Search Type
Leaked credentials - The Kodi Foundation Archived

Why did I get an email about Leaked Credentials?
The Queen’s IT Services Security team recently became aware that in February 2023, The Kodi Foundation suffered a data breach that exposed more than 400k user records. This posting included the credentials online that included email addresses of account holders who belong to Queen's University. As a precaution, Queen’s IT Services will expire the passwords of any Queen’s account found to be listed on the breached accounts list to ensure that the password posted will no longer be valid.


What should I do to protect myself?
If you received an email message from IT Services concerning the posting of your credentials, you will be sent additional emails requesting you to change your password, prior to your password expiring. NetID passwords are changed at https://netid.queensu.ca/selfservice/login/auth


We also encourage you to take the following actions to better protect yourself and your information:


Do not reuse passwords across your accounts.


If you have used your Queen’s password on multiple sites, we strongly encourage you to change that password on every other site where it has been used.


Be extra diligent of scams that may reference your Queen's account.


What data was compromised?
According to reports, email addresses and passwords were posted online.


Why is Queen’s expiring passwords for potentially breached accounts?
Queen’s account holders who fail to follow safe password practices are at risk when breaches like this occur. To protect your Queen’s account IT Services are taking this action to prevent account compromises by ensuring all accounts associated with the posting of credentials have refreshed passwords.


What caused the data breach?
Attributed to an account belonging to "a trusted but currently inactive member of the forum admin team", the breach involved the administrator account creating a database backup that was subsequently downloaded before being sold on a hacking forum. The breach exposed email and IP addresses, usernames, genders and passwords stored as MyBB salted hashes. The Kodi Foundation elected to self-submit impacted email addresses to HIBP. IT Services obtain breach information like this from the service called “Have I Been Pwned?” . Visiting the website https://haveibeenpwned.com/ will allow you to enter and check your Queen’s University email address against all publicized breaches that reference your Queen’s email address. The site also provides details about the data breach, including links to additional information.


  • Publish Date: April 25, 2023 15:32
  • Channels:
  • IT Support Centre