• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

Millons of PSN, Windows LIVE, 2K etc passwords hacked.

I JUST went through updating all my old passwords because people were logging in to a bunch of sites as me thanks to a recent hack. I use different passwords for each site, but still, fuck that noise.
 
Good thing my PSN password is very old (it's from 2010 and I pretty much only use it for PSN) and when I buy digital stuff I use prepaid cards.

I like to stay 100% physical and in cases like this it's very convenient.
 
They didnt "hack" those services. The passwords are NOT stored in a DB, the passwords of the credentials are just salted - hashed files and that's it, therefore they got the usernames and password by other means , like a key loggers, backdoors and so on.
 
Well, it's a way to show the customers and people in general how vulnerable everything on the internet is. And if the sensitization for this fact to remember requires such a dramatic measure, I won't blame the hackers for this.
This kind of threat teached me once to never leave the CC data at any online retailer, where you can avoid it.
 
Yeeeeah, just about none of these passwords seem real. I'm skeptical that this is real. Changing password just in case, anyway.

oh they seem real allright. I've worked in customer support and people used to send us their login details with the password all the time asking why they don't work.

And the passwords for most "normal people" are just like that. First names, dirty words, password123 etc.
 
I see one of the 2K account's password is "aaa". There has to be no way they would let anyone use a password consisting only of three identical characters.

Come on that's stupid, just a quick look at the list and it makes no sense

3 numbers pw? Really? : gana***2@yahoo.com:224
It's getting better : sw***l@homtail.com:1 (homtail, yeah !)
Ok, this guy doesn't even have a pw : david_***strom@hotmail.com:


these so called hackers can't even generate a proper log/pass list...

(i censored parts, you know, just in case)

.
 
Not there, must be fake I think. But hey, they are a "derptrolling" hacker group. They could just make this up for fun and fake it.
 
This is like some fear campaign or something. Thats fucked if just making a claim like this will get a huge reaction. Especially if they didn't actually hack anything.
 
They didnt "hack" those services. The passwords are NOT stored in a DB, the passwords of the credentials are just salted - hashed files and that's it, therefore they got the usernames and password by other means , like a key loggers, backdoors and so on.

I see one of the 2K account's password is "aaa". There has to be no way they would let anyone use a password consisting only of three identical characters.

these two things seem to align as well. They might not be actual passwords from a database, but passwords their keyloggers sniffing what the user was inputting at the time.
 
oh they seem real allright. I've worked in customer support and people used to send us their login details with the password all the time asking why they don't work.

And the passwords for most "normal people" are just like that. First names, dirty words, password123 etc.

The stupidity of the passwords isn't what's suspicious, it's the lack of requirements being met to actually create a password. For example: "518". Did psn EVER let people get away with passwords like that?
 
The stupidity of the passwords isn't what's suspicious, it's the lack of requirements being met to actually create a password. For example: "518". Did psn EVER let people get away with passwords like that?

yeah, see my last post, these do sound more like passwords their keyloggers sniffed from virus infected users. The system just logs everything the user types. So in some cases it might be correct as most people would type in the login and password one after the other. But sometimes you might just hammer on the keyboard, make a typo, change windows etc. and the keylogger will be confused.

This is just a raw data dump of the keylogger information.
 
yeah, see my last post, these do sound more like passwords their keyloggers sniffed from virus infected users. The system just logs everything the user types. So in some cases it might be correct as most people would type in the login and password one after the other. But sometimes you might just hammer on the keyboard, make a typo, change windows etc. and the keylogger will be confused.

This is just a raw data dump of the keylogger information.

Well, it'll be interesting to see how all this unfolds. I already changed the passwords to all the accounts I can think of, just to be safe. I sure hope no bad comes of this.
 
Yeah, regardless of whether this is just deception, I recommend updating your passwords. I'm actually kind of amused that this has happened after having just started using LastPass for the past month or so.
 
You'll need to download the .exe file and check ;)

166.gif


Also, this is a good reminder that PSN doesn't have 2 step verification. Fix this shit Guerrilla, Xbox Live has it.
 
the fact that they stolen only 2k PSN password means that they did not hack the PSN, they hacked something else, and due people stupidity, the password was the same.
also, Live Password are the same as XBL right?
 
Seems like this is leaning towards being fake. I sure hope it is. You'd imagine Microsoft or Sony would alert everyone if there was an issue.
 
Well... those guys are actually pretty clever.

Those are DDOS guys. And then presenting fake Accounts....

Okay this is what happens : Everyone changes their Account pws -> DDOS attack from normal costumers.
 
It seems there is a decent amount of evidence that this is a fake so I'll wait for more information/confirmation before panicking. Wouldn't hurt to change my passwords though. Man, what a pain...

Fuck people who do stuff like this!
 
This is like some fear campaign or something. Thats fucked if just making a claim like this will get a huge reaction. Especially if they didn't actually hack anything.

This is the scariest part. You can apparently tweet a pastebin out with alleged details, send some quotes to a news outlet, and get a story published like this where the claims are simply taken as fact.

Note the lack of words like "allegedly" in this article. Terrible reporting.
 
Just to add some more fuel to the "It's fake" fire:





And so on. Some of the e-mail accounts do exist but I strongly doubt the passwords are legit.
maybe these emails are from some old ass password hack and these names were recycled? hotmail deletes accounts after months of inactivity right?
 
You know those socially awkward people you meet who can't help but one-up EVERYTHING? You know, there always someone in their life that has done whatever you're talking about better, bigger, faster.

These people make me think of them.

I'm calling fake. They probably got in a strop because no one was taking them seriously.
 
Im not on there either...but I really wish hackers would actually fight things that are harming everyone else's well being and not make trouble.
 
Top Bottom