    Why has Curse not let Bukkit users know that the forums were compromised for a few months and that everyone who logged in during that time had their actual password stolen?


    This has been verified to be true:

    Search "authXen". This is same attack that hit Hypixel and

    Users of these forums have the right to know that many passwords were stolen in clear text - not just a hash.

    So Bukkit Users, if you logged in from August 15th~ to Nov 15th~, consider your password stolen and change it and any other website you used it on.

    and stop using the same password in multiple places.
    timtower Administrator Administrator Moderator

    Thread is locked to avoid attacks.
    Update and announcement are on their way.
