Was https://bugzilla.mozilla.org/ hacked?

Hello, I use a unique mail address for each site, forum … etc … exactly for the purpose of identifying when I receive SPAM where it comes from, or more exactly who was possibly hacked, and so leaked my mail address.

Well, I am sorry to report that this morning, I received the following mail on my Mozilla bugzilla address, which is only known by it, and which to my knowledge is hidden from non members. Although, as I can observe, members can see the email of other members, and this is probably a security / confidentiality problem that should be addressed at some moment.

Can you have somebody from bugzilla.mozilla.org check whether all is safe, and whether this is primarily an ill-intentioned member who scanned addresses he/she could gather and who is misusing the system, or if there is a more severe leakage ? (note: my account was created in 2018, so well after the hacking problem recognized by Mozilla on bugzilla in 2015, cf. https://www.eweek.com/security/mozilla-s-bugzilla-hacked-exposing-firefox-zero-days/#:~:text=Mozilla%20admitted%20today%20that%20its%20Bugzilla%20bug%20tracking,have%20happened%20as%20far%20back%20as%20September%202013.)

Here is the received SPAM:

Same here. I used a special email just for this website and for my firefox sync account and as of today receive SPAM on exactly this email address.

So that would confirm, thank you … and of course nobody would really say it on public I guess :slight_smile:

That reminds me of my Adobe account some years ago, where I got the same symptom 1 year before Adobe eventually confessed they were hacked, under image pressure … Since then, I would have thought that organizations have learnt that it’s better to say it quickly to the public than to try to keep it hidden. It always surfaces later, and hits harder then !

Email addresses on bugzilla are accessible to any registered member, there is no need to hack anything.

Correct, this is what I observed and said in the first post.

This is still a security / confidentiality problem that should be addressed at some moment, all the more if there are ways for a member to gather them in an automated way to build lists …

I just realized that the email I’ve used for https://bugzilla.mozilla.org/ is different than the one I now receive SPAM on. The one I receive SPAM on was only used for mozilla-sync