yitit
Home
/
Computing
/
Reddit hacker demands $4.5M and a change to new API rule
Reddit hacker demands $4.5M and a change to new API rule-February 2024
Feb 12, 2026 1:03 AM

  Ransomware group BlackCat has claimed responsibility for the cyberattack on Reddit in February and is now demanding a $4.5 million payment to prevent it from publishing 80GB of data that it claims to have stolen from the site.

  But that’s not all, as the group, which is also known as ALPHV, is insisting that Reddit also reverse the API price changes that have caused so much controversy just recently.

  Recommended Videos

  In a message posted by the group this week, the perpetrator said: “We are very confident that Reddit will not pay any money for their data. But I am very happy to know that the public will be able to read about all the statistics they track about their users and all the interesting confidential data we took … In our last email to them, we stated that we wanted $4.5 million in exchange for the deletion of the data and our silence.”

  Related

  Qualcomm says its new chips are 4.5 times faster at AI than rivals Over 2.5B Reddit users flee to protest API changes Hackers stole $1.5 million using credit card data bought on the dark web

  Several days after it learned of the February incident — described by Reddit as a “sophisticated and highly targeted” phishing attack — a spokesperson for Reddit confirmed that hackers had accessed some of the site’s internal documents, dashboards, code, and business systems. Data linked to current and former employees, company contracts, and some advertisers were also accessed. Passwords and other data connected to user accounts were not thought to have been compromised, Reddit said at the time.

  BlackCat also wants Reddit to abandon its move to start charging third-party apps for API access, which could potentially cost some developers millions of dollars annually and force a number of popular ones to shut down. Many subreddits have been protesting about the changes, but Reddit’s top team seems intent on sticking to its plan.

  BlackCat emerged in November 2021 and by July 2022 had compromised more than 100 organizations, according to Security Week. The group appears to have been quite active recently, too, launching an attack on Western Digital in March that apparently saw 10 terabytes of data stolen, while it also recently threatened to release data allegedly stolen from Amazon-owned video doorbell company Ring.

Comments
Welcome to yitit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Login to display more comments
Computing
Recent News
Copyright 2023-2026 - www.yitit.com All Rights Reserved