that the database has not been downloaded (nginx logs).

Are there other things we should look for? Many thanks.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [January 17, 2021, 1:57am UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/7 "2021-01-17T01:57:44Z")

</div>

Great to hear 3 of our protections were useful:

- Invader couldn’t get backups because of the needed email flow

- Invader couldn’t get admin on a email that he controls because there is emails to confirm to both addresses

- Warning emails when login happens from far away

One thing that you should check is if Discourse is running the most recent version so it’s patched against any know vulnerabilities.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [January 19, 2021, 5:49am UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/8 "2021-01-19T05:49:45Z")

</div>

Yes, and each of those protections was individually added after a hard-earned lesson, so it’s especially satisfying to see them all working together in tandem! 🙌

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [October 28, 2023, 6:50pm UTC](https://meta.discourse.org/t/hack-break-in-new-login-from/176286/9 "2023-10-28T18:50:30Z")

</div>


