Hackers broke into Automattic’s servers today and allegedly copied the source code of WordPress.com. Automattic is the company behind WordPress. Without mincing words, the company’s founder, Matt Mullenweg, noted in a blog post that they are still examining the matter and have taken necessary steps to prevent an incident like this from happening again.
Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.
We have been diligently reviewing logs and records about the break-in to determine the extent of the information exposed, and re-securing avenues used to gain access. We presume our source code was exposed and copied. While much of our code is Open Source, there are sensitive bits of our and our partners’ code. Beyond that, however, it appears information disclosed was limited.
The extent of damage is currently unknown and it is recommended for WordPress.com users to change their passwords.