• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

Deadly

Member
If you click on anything in the Account Details page it'll keep leading to someone else's page. Weird/scary thing going on.
 
D

Deleted member 80556

Unconfirmed Member
WTF Valve?! I'm so glad that I don't save my bank account on Steam.
 

Bebpo

Banned
Yeah, I'd been having trouble for the last two hours gifting people x-mas presents. The server kept crashing and my credit cards kept being rejected.

Right now having the same issue as everyone else where I see someone else's account info. Also it keeps telling me I'm not logged in and when I try to long in it takes me to the home screen and I'm logged out.

Something is pretty fucked right now.


I thought it was strange the servers were so hammered considering the sales' been going for days now and there's no new deals or anything.
 
earlier on steam was logged in as me but the store kept saying to login to do anything so I left it alone and closed steam, I guess it's related to this.
 
fyi: If you use paypal like I do for steam payments, you can go into your paypal account settings, then click preapproved payments, and find the one for Valve, and then cancel it.
 

RobNBanks

Banned
Jeeeeeeez. HOLY CRAP. This is unacceptable. Absolutely unacceptable.

Somebody could waste thousands of dollars from my bank account, delete all of my licenses, and grab my email.

Steam should shut everything down immediately.

1. They can't delete your licenses. (I'm an asshole and tried to delete some shitty game to see if I actually could)

2. You can restore the license anyway.

cant comment on the other two, i'm not that big of an asshole to find out
 
And now clicking on their activation keys takes me to somebody else's Steam account. This is not good.

EDIT: Actually it looks like there's two different accounts depending on if I go through purchase history or activation keys.
 

Zomba13

Member
It doesn't matter if you have steam guard enabled or set up a mobile authenticator. It's not a case of logging into you account, it's getting access to it from the inside, from their account.

I don't know if you can control who you were swapped with or redirected to but you don't need to log in with their details to get into their account information page so it doesn't matter if they or you have the two step stuff activated.
 
I sent an email to the compromised account. The guy might not know what's coming to him.

Btw can you PM me if you come across my account "Alpharticle"?
 

Morrigan Stark

Arrogant Smirk
Posting someone else's account name is a security compromise. Delete the image and reupload.

Imgur has the ability to completely delete the image, but you need to go back to the initial upload page.
Don't be ridiculous. A Steam username without any other context isn't a security compromise. It's just a username like a GAF name. Edit: Plus it's interesting to see that different people here see the same names, like it's really a handful of compromised accounts somehow...

Posting the screenshots with transaction history is shitty, however.
 

Slayven

Member
Glad I only use gift cards and never tied a real credit card to steam.

And knowing steam support they know duck all how to fix it
 
It seems to show accounts of people in your region and related to IP.

I tried my steam account and brother's and another one of mine on the same IP address, it shows the same account. Change ISP/ip address, different account shows up. In other words, all my steam accounts that login with my IP shows "user x", if I change ISP/IP, all my accounts show a different "user Z". It seems somehow related to IP/ISP. Also the accounts being show are of your local region it seems. Every few mins the user changes and all other of my accounts on my IP get that same user. I can see the credit card's last 2 digits but I am not going to edit it. Staying away from this, not sure if it'll show the rest of the info (I doubt it) but I wouldn't want someone snooping into mine so I'll not do it to theirs.

May just be anecdotal to me though.
 

Fandangox

Member
My friend informed me. When you go into 'Account Information' via Steam Client, it leads you to other peoples pages.

I looked at it and there is another guys page named 'minkey314' and it has saved credit card information, which is not mine. I can see his mail address clearly. Also if that random guy has money in Steam Wallet, I think you can spend it too. Mine has $0 at all.

I think big security issue is happening right now. You can check it with Steam Client. I am not gonna upload a screenshot because I dont want to spoil that guys e-mail address or other info.

Just tried it, it took me to the exact same user as you.

Good thing I never have any of my card info on sites.
 

Zoracka

Member
It seems like you can remove licenses, too. I have for obvious reasons not pressed it, but it's pressable.

What the fuck.

Edit:

1. They can't delete your licenses. (I'm an asshole and tried to delete some shitty game to see if I actually could)

2. You can restore the license anyway.

cant comment on the other two, i'm not that big of an asshole to find out
 

Tomat

Wanna hear a good joke? Waste your time helping me! LOL!
db8f34ffdc.png

I laughed.
 
Why do people keep saying Valve fucked up? This sounds like an attack of some kind.

Also, not logging into my account until this is resolved.

It doesn't matter if you log into your account or not, the porblem is that other people potentially could do.

And of course Valve fucked up.... I've never seen an attack where other users can just view other users info.
 

Burbeting

Banned
I have the same problem, what the heck is going on... At least I don't have my credit card information put in, but I do have aroun 12 euros in there.
 
Top Bottom