• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Funcom forums hacked (The Secret World, Age of Conan)

Wollan

Member
Received this e-mail an hour ago:

Data Breach on Funcom Forums

On August 24th, 2016, we discovered that user data associated with forum accounts on TheSecretWorld.com, AgeofConan.com, Anarchy-Online.com and LongestJourney.com have been compromised by a third party.

We regret to inform you that the data breach includes e-mail addresses, user names, and encrypted passwords associated with forum accounts on these forums. Even though passwords were encrypted, these can be cracked and should be considered compromised. It is important to note that forum accounts and game accounts are separate and are stored on different servers using different security systems. Game accounts have not been compromised.

The breach was possible due to a security fault in the vBulletin forum system. This security fault was corrected on our forums on August 19th, 2016, but we are unable to determine exactly when the data breach occurred prior to the fix.

As a temporary security measure, we have reset all passwords for every forum account on TheSecretWorld.com, AgeofConan.com, Anarchy-Online.com and LongestJourney.com. The next time you try to log in you will be told your password is incorrect and you will have to reset your password to continue. If you have used your old forum account password on your Funcom game account or any non-Funcom accounts, you should also change your password on those immediately.

We take this incident very seriously and will be taking measures to ensure it does not happen again. The bug that made this data breach possible has been corrected, but as a precaution we have taken our forums offline so we can conduct further investigations and ensure there are no more security issues before we bring them online again.

We sincerely apologize for the inconvenience caused. If you wish to talk to us, please get in touch with our customer service representatives via http://help.funcom.com and we will get back to you as soon as we can.

Thank you for your attention.

Best regards,

Funcom
 
oh no.

on another note: op, the link in your tag doesn't work... unless that was intentional


edit: never wipe a keyboard while in a text box
 
So what was the point then...


Most likely the passwords were stored as simple hashes, the culprits then compare those hashes to known values, then use those passwords with their associated emails to get into something more secure...

The first target would likely be their game accounts as many people would use the same password for both, but maybe it's the same passwords they also used for their emails, etc.


Or are you saying in encrypting them to begin with? Why make hackers jobs too easy? Also a long secure password is a lot harder to crack and likely not worth the time.
 

derFeef

Member
I have forum accounts on all of them, luckily and of course not the same passwords like somewhere else. Sucks though, why ...
 

snitch

Neo Member
I sincerely hope they mean hashed and not encrypted. If they're encrypting passwords; they fucked up.
 
I can't remember if my forum account shared credentials with my actual account. Guess I'll change the password to make sure nobody gets their hands on all my awesome role playing gear.
 
Neogaf runs vBulletin.

I know and as far as i'm aware they have never been hacked. That doesn't change the fact that it is frequently in need of patching/updating to stay ahead of all of the discovered vulnerabilities. This assumes there's someone in charge of doing this for Neogaf. I can guess with certainty that this is one of the exceptions across all the sites that use vBulletin.
 

Audioboxer

Member
Probably explains some of the recent PS4 account compromises...

I have an account but the password as always was long, unique and created by last pass. Chances are though the criminals have been trying to use my email to log into other services.
 
Top Bottom