Mumsnet reveals how it fell victim to Heartbleed
The website discovered it was vulnerable when a hacker posted a message on one of its forums, posing as the site's CEO


Mumsnet has released a statement detailing how it discovered it was open to the Heartbleed OpenSSL vulnerability.
On 8 April, when the first sites were affected by the Heartbleed OpenSSL vulnerability, the company ran some tests to see if it was open to an attack and patched the holes it believed hackers would use to access systems on April 9.
However, on 11 April, a message was posted on one of the website's forums, purportedly from the site's CEO, Justine Roberts.
Despite the patch being successfully applied, the hackers used data scraped before its application to make the fraudulent post.
Passwords are like underwear; change them often
It made some odd statements about the site's users, claiming they were "unreasonable and petty."
The post went on to claim Roberts would be closing the site down or selling it, finishing with: "I'm putting this grothole up for sale and spending the money on dogecoin. Probably a more sensible thing to do than run this place any longer."
Mumsnet was very quick to announce this wasn't the company's CEO and hackers had taken advantage of the Heartbleed vulnerability, bypassing the patches the company had put in place.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Shortly after, other Mumsnet accounts were used to post messages writing out the string: "All your base are belong to us."
The Heartbleed vulnerability had allowed hackers to steal usernames, passwords and post messages on user accounts. Thirty usernames and passwords were then posted to the text sharing site Pastebin, prompting Mumsnet to change user passwords to prevent any more damage occurring.
The blog post on Mumsnet said, although nothing malicious happened, it seems the vulnerability was used to highlight the security risk with Heartbleed.
It advised its users: "The internet is brilliant, but nobody can guarantee it's 100 [per cent] safe and secure - EVER. Whenever you share anything on the web, either publicly (such as on a Mumsnet thread) or privately (such as the data you give to a website when signing up), have a think about how happy you would be for that information to get into the hands of a hacker.
"Make your passwords as secure as possible and change them every few months ('passwords are like underwear; change them often'). Use different passwords for different accounts. Close redundant accounts that you no longer use."
Yesterday, security experts warned the volume of companies trying to patch holes exposed by the vulnerability could severely slow down the internet.

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Hackers are targeting Ivanti VPN users again – here’s what you need to know
News Ivanti has re-patched a security flaw in its Connect Secure VPN appliances that's been exploited by a China-linked espionage group since at least the middle of March.
By Emma Woollacott Published
-
Broadcom issues urgent alert over three VMware zero-days
News The firm says it has information to suggest all three are being exploited in the wild
By Solomon Klappholz Published
-
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claim
News Over 200 vulnerable Nakivo backup instances have been identified months after the firm silently patched a security flaw.
By Solomon Klappholz Published
-
Everything you need to know about the Microsoft Power Pages vulnerability
News A severe Microsoft Power Pages vulnerability has been fixed after cyber criminals were found to have been exploiting unpatched systems in the wild.
By Solomon Klappholz Published
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
By Emma Woollacott Published
-
A critical Ivanti flaw is being exploited in the wild – here’s what you need to know
News Cyber criminals are actively exploiting a critical RCE flaw affecting Ivanti Connect Secure appliances
By Solomon Klappholz Published
-
Researchers claim an AMD security flaw could let hackers access encrypted data
News Using only a $10 test rig, researchers were able to pull off the badRAM attack
By Solomon Klappholz Published
-
A journey to cyber resilience
whitepaper DORA: Ushering in a new era of cyber security
By ITPro Published