Data breach
Linux Mint
- Records
- 144,706
- Breach date
- 21 February 2016Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 2 more reported · 1 puts you at serious risk
- Usernames144,705
- Email addresses144,654
- IP addresses140,644
- Passwords76,650
- Private messagesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In February 2016, the Linux Mint project confirmed that attackers compromised its website and its user forum database. Our investigation team estimates the breach date as February 21, 2016, and the indexed forum dump contains 144,706 rows, including nearly 145,000 email addresses and usernames, roughly 76,650 passwords, and about 140,644 IP addresses. Around the same time, the Linux Mint website briefly served an altered download: visitors who downloaded the Mint 17.3 Cinnamon edition on February 20, 2016, may have received an installation image with a backdoor built in.
Breach Timeline
February 20, 2016: Servers hosting the Linux Mint website were compromised, and the site briefly pointed to a modified version of Mint 17.3 Cinnamon containing a backdoor, according to reporting by Hackaday.
February 21, 2016: Linux Mint confirmed on its blog that the forums database had been compromised during the attack and that the attackers had obtained a copy, urging all forum users to change their passwords (Linux Mint blog).
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, usernames or nicknames, passwords, and IP addresses.
The company's own notice, published on the Linux Mint blog, listed additional contents of the forum database: an encrypted copy of each user's forum password, any personal information a user placed in their signature or profile, and any personal information written on the forums, including private topics and private messages. In the same thread, the project's maintainer noted that the forums also store the IP address used during a user's last connection and that birthday information was set on around 9 percent of accounts.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The forum passwords were stored in encrypted form rather than plain text, which limits exposure, but the project warned at the time that encrypted passwords can still be brute forced if they are simple or guessable from personal details. People whose forum password matched their email password or a password used on other sensitive sites face the greatest risk.
Exposed email addresses and usernames are also valuable to attackers. They can be used for phishing emails that quote real details from the forum to appear legitimate, or for credential stuffing attempts against other sites if passwords were reused. IP addresses and profile details can help attackers build more convincing targeted messages. The backdoored installation image posed a separate risk to the small group of people who downloaded Mint 17.3 Cinnamon on February 20, 2016.
What Is Linux Mint Doing in Response?
After discovering the compromise, Linux Mint took its website and forum servers offline, and the project said it implemented enhanced security configurations for both. On its blog, the team told forum users to change their passwords on all sensitive websites, starting with their email password, and advised against reusing the same password across sites. The forums were later brought back online after being updated to a newer version of the phpBB forum software, according to discussion in the project's own blog thread.
What Should You Do If You Were Affected?
If you had an account on forums.linuxmint.com, change that password immediately, and change it anywhere else you used the same one. Start with your email account, since it can be used to reset access to other services. Turn on two-factor authentication where sites offer it. Be cautious with unexpected emails that reference Linux Mint, your forum activity, or your account details, as these may be phishing attempts. If you downloaded Linux Mint 17.3 Cinnamon on February 20, 2016, reinstall the operating system from an official, verified copy and change passwords stored on that machine.
