An administrator account on the OpenWrt forum (https://forum.openwrt.org) was breached. It is not known how the account was accessed: the account had a good password, but did not have two-factor authentication enabled. The intruder was able to download a copy of the user list that contains email addresses, handles, and other statistical information about the users of the forum. We are following the advice of the Discourse community and have reset all passwords on the Forum, and flushed any API keys.”]
Source: https://lists.openwrt.org/pipermail/openwrt-announce/2021-January/000008.html

