BOOSTARE PLEASE!!!
SECURITY INCIDENT ON MASTODON.BIDA.IM — ONGOING CREDENTIAL STUFFING CAMPAIGN ACROSS THE FEDIVERSE
An ongoing credential stuffing campaign is targeting Mastodon instances across the fediverse: compromised accounts are being used to post telegram spam links. You've probably seen the spam in your timeline, coming from various instances.
Our instance was hit too: starting around Aug 24, 2026, a bot logged into ~68 accounts on bida and later used some of them to spam. We've contained it locally, but the campaign is still active elsewhere — so this post is both an incident report for our users and a heads-up for other admins, with the commands we used.