Spoof email?

  • Unknown's avatar

    Hi,
    I just received the following email, wondering if it’s legit, thank you for your time and help. Brian

    Your WordPress.com password has been reset

    Howdy,

    Your login credentials were recently discovered in a list of compromised accounts published by security researchers. This list was not generated as a result of any security issue on WordPress.com, but rather an external site or service that you also use being hacked and their user data leaked by the attackers.

    For your security, we have temporarily locked your WordPress.com account (badgerbrian).

    Until your password has been reset you will not be able to access your sites:
    – badgerbrian.wordpress.com
    To request a new password and regain access to your account, please click the ‘Lost your password?’ link on the WordPress.com login page and follow the instructions.

    It is very important that your new password be unique. Using the same password on different web sites increases the risk of your account being compromised. Now would be a good time to go through all of your online services and set distinct, strong passwords for each.

    Once your password has been changed, we strongly recommend making your account even more secure by enabling Two Step Authentication under the Security section of your Profile menu.

    – The WordPress.com Team

  • Hi Brian,

    That email is from us, yes. Please log out of this account, and then follow the instructions in that email to set a new password for your other WordPress.com account that email is referring to.

  • The topic ‘Spoof email?’ is closed to new replies.