News

Steam user database cracked, credit card encrypted info not stolen
Posted: 11.11.2011 05:30 by Comments: 7
Gabe Newell has issued a frightening email that not only was the Steam forum vandalized, but hackers managed to get into Steam accounts. The hacked database included usernames, "hashed and salted" passwords, transcripts of game purchases, email and billing addresses, and encrypted credit card info. However, the encryption was not apparently cracked.

Part of the email from Newell states, "We don't have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn't be a bad idea to change that as well, especially if it is the same as your Steam forum account password."


Let us know if you received Newell's email.
Source: Joystiq
Game advertisements by <a href="http://www.game-advertising-online.com" target="_blank">Game Advertising Online</a> require iframes.

Comments

By SiyaenSokol (SI Elite) on Nov 11, 2011
SiyaenSokol
I am glad that I am reading this, so that I can change my password. Damn hackers!

Sometimes I wonder why in the world do they want to do others harm like this.
By herodotus (SI Herodotus) on Nov 11, 2011
herodotus
Changed password as soon as this came out. Make sure that if you have used this password elsewhere to change those as well.
As Mayor Vaughn said to Chief Brody in "Jaws":
"I want you to catch these paint-happy (*hack-happy*) basterds and hang them up by their busker browns!".
By nocutius (SI Elite) on Nov 11, 2011
nocutius
No email for me yet.
Changed the password as well, i'd really hate to loose my account. I have no credit cards associated with the account or any steam funds so that is not a problem.

Will be interesting to see what kind of press Steam will get over this considering the one Sony got. The site was hacked quite a few days before they told us it went beyond just the forums.
By herodotus (SI Herodotus) on Nov 11, 2011
herodotus
I'm surprised the Steam Store hasn't been taken offline.
By stuntkid (SI Elite) on Nov 13, 2011
stuntkid
i've not had email about it. though word spreads quickly in the digital age.
By SiyaenSokol (SI Elite) on Nov 14, 2011
SiyaenSokol
Things seem to be normal on my account, so I am one of the lucky ones that did not get invaded... then again, none of my banking details are on the system, and I haven't bought a game through Steam, so it is actually pointless to invade my account, unless you want to change things to spite me.
By FoolWolf (SI Elite) on Nov 15, 2011
FoolWolf
I removed my credit card info from all places after teh SONY incident - takes a few more seconds every time I buy - but now I can chose and nothing is saved except the receipt...