The breach has affected user account data stored on Drupal.org and groups.org. The information exposed includes user names, email addresses, and country information. The breach was not the result of a vulnerability within the software provider. The Drupal Association website was shut down “to mitigate any possible ongoing security issues related to the files” The open-source group has strengthened its security to prevent similar attacks, including hardening its Apache web server configurations and adding GRSEC secure kernels to most servers.”]