The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →In July 2014, CNET acknowledged that hackers had accessed some of its web servers. A group calling itself W0rm claimed it had taken a database containing more than one million registered users’ usernames, email addresses and encrypted passwords. That figure and the data claim were reported at the time, but the available accounts do not establish an independently verified final count.
What happened to CNET?
Contemporaneous reports said W0rm claimed responsibility for taking a CNET user database. CNET spokeswoman Jen Boscacci acknowledged unauthorized access, saying that “a few servers were accessed” and that the company had “identified the issue and resolved it a few days ago.” Her statement, as reported by Bitdefender on July 15, 2014, confirms CNET’s acknowledgment and remediation claim; it is not a full incident report.
At the time, reporting attributed the access to a security hole in CNET’s Symfony installation, but that explanation was presented as the group’s account. The available coverage does not include a primary technical analysis confirming the vulnerability.
What information was reportedly taken?
W0rm’s claim, described in the contemporaneous reports, concerned usernames, email addresses and encrypted passwords. SC Media’s July 15, 2014 report listing also described more than one million usernames, emails and encrypted passwords as compromised.
#1 Best Overall
“More than one million” should be treated as the group’s reported claim, not an audited CNET count. The accounts available do not independently confirm how many users were affected.
Were the passwords exposed or recoverable?
The reports describe the passwords as encrypted, but do not identify the storage algorithm, say whether passwords were salted, or establish whether an attacker could recover them. The word “encrypted” alone is not enough to determine how resistant the stored passwords were to cracking.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What did CNET do, and were users notified?
CNET said it had identified and resolved the issue a few days after access was detected. The contemporaneous statement does not establish whether every affected user was individually notified, and the available accounts do not answer that question.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

