I just got another one 0 minutes ago
This attack was different than yesterdayâs attack. We have shut down this endpoint for now.
Hopefully you guys will find out who is behind this and take appropriate action.
Could be a delayed email or an unrelated attempt by someone.
I got hit with like 10 of these earlier.
I wonder whose behind this.
The attack method was different? So someone is actively looking for ways to spam emails to us? Nice.
Just received these emails, 5+ emails since last hour ago, hopefully this is fixed soon.
I got 5 emails, hopefully this is finally resolved
Iâm still getting emails, theyâre gradually decreasing the interval at which theyâre sent.
Is this an after effect, or is there a different endpoint being abused now?
(referring to second bout of username based emails)
Iâm pretty sure the person was using a legacy password reset endpoint under api.roblox.com, which accepted a username. It was actually listed under the /docs page until a few months ago.
I previously made someone aware of the legacy endpoint, however it was never removed. Thereâs no impact besides a slight annoyance, the endpoint was rate limited as far as I had tested it.
The first attack also had a relatively low impact on end users besides the sheer amount of spam, however could have been used to smuggle phishing emails in between the legitimate reset emails since the user had the targets email address. This isnât possible in the method I mentioned in this reply, because the user does not have access to the targets email.
I am still receiving these but at the moment itâs at 4 and the latest was about 2 hours ago.
Just received another a second after this post.
Iâve received six of these over the past three hours. I received the last one 55 minutes ago.
Received 4 emails between 05:30 and 07:45, and received my fifth a few minutes ago at 09:26. Whoeverâs doing it, theyâre an equal opportunist.
Just pointing out that these emails are most likely from a backlog and are only coming through now. If you visit the link, youâll see theyâve already expired.
Just changed my email⌠not sure if that was necessary.
It wasnât. Someone was abusing the old API that required oneâs username to prompt the password reset process. Nothing was leaked with it so rest assured.
Is there going to be an official statement on this? Seen quite a lot of people spreading misinformation on this (like this post for example). Donât think that people who donât have access to this category should be kept in the dark.
I didnât get anywhere near that amount (as of the time of this post) but I still was bombarded at about 6 a.m. CEST.
Not sure why itâs being done, or how, but itâs definitely worrying.
Still very actively receiving them.
It might be worth investigating a potential security breach.