Data breach leaves Bitly accounts compromised
URL reducer comes up short after malicious attack

Bitly has confirmed its account holders' credentials may have been compromised by a malicious attack.
The website is used by millions of people to shorten links for posting on social media. Account holders link it to their Facebook and Twitter profiles, meaning their social media accounts might now also be at risk.
In a blog post, chief executive Mark Josephson assured readers "the team has been working hard to ensure all accounts are secure."
Bitly said the company has no reason to believe any accounts have been accessed without permission. As a security precaution, however, it has shut down all Facebook and Twitter-connected accounts.
"We have already taken proactive measures to secure all paths that led to the compromise and ensure the security of all account credentials going forward," added Josephson.
A step-by-step guide has been posted on the blog, directing users to reset their API keys and security settings. Bitly also advises users to disconnect and reconnect from any applications that use the service and reset their passwords.
The URL service launched its website in 2008 and gained popularity the following year as the default shortening service used on Twitter. The company also offers a paid enterprise solution used by firms The New York Times and Pepsi for their social campaigns.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The company has yet to respond to a request for comment.
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly
-
Gumtree site code made personal data of users and sellers publicly accessible
News Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website
By Connor Jones
-
Pizza chain exposed 100,000 employees' Social Security numbers
News Former and current staff at California Pizza Kitchen potentially burned by hackers
By Danny Bradbury
-
83% of critical infrastructure companies have experienced breaches in the last three years
News Survey finds security practices are weak if not non-existent in critical firms
By Rene Millman
-
Identity Automation launches credential breach monitoring service
News New monitoring solution adds to the firm’s flagship RapidIdentity platform
By Praharsha Anand
-
Neiman Marcus data breach hits 4.6 million customers
News The breach took place last year, but details have only now come to light
By Rene Millman
-
Indiana notifies 750,000 after COVID-19 tracing data accessed
News The state is following up to ensure no information was transferred to bad actors
By Rene Millman
-
Pearson fined $1 million for downplaying severity of 2018 breach
News The SEC found the London-based firm made “misleading statements and omissions” about the intrusion
By Rene Millman