Reddit announced today that some of its internal systems were breached in June, and some data was leaked, although not as sensitive. The breach was done by exploiting the SMS authentication feature that users were using.

Reddit's Chief Technology Officer explained that the breach was discovered on June 19, and is estimated to have taken place between June 14 and June 18. "Some of our employee accounts were compromised by the hacker, who gained read-only access to old backups and logs."
It is important to mention that Reddit itself uses 2 factor authentication only via token. But it seems that at least one of its partners did not have it enabled, and the Hacker took advantage of it. It is important to mention that 2 factor verifications via SMS have been considered inappropriate since 2016 according to NIST.
While we are not sure what information the hacker extracted, we are certain of 2 specific areas. First, he extracted a complete backup of the site from 2005 to 2007, which contained usernames, encrypted passwords, emails, posts, and private messages. The second item we know he extracted is the username-to-email correspondences of the new accounts created in June.
If your account was affected by this data breach, you will receive an email from the company shortly. Also, if you have an account since 2007 and have not changed your password since the day it was created, we recommend that you change it immediately.
Finally, the company has notified the authorities, launched an investigation into the origin of the attack, and improved the platform's protection.
