- all our passwords are hashed and salted, using modern methods, so they can't be reversed, even if we have a data leak
- i looked in the logs, and it simply looks like they knew the correct password
- brute force isn't feasible, because XF blocks brute force on both a username and IP level
- my current theory is that they used the same password on multiple sites, and the attacker simply collected multiple working logins, before making a targeted attack to create FSFT threads for graphics cards
- so far zero hacks today