I received a message from Atlassian about my account being compromised:
On 12 February 2017 we detected a suspicious login to your Bitbucket Cloud account. We believe that a malicious actor used a large database of usernames and passwords stolen from third party services to access Bitbucket Cloud accounts. We can't know exactly how your password was first compromised, however it was not caused by Atlassian.
Atlassian is confident it wasn't their fault and speculates it is because I use the same login details elsewhere. However I use a unique password here, which couldn't have been stolen from a third party service. Is Atlassian leaking passwords?
speculates it is because I use the same login details elsewhere
I'm not sure what gave you that impression, but that is not what the message says.
Please simply take this a strong suggestion that you should change your password if you have not already done so and consider enabling 2FA for additional protection.
Nobody at Atlassian is going to be able to give a direct answer about the specific security event that is suspected, as the fact that it involves a third party necessarily means that doing so could have legal consequences.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.