• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

npa189

Member
Mobile app seems to be effected as well, I can see other people's accounts when I go to look at mine. I think I'm done with storing CCs on online storefronts all together after this. Hopefully this doesn't end up as bad as it looks.
 

FluxWaveZ

Member
It sounds, then, that if you were never logged in before this whole thing started and haven't tried, your account can't get accessed by the caching issues?
 

Beowulf28

Member
This is so fucked. I'm getting random emails from people on steam saying they're in my account and deleted my CC info.

WHAT IS HAPPENING.
 

Grief.exe

Member
What we know so far

  • Most likely an error in the way Steam caches pages.
  • People are able to access random Steam profiles and see compromising information, account names, emails, last 2 digits of credit card, paypal email address, purchases, etc.
  • Full addresses and phone numbers were able to be accessed.
  • No changes can be made to the effected account, no purchases can be made. Any evidence to the contrary is, as of yet, unsubstantiated.
  • It's been advised to not access Steam URLs, including the client, until we have more information.
  • Do not post account names you see, huge security risk.
  • Do not log into Steam to unlink your Paypal. If you feel the need, can be done from the actual Paypal website.
  • Reminder: Steamdb is not affiliated with Valve in any way.

bJK2asd.png


owZ6BYU.png


3lbQyvr.png



I'll update this post with more information going forward.
 

DMczaf

Member
how have they not shut the servers down yet? There's some damn important information being displayed with this fuck up.

This is fucking ludicrous.
 

K.Jack

Knowledge is power, guard it well
Valve needs to cut the fucking hard lines, until this is fixed.

Shut this fucking shit down man!
 

MattyG

Banned
Wait, so what should I do about this? I'm not logged into the store and I don't have steam open on my PC, but I have my CC info stored. Should I login and change it or just stay logged out?

Edit: Ah, nevermind. Thanks Grief
 

Arren

Member
Except I made it all the way to the purchase confirmation page on someones account with no passwords entered, and that many others have had games bought with their accounts, and that also many people have had their info changed... so this post is invalid.

Exactly, unfortunately that is false. Billing addresses and complete phone numbers are currently compromised and accessible to other random people and there have been lots of user info changes reported in this very thread.
 

benny_a

extra source of jiggaflops
Well this calmed me down a bit. Will definitely change my email and never save my card info again though.
I wouldn't take that at face value.

This has been ongoing for approx. 45 minutes. Just because certain things don't work now any more doesn't mean there wasn't a window where they did work, as several posters have said they were affected.

In the end who knows, could also be coincidental. But things happening T+5 mins are not disproven by saying things don't work T+45 mins.
 

yatesl

Member
You'd be wrong. Someone definitely removed my phone number from my account.

Are you sure? I just tried to delete someone's, and it didn't work. I also tried to delete someone's PayPal details, and someone else's CC details. I can't see any addresses.
 

cptodin

Member
That's the reason why´I never save any details on stores.
First thing I do is change my password when this issue has been resolved, just to be on the safe site.
I guess everyone should do that...
 

jmga

Member
It's worse. Depending how long this has been active for people could have lost millions that Valve will have to compensate for.

You can't do any purchases.
You can't see phone number nor CC info.

They fucked up, but the only personal data compromised here is email.
 

rdytoroll

Member
Jesus christ. Stop it with the excuses already. Even only seeing someones phone number and e-mail is a big breach. And people have reported that they could delete other's information.
 

strafer

member
Well, I was about to go out for dinner, that is not going to happen now.

I'm going to sit and guard my stuff very clearly. I'm not leaving my computer.

And Valve, can you just please shut the stuff down.
 

HardRojo

Member
Why are people now trying to delete and mess with other people's stuff? just log out of steam and wait until it's fixed. Jesus.
If people going out of their way to screw others by spoiling Star Wars wasn't enough evidence, people will be assholes when the opportunity presents itself and they feel no punishment will come for them.
 
I think this has indeed something to do with caching. While being confused myself I've seen a bunch of Russian/Polish/English not-logged in main pages, and a pair of registered Poles. (Shut-outs to Victor and Zeus, merry Christmas pals!)

Browsing Steam web portal logged in may result in your data being cached in turn, so the advice to not do anything until Valve does something about it isn't the worst one.
 
D

Deleted member 125677

Unconfirmed Member
Stump do you want me to clear your account of turd games?
 

Zomba13

Member
I'm confused at this "it's a holiday" shit. I mean, you telling me they don't have anyone anywhere handling this able to shut stuff down if it gets bad? Don't they typically offer more pay for holidays to get what few people they can to stay in and work when it's a big huge online thing?

Yeah, they won't have everyone. Yeah, they didn't expect this and are understaffed but they should have some people there able to handle this and if not fix it at least shut it down so nothing gets worse.

Then again I guess losing out on Christmas day sales isn't worth it.
 

Vuapol

Member
So when I view my account information I am some poor bloke from the UK, with all of his information for me to view. When I see purchase history, I am some different fellow from Canada. When I view Product Keys, I am some other different fellow from Latin America.

This is pretty fucking bad Valve.

Thank god I use Steam Wallet Cards for everything, good god. Hopefully the assholery of screwing with other's accounts will be as little as possible with the holiday and whatnot.
 
Top Bottom