• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

Tenebrous

Member
Shit, mine too. I can see another British guys purchase history, email address, funds, etc...

How do I remove my CC info when I can't get to my payment page?! I seriously can't afford to be overdrawn.

Oh shit, get ahold of your banks/card companies steamGaf, hope every turn out alright

It's Xmas day. It's hard enough to contact Natwest on a Tuesday, never mind Xmas day.
 

Vibranium

Banned
So much for steam guard, email confirmation, phone number and whatnot...
Why hasn't Valve shut it down yet?

Yeah, they certainly look bad after having tried to justify stuff like the phone authenticator and 72 hour trade holds.

I hope this is fixed fast, scary stuff...
 

Stiler

Member
I can see some chester guys account.

I've also seen other people here talking about seeing tihe same exact account that I see.

So I am thinking that it's a select amount of poeple that everyone is seeing and not simply every single steam users account randomly logging you into others.
 

Alucrid

Banned
Yep that's some scary shit.

I'm also getting the account details from someone in the US ("").

Please fix this shit asap, Valve!

And don't worry orensaf-bro I won't mess with your account. :(

i got that same person too

now my steam store page is in spanish


i'm not multi lingual, please help
 

MrV4ltor

Member
Switching through people's accounts as I'm selecting games and able to look into other people's carts and wishlists too. This could turn into a disaster if it isn't fixed soon.
 

The Technomancer

card-carrying scientician
If we are just getting funneled to the DDOSers accounts its still an unacceptable security flaw for obvious reasons but it does make me slightly less panicked about my personal account

I've got a guy named Plitt45 by the way
 

Grief.exe

Member
Don't be ridiculous. A Steam username without any other context isn't a security compromise. It's just a username like a GAF name.

Posting the screenshots with transaction history is shitty, however.

That is unequivocally false.

A GAF user name is publicly available, while a Steam user name is completely private for security reasons. Beyond that, no payment or personal information is tied to a GAF account unless a user chooses to do so.
 

taco543

Member
So I got on steam and to pick up a couple games and it keeps pushing me through peoples accounts and this is bad guys... I can see the persons full name and phone number and address...

plDR0uV.png


My names not james....
 

dispensergoinup

Gold Member
Welp, my account details shows up as:

Error Code: -302

Unable to load URL, bad hostname or format

So maybe they took it offline on purpose? Fuck, if it's still going on I wanna take my cc shit off of it!

EDIT:

NVM MINE IS IN CHINESE! Won't post his username but goddamn this is ridiculous!
 
If I go to account details, it always brings up the same user.
But if I go to purchase history, or view licenses it goes to different users, but always to the same users.
This is madness.
 

Mithos

Member
Steam (website through browser, not steam client), it's all Russian for me, and from within the client it's random languages depending on what i click..
 

Haunted

Member
So what's the best course of action to protect your account right now?

Is there even anything a user can do?
 

ItIsOkBro

Member
1. They can't delete your licenses. (I'm an asshole and tried to delete some shitty game to see if I actually could)

2. You can restore the license anyway.

cant comment on the other two, i'm not that big of an asshole to find out

I mean it's still a huge compromise to privacy.
 

Crackbone

Member
If we are just getting funneled to the DDOSers accounts its still an unacceptable security flaw for obvious reasons but it does make me slightly less panicked about my personal account

I've got a guy named Plitt45 by the way

Same. Same dude here. Mobile app is just giving me errors but desktop client it's the same guy.
 
Top Bottom