• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

cw_sasuke

If all DLC came tied to $13 figurines, I'd consider all DLC to be free
Some stupid posts on the last 2 pages - some people just wanna see the world burn.

How can you unlink Steam from your PP account via the PP Site ? Cant see that option.
 

Grief.exe

Member
how does a company like steam have ZERO social media presence for stuff like this? This is extremely laziness or hubris.

Historically, Valve hasn't exactly been a chatty company, but it is possible they are waiting for all of the information and a solution before posting.

Would be nice to see a standard, 'we are aware of the issue and working on a solution,' post.

most of my friend's list is still playing games as usual

nothing-stops-this-train.gif

I just want to buy Sunless Sea and Downwell and check out some legitimate GOTY candidates.
 

a916

Member
So fortunate it doesn't have my existing credit card on the acount. So fortunate.

I hope for all those affected that their credit cards cover everything smoothly and Valve issues a prompt apology and what not.
 

GuardianE

Santa May Claus
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

Next time, please use a little discretion and source your image. Preferably with a link.
 

TheTux

Member
So it would probably be good to clarify if you're posting a meme image, if so from where, whether there's any reason to believe this is real or if it's just an edited screenshot, etc.

I agree.

I'm sure there are people out there photoshopping images right now just to create panic.
 

Shepard

Member
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.
How could they access cc info? I mean, you could only see the last digits.
 

DeaviL

Banned
As one of the accounts affected by this (shout-outs to the nice random people on Steam contacting me to chat because they were in my account and looking at my stuff--all seemed like standup, trustworthy guys), the basic information I want to know:

1) Was this a breach, a staff error, or a configuration error that happened due to some unusual hardware cascade situation?
2) How many users were affected?
3) How many people accessed my information?
4) What information did they access?
5) If my address or cc info was even partially exposed, I expect a year or two of credit monitoring
6) If a breach, was my tax information accessed
7) Will I be permitted to change my login username in light of this?

It goes without saying that if purchasing was exposed they should do a full rollback, but I'm not worried about that because that's obvious. More worried about the personal info.

1) You saw the pages people recently visited on their account. So a server problem.
2) Everyone browsing Steam during the problematic period.
3) Depends on which pages you visited, if you didn't enter account info then no one has.
4) See 3
5) Dunno
6) Dunno
7) Probably not

This should be correct.
 

TimFL

Member
I mean this could easily be shopped...

Or someone is using the sandbox feature that literally allows you to create accounts and push through fake transactions for the sake of testing your PayPal integration in your app/website etc.

Last time I checked all Steam PayPal purchases are titled WWW.Steampowered.com and not STEAMPOWERED.COM

//EDIT: That screen literally says "Sale" and the amount is positive instead of negative.
 

Hektor

Member
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

It's not spreading panic, it's a realistic scenario. The image could be fake for all we know, but I'm looking at people's CC info on 4chan right now.

Not surprised by that. FFS valve.
 

Accoun

Member
My thinking exactly.

I know it's easy to jump to conclusions on these matters, but we need confirmation.

Wasn't there a limit on how much you can buy at once? Or at least a Steam Wallet limit (I might have mixed that up if there's one). I vaguely remember hearing something like that.
 

Vamphuntr

Member
Can someone knowledgeable explain to me how can something like this happen? There's no security fail safe regarding cached data? I find it pretty weird they didn't think this could happen.
 

Tainted

Member
I guess Steam Guard is working correctly. Was unaware of this Steam fuck up and when I tried logging into my account, I got email from Valve saying there was a login attempt from me (IP address on email is identical to my pc's IP address).

So, I should be ok?

There were some here saying they were viewing details of steamguarded accounts during the breach....so who knows at this point.

Until we get an official statement from valve on what was compromised etc we are all just guessing
 

Grief.exe

Member
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

It's not spreading panic, it's a realistic scenario. The image could be fake for all we know, but I'm looking at people's CC info on 4chan right now.

...and people were posting account names in this thread.

Some stupid posts on the last 2 pages - some people just wanna see the world burn.

How can you unlink Steam from your PP account via the PP Site ? Cant see that option.

Then you are fine.
 

Lagamorph

Member
So, what excuses explanations do we think Valve will give for how this totally isn't their fault and they therefore owe nothing to those who've had their private information given to random people?
 

inky

Member
I don't give a shit about free games. I care what Valve is going to make to allow me to protect my info if any got out, which is very likely.
 

iNvid02

Member
i dunno about you guys but i can only think of 1 thing that could adequately compensate me for this gross violation of privacy, it begins with a h and ends with a 3. i think you know what im talking about dont you.
 

Smash88

Banned
Next time, please use a little discretion.

Other GAF users were reporting that they were getting steam wallet charged. It's not an unrealistic scenario.

How could they access cc info? I mean, you could only see the last digits.

I have no idea, all I'm seeing is info being posted. Name/Visa/Address/etc. I have an image of a post, of course we don't know how authentic this is.

I will repeat I said it wasn't me and I found people reporting it on /r/Steam. People on GAF have confirmed things can be purchased, whether it is exaggerated or not, or real or not, it's a real scenario even if the image was shopped (and for our sakes I hope it was shopped).
 

eFKac

Member
Jesus what a huge fuck up.

Just got to the thread, any security measures advised beyond what is said in OP? Thank you.
 

Dryk

Member
Once they have Steam properly working again, I'm removing my CC info and making a dedicated email for Steam only. Fuck this.
Turn on mobile authentication for Steam and/or email so that any prospective hacker has to physically track you down to get into your account
 
Top Bottom