| Hi everyone, A large pet-site has been reaching out to us over the last week or so to let us know that their users’ accounts have been under attack, and to give us some details and a heads up that they may try to target Mycena Cave accounts in the future. With that in mind, please take a few moments to help keep your Mycena Cave account and its contents safe from those who would like to steal it. The single most important thing you can do is to use a password that you have not used anywhere else, ever. 
 This kind of attack is called credential stuffing, and is the most common source of account compromises on the internet today. People love using the same password on multiple services. Don’t let it happen to your Mycena Cave account: use a unique password that you have never used anywhere else (and make no mistake, if you use the same password here as you use(d) on Neopets, it’s not about if your account will be stolen but when). How can I tell if my password is on a list? We’ve built a tool which can tell you if your password is known to be compromised. That being said, the easy answer is that if you’ve used it in more than one place, you should assume that it is not secure. 
 The second most important thing you can do is to use a long password 
 
 Where can I get more information? 
 
                Posted 11/29/19, edited 11/29/19               | |
| My password was found 19 times p.q I guess I’m extra at risk lol Changing now <3 Hah my new password is hilarious, if anyone needs it I used 4 words from this random word generator :) So I got something along the lines of Correct Horse Battery Staple lol 
                Posted 11/29/19, edited 11/29/19               | |
| ahh the neopets breach of 2013, we luv to see it!! this is a great heads up tho, thank you!! i know for certain i was on that neo breach because one of my sides was hacked in a way that could only have been explained as part of that breach. i’ve cleaned up neo since then but never thought to look into other petsites! are u able to say which one is facing this issue? the majority of people who hack into neo accounts do so to sell the contents of old, abandoned accounts off site (particularly retired artwork pets) so if it’s a petsite that’s got a similar sort of issue (i think fr has had a similar black market form?) then that may be helpful to at least know what kinds of activity to look out for that would indicate mycena’s being targetted? (basically, if custom pets are being moved off inactive accounts; luckily we’re a tight enough community here that would be recognized IMMEDIATELY haha) (I dunno if that’s anything to think about/is helpful, just spitballing based on my knowledge of the neo breach!) 
                Posted 11/29/19               | |
| Coming back to say that instead of spreading out the task over the next day or so, I decided to do all of this in one night (like a LOON), and I’m happy to say my new password yields a much more comforting message: “This password was not found in any common data dumps.” :‘D I’m very tired lol. Thank you for the well-wishes! XD They helped me power through! 
                Posted 11/29/19, edited 11/29/19               | |
| I’d love to change my password, but I don’t remember my current one :‘D I’ll have to do an incognito mode reset. 
                Posted 11/30/19               | |
| Just for fun I checked all my passwords. Everything but one was free and clear. That’s a nifty checker there glitch Thanks! 
                Posted 11/30/19               | |
| Ah, yes…the exact sort of thing that led to me losing my Gaia Online account back in the day (filled with lots of rare-ish items…and then I couldn’t even get back on the account at all) because it had the same password/username/e-mail as my account on another site that had a data base breach.  Whoops.  Haha.  I’ll….check my passwords… 
                Posted 11/30/19               | |
| I’ve changed to a longer password because of this thread! It has 14 characters, and it was much better than my original password, which has eight only and was used for :-a hundred times in elsewhere! 
And I typed  This password was not found in any common data dumps. 
                Posted 07/14/20, edited 07/14/20               |