Steam database hacked. Encrypted credit card information/passwords compromised

Started by .Griff., Nov 10, 2011, 23:55:15

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

.Griff.

http://www.pcgamer.com/2011/11/10/steam-database-hacked-encrypted-credit-card-information-and-passwords-compromised/

Valve have just informed us that Steam's database has been compromised.

An IM is being sent out to all Steam users. Here are the details straight from Gabe:

"Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked."

Valve are "still investigating" the situation. They mention that there's been no evidence of illegal credit card activity as yet, and that it's probably a good idea to change both your Steam passwords. To do that, access Settings from the Steam menu within the client.

Newell signs off his IM with sincerity: "I am truly sorry this happened, and I apologize for the inconvenience."

Steam joins a long list of high profile targets who have recently been targeted by Hackers. Sony, Codemasters and Bioware have all taken the hit. Valve recently announced Steam Guard, designed to increase account security; Gabe even gave out his password to show off its true power. That makes us extra sad.

zappaDPJ

An hour ago I Googled 'Steam hacked' and had to go way down the list of search results before I could get a site that would resolve. Seems the net momentarily buckled under the strain.
zap
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Technical Ben

Nope. I think there are some ongoing routing problems. I just had a net session die (had sync, but nothing responding).

I'm glad Steam is acting both professional and sincere. I hope it gets sorted out. They have taken extra precautions over that of Sony though to protect their customers. One is IP logging and protection for Steam accounts. You can set the account to only respond to your IP/PC. So hopefully those who use this part of the service are protected, as any hacker will resolve to the wrong IP and get blocked. Still means a new set of passwords/CC details needed to be safe though.
I use to have a signature, then it all changed to chip and pin.

Niall

Oddly I only just got this information through the steam announcement. No idea why it took 2 days to tell me :shrug:
Flickr Deviant art
Art is not a handicraft, it is the transmission of feeling the artist has experienced.
Leo Tolstoy

Glenn

Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.