• BlueÆther@no.lastname.nz
    link
    fedilink
    arrow-up
    3
    ·
    2 年前

    The attack shouldn’t have exposed passwords or hashes, only the JWT cookie. The secret on the server has been changed so all old cookies should no longer work.

    There is a very small possibility that email address may have been able to be seen if they logged is as you, but they were looking for admin accounts