Kickstarter Hacked

Kickstarter was infiltrated by hackers on February 12, 2014.  Reportedly hackers gained unauthorized access to customer’s data, such as email addresses, usernames, mailing addresses, phone numbers, and encrypted passwords.  They revealed this information in a blog post, stating that they were contacted by law enforcement officials, who informed them of the breech.
Kickstarter has stated that no credit card information or passwords were revealed, however they strongly urged their users to change their passwords.

Kickstarter released an FAQ:

[container]

How were passwords encrypted?

Older passwords were uniquely salted and digested with SHA-1 multiple times. More recent passwords are hashed with bcrypt.

Does Kickstarter store credit card data?

Kickstarter does not store full credit card numbers. For pledges to projects outside of the US, we store the last four digits and expiration dates for credit cards. None of this data was in any way accessed.

If Kickstarter was notified Wednesday night, why were people notified on Saturday?

We immediately closed the breach and notified everyone as soon we had thoroughly investigated the situation.

Will Kickstarter work with the two people whose accounts were compromised?

Yes. We have reached out to them and have secured their accounts.

I use Facebook to log in to Kickstarter. Is my login compromised?

No. As a precaution we reset all Facebook login credentials. Facebook users can simply reconnect when they come to Kickstarter.

[/container]