>>476694
Hey,
I'm sending this to everyone, just in case there are people who weren't in Discord or IRC, haven't been paying attention to the news, and are completely unaware of the events that have transpired, but are still checking their email. On the afternoon of April 14th, one of our servers was breached. The attacker managed to exfiltrate quite a bit of data before going public with a brief shitposting spree, at which point I became aware of what had happened and shut the servers down. Over the next ~24 hours the hacker released some of the data he had taken.
Relevant to you are that he released mod and janitor usernames, password hashes, email addresses, and the IP address last used to log in. With this information made public, people were able to find additional information from public sources, including major data breaches on other websites, to partially or fully dox some 4chan mods and janitors. Even if you have not been doxxed, please check your email address against
https://haveibeenpwned.com/ to see if there may be leaks of data from other websites that may be associated with you.
Unfortunately there's no way for us to take this back and undo the harm that you've suffered due to this hack, but you can take steps to mitigate further harm. I'd recommend that everyone change the password of the email account you used when applying to be a janitor, and any other email accounts you have used thereafter in association with 4chan. You should also add two-factor authentication if at all possible, ideally via an authenticator app, such as Google Authenticator or Authy.
I would also recommend using a password manager of some sort, such that you can use strong passwords easily. Keepass or KeepassXC are good examples, but there are other popular password managers such as Bitwarden, 1Password, or those integrated into popular browsers like Firefox. Generate random passwords of at least 16 characters using upper case, lower case, numbers, and symbols. Do not re-use any passwords. If you had used the password associated with your mod or janitor account elsewhere for some other account(s), you should change that password for those other accounts as soon as you can. We will be doing a forced password reset when the site is back up, and 2FA via an authenticator app will be mandatory for both mods and janitors.
Most IPs are dynamic, but if your IP address is static, you can usually just unplug your modem or router overnight to get a new one. Failing that, you should consider calling your ISP to have it changed. In either case, you should also consider using a VPN such as NordVPN, Surfshark, or Private Internet Access (there are plenty of options here).
A lot of you will want to change your login names, discord names, or email addresses. I will contact each of you individually on Discord to discuss these changes, so please wait until I do so. Much easier keep things organized that way, contacting each person in turn rather than having to get blasted with hundreds of emails or Discord messages of people asking to change info.
As for when the site will be back (and it will be back), "We get there when we get there". Obviously we have a lot of work ahead of us with respect to patching holes and updating software, so please bear with us. Maybe catch up on your backlog, watch some anime, play some vidya, and enjoy this extended break from reports and shitposting.
For those of you who have had personal information exposed, I'm sorry this happened. We had bought new servers a few months ago and were working to transfer 4chan's functionality to them as quickly as we could, but obviously we weren't fast enough, and all of you have suffered due to our failure. I know you've placed your trust in us to keep your personal information safe, and we have let you down. I can't undo what happened, but we're going to do everything we can as fast as we can to secure 4chan's servers and codebase, and get the site back online. All I can do is hope that, despite what you've suffered, that you'll continue to help keep this community alive. There's nothing else quite like it on the internet, and without you, there might never be anything like it ever again.
Regardless of your personal decisions in the coming days and weeks, I want to thank you for all the time and effort you've put in to this website and this community. 4chan's users might not show it openly, but I know they appreciate what you do as well. I think they'll appreciate you even more when 4chan returns, as now they've had time to feel 4chan's absence, and absence makes the heart grow fonder.
Odds are the contents of this email will be posted on Sharty and Kiwifarms shortly after I send it, but I don't much care. If they want to make fun of me for appreciating the 4chan Team, they can go right ahead. I think you are all wonderful and I don't care who knows.
I will be in touch with each of you via Discord in the coming days, but if there's something that can't wait, please reach out.
--GrapeApe