Hackers had access to Drupal server infrastructure
Hackers managed to break into the Drupal Association’s servers, gaining access to Drupal.org and groups.drupal.org users’ usernames and encrypted passwords. The hack does not affect sites running Drupal.
The Drupal Association reports the hack to its users via email. “The Drupal.org Security and Infrastructure Teams have discovered unauthorized access to account information on Drupal.org and groups.drupal.org,” the organization warns, “The information includes usernames, email addresses, country of origin information, and hashed passwords. ” Research may reveal that even more data was accessed by the hackers, thus Drupal.
All passwords except groups.drupal.org were both hashed and salted. As a precaution, however, they have been reset, so that users must create a new password on their next visit. The organization also advises users to change passwords for other services if they were similar or identical to the Drupal password. It is unclear how many users are involved.
Access to the servers would have been obtained via third-party software on the Drupal.org infrastructure and not via a vulnerability in Drupal itself. The hack therefore does not affect sites that run Drupal or their administrators.