You’ve probably heard the news that Bitly, the popular link shortening service, is facing security issues.
We have reason to believe that Bitly account credentials have been compromised; specifically, users’ email addresses, encrypted passwords, API keys and OAuth tokens. We have no indication at this time that any accounts have been accessed without permission. We have taken steps to ensure the security of all accounts, including disconnecting all users’ Facebook and Twitter accounts. All users can safely reconnect these accounts at their next login.
What Do You Need to Do?
Bitly is recommending that all users make the following changes to secure their accounts.
- Change your API key and OAuth token
- Reset your password
- Reconnect any accounts you have provided Bitly API access — Facebook, Twitter, Buffer (we’ll touch on this in a moment), etc.