Patreon suffers data breach – customer data exposed – Crowdfunding platform hacked, but no credit card data stolen
Patreon, the crowdfunding site that helps artists find backers for their projects, has confirmed a data breach in which important information . The news first surfaced on Twitter as a rumor, but was later confirmed by Patreon CEO and co-founder Jack Conte.
In a technical report posted on the company's blog by Mr. Conte, he admits to the incident, saying that hackers managed to gain access to registered names, email addresses, messages, and some shipping addresses. Some information for billing addresses added before 2014 was also accessed during the incident.
The good news is that Patreon doesn't store credit card information, so hackers weren't able to get their hands on that data. Additionally, Patreon's CEO also claims that the company uses 2048-bit RSA keys to encrypt information related to users' social security numbers, tax forms, and passwords
As a precautionary measure, the company sent email notifications to all users, asking them to change their passwords just in case. The cause of the incident appears to be a debug version of the Patreon website that was left accessible via the Internet.
Mr. Conte claims that no unauthorized access to any of his production servers has ever been recorded, and that no private keys have been lost to any other server. However, private keys and API keys have been changed as a precaution.
UPDATE: There are several reports that the database of Patreon users' details is available on Mega, the Kim Dotcom Megaupload clone.

