3 ms·
So hackers breached the network and still might have been present. Having everyone reset their passwords at that time is the LAST thing you want to do, as the
by fuzzylightbulb 6y ago
So hackers breached the network and still might have been present. Having everyone reset their passwords at that time is the LAST thing you want to do, as the hackers could have just collected all the fresh credentials, a significant percentage of which are also used for other services because users are users.
Legal made the right decision. You clean up the internals, close the backdoors, and then you notify/refresh user credentials.