Close Menu
The Politic ReviewThe Politic Review
  • Home
  • News
  • United States
  • World
  • Politics
  • Elections
  • Congress
  • Business
  • Economy
  • Money
  • Tech
Trending

Wayne Root Reports on Two Opposites – A Great Woman Put in Prison, Tina Peters, Versus a Vicious Commie Witch Who Could be in Prison for Mortgage Fraud, NY Attorney General Leticia James

May 13, 2025

Megan Fudge Takes Over All-Time Association Of Pickleball Players Medal List At Vlasic Classic Cincinnati

May 13, 2025

Report: Hamas Tortured American-Israeli Hostage Edan Alexander; Handcuffed in Cage

May 13, 2025
Facebook X (Twitter) Instagram
  • Donald Trump
  • Kamala Harris
  • Elections 2024
  • Elon Musk
  • Israel War
  • Ukraine War
  • Policy
  • Immigration
Facebook X (Twitter) Instagram
The Politic ReviewThe Politic Review
Newsletter
Tuesday, May 13
  • Home
  • News
  • United States
  • World
  • Politics
  • Elections
  • Congress
  • Business
  • Economy
  • Money
  • Tech
The Politic ReviewThe Politic Review
  • United States
  • World
  • Politics
  • Elections
  • Congress
  • Business
  • Economy
  • Money
  • Tech
Home»Tech»Wikipedia Owners Will Require Increased Security After 35,000+ Accounts Compromised
Tech

Wikipedia Owners Will Require Increased Security After 35,000+ Accounts Compromised

Press RoomBy Press RoomMay 12, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram

The Foundation that owns Wikipedia is preparing to require two-factor authentication for users with significant privileges starting in late May. It comes after the Foundation announced in March that they had locked 35,893 accounts across all Foundation-owned sites upon determining the passwords had been compromised. According to the announcement, the Foundation suspected this was due to account names and passwords being used on another compromised site.

Most accounts were said to be low-activity with only 2 percent having made over 100 edits with no evidence of the accounts being significantly misused. One Wikipedia account compromised a week prior to the announcement made nearly 1,000 edits in the preceding year. Previous hacking incidents had already led to increased password requirements for those with admin privileges.

Foundation staff published the intended requirements on May 6 in order to invite community input before it is implemented on May 20. Citing the recent breach, the announcement stated they had “begun technically enforcing mandatory two-factor authentication for wiki interface administrators” who can edit sitewide javascript pages. The announcement stated that the new requirements for two-factor authentication would be limited to checkusers, who can access private account information, and oversighters who can delete content so that even regular admins cannot see it. Regular administrators have the authority to suspend user accounts and delete content.

Expansion to bureaucrats, users who have the privileges to appoint and remove administrators, was also contemplated. They acknowledged difficulties in requiring authentication and “intend to expand the accessibility and security of our 2FA capabilities, such as allowing users to set up multiple authenticators, and to more fully support modern phishing-resistant methods like security keys and passkeys” to make it easier for those subjected to the requirements. Currently, they state two-factor authentication is only available to users with privileged access, but will investigate enabling the option for all users. Two-factor authentication means logging in to an account requires providing additional verification beyond a password, such as a code sent to a mobile device.

Announcement of the recent hacking incidents was published on March 27. In the announcement, they stated the Foundation “in collaboration with volunteer functionaries, recently identified a pattern of unusual log-ins to registered accounts.” The tens of thousands of accounts identified as compromised were then locked and account-holders notified by e-mail where possible. Wikipedia does not require e-mail for account registration. Staff believed the compromise was due to “credential stuffing” where hackers “find stolen usernames and passwords and attempt to use those same combinations across a variety of other websites and accounts.” Details of the accounts, such as “email addresses, time zones, and other profile settings” were noted to be accessible.

Staff emphasized that they did not believe their site’s systems were compromised or that there was a targeted attack, further adding that “mostly inactive or low-activity accounts” were compromised with just 2 percent having over 100 edits. An update the next day stated they had “not seen evidence of significant malicious editing activity from any compromised account” to any Foundation-owned sites, but were still investigating. No further updates on the breach itself have yet been provided.

One account compromised a week prior to the announcement was “CoffeeCrumbs” on Wikipedia. The editor mentioned contacting the address for compromised accounts, but raised it publicly to quickly have the account locked. Coffee Crumbs also mentioned having received warning of the account password appearing somewhere else before the compromise occurred. Admin “Spicy” who possesses checkuser privileges on Wikipedia confirmed the compromise and remarked that this was “Along with some others” adding it would “be a long night in the CU mines.” Unlike most accounts mentioned in the Foundation announcement, CoffeeCrumbs had over a thousand edits when the account was compromised.

In a thread on Wikipedia criticism forum Wikipediocracy, where the editor used the same username and password, the editor posted that the notification received from Google about the password appearing on another site did not clearly identify the source, but it “was found somewhere eight months ago.” CoffeeCrumbs noted the Foundation Trust and Safety Team was able to restore access to the account, but did not know if the compromise was related to the wider breach.

Previous hacking incidents have caused significant problems for Wikipedia. Back in 2018, multiple accounts were compromised, including admin accounts, and used to vandalize Wikipedia articles. This included edits replacing the top image of Donald Trump on his article with a penis. Six admin accounts that were compromised at that time and months later, including one that vandalized articles related to YouTuber PewDiePie’s feud with Indian music company T-Series, were locked and temporarily stripped of their privileges by the Arbitration Committee, often compared to a Supreme Court, with some never unlocked. The Committee eventually adopted stricter practices for admins who violate the site’s password policy and the Wikimedia Foundation also adopted tighter password requirements.

T. D. Adler edited Wikipedia as The Devil’s Advocate. He was banned after privately reporting conflict of interest editing by one of the site’s administrators. Due to previous witch-hunts led by mainstream Wikipedians against their critics, Adler writes under an alias.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link

Related Articles

Tech

Report: Chinese Companies Can Still Access AI Tools Through Microsoft Despite OpenAI Ban

May 12, 2025
Tech

Chinese Payment Firm Probed by FBI Has Biden-Linked Backer

May 12, 2025
Tech

Media Research Center: Meta ‘Nudged’ Big Tech Critic for Support Ahead of FTC Antitrust Trial

May 12, 2025
Tech

Equipment Issues Grind Air Traffic to a Halt in Newark and Atlanta

May 12, 2025
Tech

Pope Cites Artificial Intelligence, Tech Boom for Choosing Leo XIV

May 10, 2025
Tech

Theranos Fraudster Elizabeth Holmes Loses Latest Bid for Appeal Hearing

May 10, 2025
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Megan Fudge Takes Over All-Time Association Of Pickleball Players Medal List At Vlasic Classic Cincinnati

May 13, 2025

Report: Hamas Tortured American-Israeli Hostage Edan Alexander; Handcuffed in Cage

May 13, 2025

Exclusive: Author of Shocking Abortion Pill Study Suggesting Higher Complication Rate Calls On Trump’s FDA to Conduct Its Own Research

May 13, 2025

Got coke? Just cope: Macron’s Ukraine trip was powered by drug-like delusion

May 13, 2025
Latest News

HUGE WIN: Federal Judge Gives Green Light for IRS to Share Illegal Immigrants’ Tax Data with ICE

May 13, 2025

Game Shows, Sports, Animation And Gordon Ramsay; Scripted Is Thin

May 13, 2025

Visa of Mexican Governor, Husband Revoked by U.S. State Department

May 13, 2025

Subscribe to News

Get the latest politics news and updates directly to your inbox.

The Politic Review is your one-stop website for the latest politics news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Instagram Pinterest YouTube
Latest Articles

Wayne Root Reports on Two Opposites – A Great Woman Put in Prison, Tina Peters, Versus a Vicious Commie Witch Who Could be in Prison for Mortgage Fraud, NY Attorney General Leticia James

May 13, 2025

Megan Fudge Takes Over All-Time Association Of Pickleball Players Medal List At Vlasic Classic Cincinnati

May 13, 2025

Report: Hamas Tortured American-Israeli Hostage Edan Alexander; Handcuffed in Cage

May 13, 2025

Subscribe to Updates

Get the latest politics news and updates directly to your inbox.

© 2025 Prices.com LLC. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact

Type above and press Enter to search. Press Esc to cancel.