TaskRabbit has reset its customers' passwords after detecting "suspicious activity" on network .

The online marketplace owned by IKEAtook this action, as it says it "took steps to prevent access to user accounts," a TaskRabbit spokesperson said.
The company later confirmed that it was a credential stuffing attack , where existing sets of exposed or compromised usernames and passwords are matched against different websites to access accounts.
“We acted with great caution and reset passwords for multiple TaskRabbit accounts, including all users who had not logged in since May 1, 2020, as well as all users who were logged in during the time period of the attack, even though the activity was due to users,” the spokesperson said.
"As always, the safety of the TaskRabbit community is our priority, and we will continue to be vigilant about protecting our users' personal information."
TaskRabbit customers were notified of the incident with a vague email that noted that their password had recently been changed “as a security measure,” but did not explain what led to this action.
It's not uncommon for companies to reset passwords after a security incident where customers or account information has been compromised or stolen.

TaskRabbit was founded in 2008 and has grown over time from an platform for trading tasks and tasks to a more mature and customized marketplace for matching customers with contractors. This eventually caught the attention of furniture retailer IKEA, which bought the company in September 2017.
A year after its acquisition, however, TaskRabbit had to take down its website and app due to a “cybersecurity incident .” The company later revealed that an attacker had gained unauthorized access to its systems.
Following the attack, the company said it was implementing several new security measures and would work to make the login process more secure. It also said it would reduce the amount of data it holds on its employees and customers, as well as “improve its overall cyber threat detection technology.”.
