• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

Witcher 3 dev forums hacked, 1.8 million accounts stolen

The goal of hacking a major corporation is to keep collecting current data. They want to be as invisible as possible. It could be the case the CDPR did not know that their data has been compromised and just found about it recently. It's no brainer that having current information fetches a lot more money.
 
I got hit. That was signing up to their forums to report unaddressed bugs in TW3 that prevented me from progressing for a couple weeks.

Merged with my GOG account and change password, turned on two-step. Already have my Gmail password changed since then and have two step to phone.
 
Yeah, I was trying to figure out when I signed up for an account since I have no record of registering to the Witcher forums.

Change your password if you use it on any other site. If you used the same one for your GOG account then someone has your password for that too!

CD Projeckt should have done more than make a forum post and notify all of their users by of the breach, old database or not.


Don't worry that much. Passwords were hashed, and cracking one takes ages on even powerful CPU.
 
Stay safe everyone, but hopefully it's too resource intensive for the hackers to do anything with the information.
 
Speaking of which, aren't GOG and CDPR accounts shared nowadays?
I don't have a CDPR account but I have GOG account. Should I be worried? I don't have CC data in there though. Does GOG have 2FA? Edit: it does and I have it. Good. I'm changing my password anyway.
 
I don't have a CDPR account but I have GOG account. Should I be worried? I don't have CC data in there though. Does GOG have 2FA? Edit: it does and I have it. Good. I'm changing my password anyway.

When a personal doubt surfaces, always the answer. Plus, everyone should have unique passwords for EVERYTHING.
 
As long as it's just salted passwords, there's not much issue. Reading the thread title I thought they were storing plain passwords which unforgivable as it is, some companies still do.

The real news for me is that their forums have 1.8 million accounts. That's a damn lot.
 
I'll give them a break because it's evidently from an old database before they switched to the gog.com based system but these companies need to do better. MD5 is just not good enough.

http://forums.cdprojektred.com/forum/en/the-witcher-series/news-aa/7248610-important-unauthorized-access-to-the-forums’-data

Cheers, updated op to correct hashing algorithm used.

Also, I don't think anyone (or at least me) is trying to be tough on CDPR. Shit happens, but it's important to warn users that their info has leaked.
 
It's says on the forum it's a salted md5 hash which is not encryption at all (its a hashing alg) and is not really secure enough at all.

I'll give them a break because it's evidently from an old database before they switched to the gog.com based system but these companies need to do better. MD5 is just not good enough.

http://forums.cdprojektred.com/forum/en/the-witcher-series/news-aa/7248610-important-unauthorized-access-to-the-forums’-data

Uh wow yikes. So all they need to do is figure out what or how the salt was generated. Break one and you break them all.
 
Trying to be as positive as I can about it, at least we know that nobody ever shares their passwords and/or email address across multiple online account logins, so that's a thing, right?

Right?
giphy.gif
 
Top Bottom