Uh oh.
I hope they have a nice GDPR compliant deletion policy and my account is long gone.
So at least they get some old accounts to become active again :D
The VPN access disruption suggests the breach may be deeper than initially disclosed. If you used the same password on banking, email, or other sensitive accounts, change those first.
For anyone managing 50+ accounts: automated password rotation tools exist now that can handle the tedious clicking through each site. Saves hours vs manual changes.
The Password App does this on macOS - full disclosure, I'm affiliated, but the general advice stands: don't wait for breach notifications to rotate credentials.
My understanding is that this prevents anonymous access to servers which would help during investigation if any further unauthorized access showed up. But it doesn't confirm that unauthorized access continued. Just curious how you are thinking about this though.
owlninja•6h ago
https://news.ycombinator.com/item?id=46269891