This weekend the Wikimedia Foundation was notified by an outside security
expert that they had discovered public access to what was intended to be a
private mailing list. External access to the mailing list was immediately
disabled, and our Office IT team began assessing which other private
mailing lists may have been publicly accessible. The two mailing lists we
ultimately found to have been publicly accessible for a period of time had
been and are utilized by Wikimedia Foundation staff as intake email
addresses to facilitate processing of the now-deprecated Project & Event
Grants (PEG) program and the current Project Grants program.

We have no indication that the emails were accessed and misused by third
parties. However, we will shortly be contacting everyone who interacted
with these lists to provide them with more specific information about how
they may have been affected, and recommend precautionary steps they may
wish to take. Multiple departments within the Foundation are also reviewing
potential internal procedural changes to prevent future incidents, and
sharing additional information on secure mailing list management with the
staff.

-- 
Gregory Varnum
Communications Strategist
Wikimedia Foundation <http://www.wikimediafoundation.org>
gvar...@wikimedia.org
Pronouns: He/His/Him
_______________________________________________
Wikimedia-l mailing list, guidelines at: 
https://meta.wikimedia.org/wiki/Mailing_lists/Guidelines and 
https://meta.wikimedia.org/wiki/Wikimedia-l
New messages to: Wikimedia-l@lists.wikimedia.org
Unsubscribe: https://lists.wikimedia.org/mailman/listinfo/wikimedia-l, 
<mailto:wikimedia-l-requ...@lists.wikimedia.org?subject=unsubscribe>

Reply via email to