I love that Reddit is doing a Ask Me Anything on their just-announced breach involving the phishing of employee credentials.

https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/

We had a security incident. Here’s what we know.

**TL:DR** Based on our investigation so far, Reddit user passwords and accounts are safe, but on Sunday night (pacific time), Reddit systems were...

reddit
@briankrebs "Hey, Reddit, what's your mother's maiden name, the first street you lived on, and your favorite pet's name?"
@briankrebs: "I am a credential-haver! Wanna ask questions about people who work hard to illegitimately have credentials?"
@briankrebs I'm sure their legal team doesn't
@briankrebs agreed, it is a really great example of what to do. No one is immune to a good phish and I think it speaks well of reddit that the employee self reported.
@briankrebs definitely handling it better than TMH in Tallahassee is
@briankrebs it’s terrible that they were breached but simultaneously I absolutely love how they are handling it. It feels so in,one with their own community and culture, and it’s also incredibly transparent and informative too.