Quantcast
Destructoid Japanator Tomopop Flixist
Dtoid Forums now support TapATalk and ForumRunner on your iOS/Android devices. Whoot.

A Steam database has been hacked, warns Valve photo

Following talk that the Steam forums had been hacked, Valve's Gabe Newell has issued a response. The official forums were in fact "defaced" on Sunday, and unfortunately, intruders have gained access to a Steam database as well.

"This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked."

The investigation is ongoing, though Valve recommends you watch your credit card activity to be safe. There is no evidence of credit card misuse yet, and the company is only aware of "a few" compromised forum accounts, but you should still change your password(s). As far as Steam accounts go, Valve has yet to come across any that were compromised.

[Image]

Dear Steam Users and Steam Forum Users,

Our Steam forums were defaced on the evening of Sunday, November 6.  We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums.  This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don't have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely. 

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well. 

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn't be a bad idea to change that as well, especially if it is the same as your Steam forum account password.  

We will reopen the forums as soon as we can. 

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.








More gaming stories around the web. Got news? Submit yours to tips@destructoid.com

Jordan Devore is Destructoid's PC gaming manager and founding ginger editor. He is said to be easy to love but difficult to know. When Samit inquired about his curious bio photo Jordan simply replied: "bitches love sandcastles" ... yet, there is no sandcastle in that photo. We may never truly understand his ways. Likes Platformers, Pixel-based graphics, Stickerbrush Symphony, Pokemon, Leaderboards Meet the rest of the team



Post a comment! You can also post a photo below:

Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

75 comments | showing # 1 to 50
prev
next 50 comments

quantumriian's Avatar - Comment posted on 11/10/2011 17:31
quantumriian
And...here...we...go.
SayWord's Avatar - Comment posted on 11/10/2011 17:34
SayWord
So is there going to be any unwarranted hate like there was towards sony? Probably not.
occono's Avatar - Comment posted on 11/10/2011 17:34
occono
And Steam doesn't even have prepay cards.....
GoodlyMike's Avatar - Comment posted on 11/10/2011 17:36
GoodlyMike
Jesus Christ...
Klarden's Avatar - Comment posted on 11/10/2011 17:39
Klarden
...what a misleading title. Steam datebase was PROBABLY ACCSESSED. IF it was accessed and downloaded, all the important info needs to be hacked as well, which is nigh imposiible, since it was "hashed and salted".
josmeister's Avatar - Comment posted on 11/10/2011 17:40
josmeister
@SayWord
Well, unlike Sony, everything was encripted and even if they take your account they wouldn't be able to get into it due to SteamGuard.
Anyway, I changed my password and secret question today without knowing about any of this, which was pretty damn aweeeesome.
Enzi's Avatar - Comment posted on 11/10/2011 17:41
Enzi
@SayWord: No, because absolutely everything is encrypted. In the case that they really did a proper job and I hope they fucking did, we don't have to worry.
God Complex's Avatar - Comment posted on 11/10/2011 17:42
God Complex
FUCK YOU JORDAN AND YOUR FUCKING SCARY SPIDER
psycho terror2's Avatar - Comment posted on 11/10/2011 17:42
psycho terror2
i fucking love salted hash browns.

i'm not worried by this despite being a steam user.
Epic-Kx's Avatar - Comment posted on 11/10/2011 17:43
Epic-Kx
Gabe really meant to say:

"Them bitch ass niggas messin with MAH steam? Aw hell naw, they brought beef. I'm bringing the ruckus."

Go get em, Gabe!
God Complex's Avatar - Comment posted on 11/10/2011 17:43
God Complex
i may have over reacted there, but that spider is fecking creepy
Shane Saiyan's Avatar - Comment posted on 11/10/2011 17:46
Shane Saiyan
For the last fucking time people Sony's info WAS encrypted. Stop spreading that fucking LIE.

*facepalm*
Joseph Leray's Avatar - Comment posted on 11/10/2011 17:47
Joseph Leray
@Klarden -- what other word besides "hack" describes unauthorized access to a server or database?

"We learned that intruders obtained access to a Steam database in addition to the forums."
Klarden's Avatar - Comment posted on 11/10/2011 17:50
Klarden
@Joseph Leray
ability to access it and download it as it is. to hack it is to gain access to what's inside it.
but okay in this. it's misleading because it sounds as if the important info was hacked. and it wasn't. in fact it's not even known if hackers knew what was in their hands so far
Syn's Avatar - Comment posted on 11/10/2011 17:50
Syn
@SayWord: Valve also didn't wait weeks to inform everyone.
mix's Avatar - Comment posted on 11/10/2011 17:52
mix
VALVE IS A JOKE AND I AM GETTING RID OF EVERYTHING VALVE BECAUSE THIS COMPANY SUCKS BANANA BREAD..........oh wait it's Valve and Steam? No biggie, keep on being Steamy and shit.

Sony was indeed encrypted and shit gets hacked and stolen all the time and just like when Sony was hacked, two shits are not given by me. I will change passwords and watch my credit card like I do all the time. If you don't look at your statement each month, your doing it wrong.
Janklogs's Avatar - Comment posted on 11/10/2011 17:53
Janklogs
What now, PC gamers? WHAT NOW?
Klarden's Avatar - Comment posted on 11/10/2011 17:55
Klarden
@Shane Saiyan
actually, it's Sony's fault (their PR guys, to be precise) that people say it was unencrypted. They didn't clearly say that info was also hashed (like here with Valve) until almost before PSN started working again.
Plus, people simply don't trust Sony enough. And that info mixup made them even less trusting.
Klarden's Avatar - Comment posted on 11/10/2011 17:57
Klarden
@Syn
Valve waited almost a week, which was really frustraiting. Talks of a forum hack were since it happened 5 days ago. Still, it seems that it was because they were sure everything's under control, apparently.
UltorOscariot's Avatar - Comment posted on 11/10/2011 17:59
UltorOscariot
Attack the Holy Valve? These infidels gotta die.
Pringao's Avatar - Comment posted on 11/10/2011 18:02
Pringao
I think corgis are cooler than spiders.
Sonic7877's Avatar - Comment posted on 11/10/2011 18:02
Sonic7877
During the PSN attacks I just cancelled my credit card and got a new one. No problems here. It was a pain in the ass not being able to get online for so long though.
Tristrix's Avatar - Comment posted on 11/10/2011 18:03
Tristrix
Hack Sony, you're a freedom fighter. Hack Steam, you're a terrorist.

#gamerlogic
Manthai's Avatar - Comment posted on 11/10/2011 18:04
Manthai
I just emailed Gabe about this and he said that even though I am using Steam Guard I should change my pw just to be safe.

True story. What a cool guy.
CapTN Riggz's Avatar - Comment posted on 11/10/2011 18:08
CapTN Riggz
Good job posting this quick Jordan. Saw this upon launching steam 20 min ago and changed my PW. At least Valve let us know reasonably fast unlike a certain other company ... lol

JimmyX get on top of this investigation NOW!
Syn's Avatar - Comment posted on 11/10/2011 18:12
Syn
@Klarden: I'd argue that 5 days isn't quite a week, but it's moot. Sony waited week(S) with an S to tell people their info had been compromised.

Not that it affects me one way or t'other. I've never put a CC number into the hands of either company.
The Silent Protagonist's Avatar - Comment posted on 11/10/2011 18:13
The Silent Protagonist
@sayword

Valve had encryption. Sony didn't.
Valve informed their customers within a couple days, Sony waited a couple weeks.

Also, valve clearly updates their shit, before this year Sony was skimping on security updates.
Cla's Avatar - Comment posted on 11/10/2011 18:15
Cla
I would love to change my forum password, but I can't because the Steam Forums won't do anything else besides telling me that I should change my password.
Ace829's Avatar - Comment posted on 11/10/2011 18:15
Ace829
@Tristix Who are these people, specifically, that think this way? I'm pretty sure it was nearly unanimous opinion that the hackers were scumfucks.
TechnicolorDewDrop's Avatar - Comment posted on 11/10/2011 18:17
TechnicolorDewDrop
@Syn: Actually, Sony waited about about a week (maybe a day or two more) to tell people info was compromised.
GREENGUY's Avatar - Comment posted on 11/10/2011 18:21
GREENGUY

Well shit
ZRB's Avatar - Comment posted on 11/10/2011 18:22
ZRB
As a huge steam gamer and valve supporter, I still have to say that this incident wasn't handled very well and people have the right to be angry (just as some were with the sony incident). There have been indicators all week that something was going down but we haven't heard anything about it until today.
Tristrix's Avatar - Comment posted on 11/10/2011 18:22
Tristrix
@Ace829

Really? You didn't see all the people claiming it was poetic justice because of the Geohotz thing and celebrating it?

Also worth reminding everyone that Sony's info WAS encrypted. The whole thing about it not being encrypted? Came from a single forum post from an anonymous source on a board somewhere. Seriously. That's the source.
Stop Spoilers's Avatar - Comment posted on 11/10/2011 18:28
Stop Spoilers
Oh boy here we go again. Oh by the Way CC info was encrypted stop spreading fucking spreading false info. http://www.businessinsider.com/playstation-network-credit-card-info-was-encrypted-sony-confirms-2011-4
PalinRMA's Avatar - Comment posted on 11/10/2011 18:28
PalinRMA
Ok Steam, time for some free games now!
KwikPwn's Avatar - Comment posted on 11/10/2011 18:37
KwikPwn
@Tristrix

Sony themselselves admitted on the Playstation blog that PSN's personal data table was unencrypted.
KwikPwn's Avatar - Comment posted on 11/10/2011 18:38
KwikPwn
*themselves
Stop Spoilers's Avatar - Comment posted on 11/10/2011 18:40
Stop Spoilers
KwikPwn: that info was hashed but people have been assuming that ment Credit Card info. Like 10 people said CC info was was left in plain text when that was released and apparently people still do.
KwikPwn's Avatar - Comment posted on 11/10/2011 18:44
KwikPwn
@Waka

The cc table and the personal data table were two different data sets.

The former was encrypted while the latter was not. I wasn't claiming otherwise so I don't quite get your point.
jargy1's Avatar - Comment posted on 11/10/2011 18:50
jargy1
Ok someone with connections let Valve know this is a personal attack against me. I Sherlocked that because when Sony got hit, it was the night I got Portal 2 and I couldn't play co-op or the PC version for a month. Now Skyrim hits tonight and I imagine they'll shut down right before that just o screw with me.

So look for any enemies of mine who are hackers. Should be a short list since most people who hate me are mouthbreathing idiots.
KwikPwn's Avatar - Comment posted on 11/10/2011 18:57
KwikPwn
@Stop Spoilers

CC data was being sent unencrypted from the PS3 to PSN. The danger there was that people would distribute hacked firmware that would direct traffic from those who downloaded their hacked firmware to another server before passing it on to Sony's servers aka a man in the middle attack.
JQM78's Avatar - Comment posted on 11/10/2011 19:04
JQM78
I had my xbox live acct hacked and $80 worth of points purchased. My acct has since been locked and ms is "investigating".
Stop Spoilers's Avatar - Comment posted on 11/10/2011 19:04
Stop Spoilers
KwikPwn: And that would only effect people that had systems with CFW. Try again.
KwikPwn's Avatar - Comment posted on 11/10/2011 19:08
KwikPwn
@Stop Spoilers

That was my point, perhaps I should have worded it more clearly.

Not trolling here guys, just stating facts.
PrinceHeir's Avatar - Comment posted on 11/10/2011 19:08
PrinceHeir
the funny thing is that i remember during the PSN attack that tons of PC Fanboys where acting douchebags on how Steam is "unhackable" or "this never happens to steam"

and look what we have here :D

sure they informed the customers ahead of time, and the CC are encrypted, but but the fact that hackers still manage to do some damage just shows you nothing is safe.

i love Steam and all and Valve will probably handle this seriously.

but still nothing is safe. and i assure you this will not be the last one.
J Dizzly's Avatar - Comment posted on 11/10/2011 19:08
J Dizzly
Spiders are so damn cool
Blahblahblahblah's Avatar - Comment posted on 11/10/2011 19:41
Blahblahblahblah
Spiders?

Fuck you.
FatherChesz's Avatar - Comment posted on 11/10/2011 19:52
FatherChesz
Eye smile. Once you see it, you can't unsee it.
prev next 50 comments

Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

Comments policy

Destructoid is an open discussion community. You don't need to "audition" to post a comment - just speak your mind. We respect differing opinions on the site, so have at it. Be smart, funny, insightful, clueless, or cute -- but back it up with substance. Keep your cool, keep it fun. We only ask that you act respectfully and above all: don't be a troll and ruin it for everyone else. Don't bring down gamers or we'll, you know, gently shoot you in the face and stuff you into a flaming mailbox. Each comment is your opportuntity to make this community awesomer. Is that even a word?

Avoiding the banhammer only requires common sense: spamming, trolling, racism, NSFW stuff, and other forms of sucking will not be tolerated. If anyone is griefing please report abuse. Be good. Don't suck!