Australian software maker Atlassian announced that suspicious activity was detected on computers using its HipChat messaging service and that attackers could gain unauthorized access to customer information.
HipChat is an instant messaging (IM) platform compatible with Android and iOS operating systems, as well as Windows and OS X. A monthly subscription ($2 / €1.77 per user) is available, offering an extensive list of features that includes 1-to-1 chat and video calling, screen sharing, and unlimited file storage.
Atlassian's chief security officer, Craig Davies, alerted the problem last Saturday, saying that the exposed information belonged to less than 2% of customers and included names, email addresses, usernames and passwords.
The method used by the attackers to gain access to the system has not been disclosed, but the security team has been able to prevent the intrusion since it was discovered. Davies says the service protects customer passwords and stores them in encrypted form. Therefore, the risk from an attacker is relatively small.
However, out of prudence, a password reset was recommended for all HipChat users, as well as all Atlassian services, associated with the same email address.
The investigation into the incident has not yet produced any evidence that the attackers also had access to payment information, putting credit cards , as Davies stated in the official statement from the service, which was released this week.

