Important ➤ No, #Slack has not been breached again. Company is just sending a quick notification to all those users who have not changed their password since 2015 #databreach and decided to reset passwords for all of them as a precautionary step.
That's probably because someone had successfully cracked passwords that were leaked during the 2015 Slack data breach, even when the company used bcrypt hashing algorithm with a randomly generated salt per-password.
Late last month, many #Slack users received a similar personalized breach notification from the company, as shown in the screenshot people shared online, without giving any explanation on what exactly happened.
When one of the affected users contacted Slack, the company said someone sent them a list of username and plaintext password combinations, which matches with the credentials of their users who have not changed their passwords in recent years.
When one of the affected users contacted Slack, the company said someone sent them a list of username and plaintext password combinations, which matches with the credentials of their users who have not changed their passwords in recent years. https://t.co/1GFaU8OEZ7