Account Security Warning: Steam Compromise

Account Security Warning: Steam Compromise

As some of you may know, Valve Software recently announced that certain Steam user account information was compromised by an illegal and unauthorized intrusion into their network. The statement from Valve on these events can be found here:

http://forums.steampowered.com/forums/announcement.php?f=14


If you’re a registered account holder with Steam, we encourage you to review the information provided by Valve as soon as possible. We also recommend that you update your Battle.net password via Account Management (https://us.battle.net/account/management) should it be the same as or similar to the one you used for Steam or for the Steam forums. You may also wish to change your registered email address as a further security measure, or to change the password to your email account and other online accounts that might be at risk of compromise. If you are unable to update your Battle.net email address and/or password on your own, please contact our customer support staff for assistance: http://us.blizzard.com/support/webform.xml

For additional tips and suggestions for how to improve your Battle.net account security, such as by adding a Battle.net Authenticator to your account, check out our Account Security Awareness guide (http://us.battle.net/en/security/) and blog post (http://us.battle.net/wow/en/blog/2299938).

Report Post # written by
Reason
Explain (256 characters max)

Reported!

[Close]

Comments (173)

Login to rate
Healingnut
The Forgotten Coast
Healingnut
5/12/2012
my account immune to hacks :) Authenticator ftw xD
Login to rate
Ishko
Sentinels
Ishko
5/10/2012
Can't help to think they're gloating. "We're better than Valve." Still thanks for the heads up, nice to know about of time my email was compromised :(
Login to rate
Bigdaddy
Nordrassil
Bigdaddy
5/9/2012
Steam is a garbage company, if you need support for any of thier games you can forget about it they only answer an the 6th Tuesday of Neveruary.
Login to rate
Thanks for letting us know about this Blizzard, I was actually a little surprised that you took this much of an initiative... I approve good sir.

Also, I REALLY like the picture you used of Jaina, makes it look like she is an admin for World of Warcraft... that and I like her as a story character, thus it makes her look even more like a good person.
Login to rate
Bluurains
Winterhoof
Bluurains
5/9/2012
Six Bucks or free phone authenticator to protect ur account from those probs, yeah id say its worth it. Just sayin. :)
Login to rate
Remethos
Moon Guard
Remethos
12/16/2011
Funny how I was this close to getting a forums account, then this happened. PHEW!!!
Login to rate
Abacritdabra
Kel'Thuzad
Abacritdabra
11/20/2011
Streaming is believing
Login to rate
Gralan
Bloodscalp
Gralan
11/19/2011
Wait but isn't that why we were forced ... err I mean 'enticed' to buy authenticators?
Login to rate
Drahliana
Earthen Ring
Drahliana
5/9/2012
@Gralan: Not everyone bought authenticators despite enticement.
Login to rate
I want that picture as a full-size wallpaper. It looks awesome.
Login to rate
Wrasam
Frostmourne
Wrasam
11/19/2011
@Moggy: http://goo.gl/9Ce53 there you go. :)
Login to rate
Flamboozle
Moonrunner
Flamboozle
11/18/2011
Good thing all I play on Steam is TF2, and a gifted copy of that one dirtbike ragdoll game.
And I don't use the forums. Heheh.
Login to rate
Kayzarv
Spirestone
Kayzarv
11/17/2011
lets all just post are passwords on facebook lol
Login to rate
Aww, isn't that sweet. They're not even directly affiliated and they're all concerned about us. I feel so loved. Not even joking.

Still, it's a good thing I don't even use Steam.
Login to rate
Dreamdweller
Kael'thas
Dreamdweller
11/17/2011
I just give people my password from now on
Login to rate
Fixup
Terokkar
Fixup
11/17/2011
D'0h! Now I gotta go change the password on my luggage? (Ref: Space Balls)
Login to rate
Averen
Moon Guard
Averen
11/16/2011
Authenticator FTW. Still passwords for Steam is changed almost quarterly a year.
Login to rate
Matban
Thaurissan
Matban
11/16/2011
Guess i should get rid of my universal password
Login to rate
Todesritter
Azjol-Nerub
Todesritter
11/16/2011
@Matban: probly should say in a form that you have a universal password
Login to rate
Chromosome
Tichondrius
Chromosome
11/16/2011
@Matban: I second this ^
Login to rate
Ekyu
The Forgotten Coast
Ekyu
11/15/2011
This is why I have about 6 different passwords I use for select things. :D
Login to rate
Zachiri
Bronzebeard
Zachiri
11/15/2011
Wow I gotta say gratz Blizz just for announcing something that doesn't have to do with themselves. I like it when gaming companies care about other companies, compared to a lot the cut-throating you see in business in general.
Login to rate
Twicedaily
Dark Iron
Twicedaily
5/10/2012
@Zachiri: they don't give a rats !@# about other companies. there is a simple reason behind everything blizzard does - money. By warning customers of this possible account theft, they will have less calls of stolen accounts to deal with. money money money
Login to rate
Lolkitten
Blackrock
Lolkitten
11/15/2011
link broken, doesn't link where the text says it does
Login to rate
Bozanimal
Scarlet Crusade
Bozanimal
11/14/2011
DID YOU NOT RECEIVE A NOTICE FROM STEAM?

Steam has THREE separate logins, to my knowledge:
1 - Steam Store
2 - Steam Forums
3 - Steam Support

If you have a Forum account, you ARE impacted. If you have a basic Steam store account that allows you to buy and play games through the Steam Client you are unaffected unless you have a Steam forum account.

Please reply with corrections, if necessary.
Login to rate
Jigawatts
Kirin Tor
Jigawatts
11/14/2011
@Bozanimal: They did say that they were still looking into it to make sure other things weren't accessed, but I doubt they were. However, it's unlikely that the store was also hacked.
Login to rate
Potluck
Cenarius
Potluck
11/14/2011
@Bozanimal:

You need to read the message CAREFULLY.

He says, "If you have used your Steam forum password on other accounts you should change those passwords as well."

See below for the full announcement.

---------------------------------------------------------
Dear Steam Users and Steam Forum Users,

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.
---------------------------------------------------------
Login to rate
Bozanimal
Scarlet Crusade
Bozanimal
11/14/2011
I appreciate the feedback! Still, I think my original comment still seems accurate. To their knowledge no other Steam services were compromised. If you use multiple Steam services that use the same password, or the same password on other sites (as Blizzard mentions in its announcement), you need to change them. That said, you should never use the same password for multiple sites, anyway. ;)

If you do use the same password for multiple sites, consider instead using an encrypted password manager like Password SAFE. It allows you to generate random passwords and manage those passwords across multiple sites. Once it's set up it is extremely convenient, and makes web browsing and e-commerce significantly safer.

Happy - and safe! - gaming.
Login to rate
Maxwelljd
Sen'jin
Maxwelljd
11/14/2011
@Bozanimal: The notification i just recived says that all sections of steam got intruded and even the encrypted credit card data was placed at risk. There is no save zone right now, and all i can say is that 15 month for x-box live and the security that it offers is very nice compared to having your credit cards taken from you 2 times in one year.
Login to rate
Auston
Ysondre
Auston
11/14/2011
steam said that it was the forum accounts. having just a steam account doesnt mean you were part of what was hacked. i know people have stated this below me but i figured i would keep up the update since some peeps dont scroll down too far on forums
Login to rate
Potluck
Cenarius
Potluck
11/14/2011
@Auston:

This is somewhat false because if you use the same password and email for the other accounts, then you are screwed. The operative sense here is if you are LAZY, INCOMPETANT and just too STUPID then you're gonna be screwed in all of your accounts. This is the reason Blizzard posted this warning here. Some of you only have one email for everything and are likely to be affected by this. Also note that he also said:

"We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information."
Login to rate
Auston
Ysondre
Auston
11/14/2011
We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.
Login to rate
Maxwelljd
Sen'jin
Maxwelljd
11/14/2011
@Auston: Actually on the 10th they said that all databases were violated. Not just forums. So even the encrypted and identifying information was placed at risk.
Login to rate
Koonannirc
Nathrezim
Koonannirc
11/14/2011
To the people complaining about Steam: Steam is free. If you were paying for it then you can !@#$% and complain. And its digital downloading service isn't all THAT bad, and most people have at least DSL these days (which is fast Internet). If you don't, well, Sad for YOUUU!
Login to rate
Badjudgement
Tanaris
Badjudgement
11/14/2011
@Koonannirc: I have slow internet......*sadface*
Login to rate
Lenâ
Grizzly Hills
Lenâ
5/11/2012
@Badjudgement: i understand that most dont go out where that person lives......i have had that till i moved in to the city
Login to rate
Kittencute
Arthas
Kittencute
11/14/2011
Well, I made a steam account about two weeks ago when I heard Skyrim was going through Steam, same email & password as Battle.net.

I ain't scared. I really don't think those so-called "hackers" are actually going to get the unencrypted information out of what they apparently managed to get.

In the case they do, and I end up getting my Battle.net account hacked, I probably won't be too worried as I know Blizzard has the absolute best customer support available for getting everything restored to how it was before the incident.

Though they probably don't like having to restore things over my laziness to change a password... /rolleyes
Login to rate
Potluck
Cenarius
Potluck
11/14/2011
@Kittencute:

This is kind of naive of you. You do realize that your credit card information will likely trickle to black markets and then they'll assume your indenity and sign up for all sorts of crap you didn't even know existed and without you knowing until your credit score is examined years down the road.
Login to rate
Maxwelljd
Sen'jin
Maxwelljd
11/14/2011
@Potluck: That is why i dont use credit cards. However! Every purchase i do online is from paypal, so even if they got access to my payment method there is no card bound to the paypal i used so minimal risk there.
Login to rate
Lenâ
Grizzly Hills
Lenâ
5/11/2012
@Maxwelljd: but some poeple dont think or dont have the ablilty for them