After a few days of downtime, BrickLink is now back up and running with operations seemingly back to normal. As confirmed, they did get a ransom letter and from their investigations and they’ve been looking into some suspicious activity on the site since October. At this point, they suggested that it was a credential stuffing event in which cybercriminals use stolen usernames and passwords from another site to access BrickLink. As a result, you’ll have to change your passwords when you access the site and suggest not using the same ones as for other sites.
Welcome back and thank you for your patience. We were down for longer than anyone would have wanted. Now that we’re back up and running, we can share with you what’s happened.
As many of you will know, we received a threat and ransom demand on Friday, November 3rd. We’d been aware of and actively managing some limited suspicious activity since mid-October, with unauthorized sellers offering products at huge discounts and fraudulently accepting payment from buyers.
As soon as we were aware of the potential escalation on November 3rd, we put the site into maintenance mode out of an abundance of caution. We did this to protect our members and keep complete control of the platform while investigating.
We found that a relatively small number of BrickLink accounts may have been accessed. It is important to note that there is no evidence so far that our systems were compromised.
At this stage we believe this was a ‘credential stuffing’ incident, where
…
Continue