Steam has been hacked - AVS Forum
Forum Jump: 
 
Thread Tools
post #1 of 10 Old 11-15-2011, 03:31 PM - Thread Starter
AVS Addicted Member
 
joeblow's Avatar
 
Join Date: May 2006
Location: Los Angeles, CA
Posts: 12,051
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 2 Post(s)
Liked: 185
Link:

Quote:


Originally Posted by Gabe Newell

Dear Steam Users and Steam Forum Users:

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don't have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn't be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.


Los Angeles Lakers - 16 NBA Championships!

joeblow is offline  
Sponsored Links
Advertisement
 
post #2 of 10 Old 11-15-2011, 03:37 PM
AVS Special Member
 
krimson's Avatar
 
Join Date: Jan 2006
Location: Winnipeg, MB
Posts: 2,100
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Liked: 17
Bit of a misleading title. It's only the forum that has been hacked. There is no evidence of anyone having their steam account itself taken over.

PSN / Steam - KrimsonStudios
krimson is online now  
post #3 of 10 Old 11-15-2011, 03:37 PM
AVS Special Member
 
LexInVA's Avatar
 
Join Date: Jun 2007
Posts: 1,864
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 3 Post(s)
Liked: 37
We covered it already in the Steam thread.
LexInVA is offline  
post #4 of 10 Old 11-15-2011, 03:44 PM - Thread Starter
AVS Addicted Member
 
joeblow's Avatar
 
Join Date: May 2006
Location: Los Angeles, CA
Posts: 12,051
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 2 Post(s)
Liked: 185
I was out of the country on a family trip all last week. Although I've stopped by AVS, I don't go into every thread so I didn't see this info until now at another site.

Besides, new threads go up for new news. You can't always expect people to find something as important as this buried inside a thread, especially if they come by here infrequently.

Quote:
Originally Posted by krimson View Post

Bit of a misleading title. It's only the forum that has been hacked. There is no evidence of anyone having their steam account itself taken over.

I changed the title to be more generic, but more than the forums have been hit. A quote from the statement:

Quote:


We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked.


Los Angeles Lakers - 16 NBA Championships!

joeblow is offline  
post #5 of 10 Old 11-16-2011, 02:54 PM
Advanced Member
 
tomfoolery_79's Avatar
 
Join Date: Sep 2007
Posts: 701
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Liked: 10
Really really old news.

STEAM: Augcliffe
PSN: Augcliffe
tomfoolery_79 is offline  
post #6 of 10 Old 11-16-2011, 02:59 PM
AVS Special Member
 
Brad Horstkotte's Avatar
 
Join Date: Dec 2005
Location: Torrance, CA
Posts: 5,116
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 8 Post(s)
Liked: 55
It was news to me, so thanks OP for posting. I don't follow the general Steam thread, as I'm not a frequent Steam user, just occasionally (my son much more often).
Brad Horstkotte is offline  
post #7 of 10 Old 02-10-2012, 06:27 PM - Thread Starter
AVS Addicted Member
 
joeblow's Avatar
 
Join Date: May 2006
Location: Los Angeles, CA
Posts: 12,051
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 2 Post(s)
Liked: 185
*** February 2012 Update ***

Quote:
Dear Steam Users and Steam Forum Users:

We continue our investigation of last year's intrusion with the help of outside security experts. In my last note about this, I described how intruders had accessed our Steam database but we found no evidence that the intruders took information from that database. That is still the case.

Recently we learned that it is probable that the intruders obtained a copy of a backup file with information about Steam transactions between 2004 and 2008. This backup file contained user names, email addresses, encrypted billing addresses and encrypted credit card information. It did not include Steam passwords.

We do not have any evidence that the encrypted credit card numbers or billing addresses have been compromised. However as I said in November it's a good idea to watch your credit card activity and statements. And of course keeping Steam Guard on is a good idea as well.

We are still investigating and working with law enforcement authorities. Some state laws require a more formal notice of this incident so some of you will get that notice, but we wanted to update everyone with this new information now.

Gabe


Los Angeles Lakers - 16 NBA Championships!

joeblow is offline  
post #8 of 10 Old 02-10-2012, 06:41 PM
AVS Special Member
 
jhoff80's Avatar
 
Join Date: May 2005
Posts: 3,926
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 10 Post(s)
Liked: 128
Eh, not too concerned. My credit card from 2008 has long since expired.

XBL/Steam: JHoff80
jhoff80 is offline  
post #9 of 10 Old 02-10-2012, 06:48 PM
AVS Special Member
 
pcweber111's Avatar
 
Join Date: Dec 2001
Location: In a van, down by the river.
Posts: 3,553
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 20 Post(s)
Liked: 261
Well it doesn't matter because the card information is encrypted and I highly doubt they'd be able to crack it. Even better is that more than likely quite a few of the cards on file, even if cracked, probably are old and have been replaced. Still makes you wonder just how safe your info is with them.
pcweber111 is offline  
post #10 of 10 Old 02-10-2012, 07:49 PM
AVS Special Member
 
pjb16's Avatar
 
Join Date: Jul 2007
Location: Katy, TX
Posts: 1,331
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Liked: 11
Quote:
Originally Posted by jhoff80 View Post

Eh, not too concerned. My credit card from 2008 has long since expired.

I wasn't even on steam in 2008.

PSN - Mr_Frisch
XBL - Mr Frisch
Steam - Sneaky Pete
pjb16 is offline  
Reply HTPC Gaming

User Tag List

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page


Forum Jump: 

Posting Rules  
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off