Many of you have probably noticed the recent Steam forums downtime, but Valve have today confirmed that it's more than just technical issues. In an message sent to the Steam user base, Valve chief Gabe Newell revealed that not only were the Steam forums defaced by hackers, but customer database records of forum users were accessed.
We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.
We don't have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.
While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.
We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn't be a bad idea to change that as well, especially if it is the same as your Steam forum account password.
We will reopen the forums as soon as we can.
I am truly sorry this happened, and I apologize for the inconvenience.
With so many big titles depending on Steamworks support this holiday season, we're certainly glad this has only affected the functionality of the Steam forums and not Steam proper thus far. Let's hope it stays that way.
Posted 09:56am 11/11/11
Posted 09:57am 11/11/11
Posted 10:18am 11/11/11
A good time to remind people to maybe turn on Google 2 factor authentication. If you get hacked there (like I did once) its really a pain in the ass. I think people got in because of the PS3 password leak.
Why also were credit cards stored along side forum information?
This also explains the e-mails I got from 'Steam Forums' that looked hacker-ish.
Posted 10:21am 11/11/11
Posted 10:22am 11/11/11
This.
I don't remember what my steam forum pwd was, but I've never had anything of mine hacked/stolen before and I've been using a similar password for years.
Posted 10:22am 11/11/11
Posted 10:38am 11/11/11
Speaking of 2-factor authentication, Paypal also has 2-factor authentication (either through a security card/key that costs AU$32.95 to order or SMS). Are there any banks aside from HSBC that have 2-factor authentication?
Posted 10:45am 11/11/11
Posted 12:40pm 11/11/11
HSBC rsa token annoys me, means I cant login to internet banking at work :/
Posted 01:39pm 11/11/11
Posted 01:55pm 11/11/11
Posted 03:00pm 11/11/11
Posted 03:30pm 11/11/11
Posted 03:50pm 11/11/11
Posted 04:11pm 11/11/11
Posted 04:29pm 11/11/11
Posted 05:16pm 11/11/11
Edit: Is it just me or is there no way to do anything to your account if you don't have the Steam client installed...I can't find any way to change passwords or do anything to my account from the Steam site...
Posted 06:33pm 11/11/11
keepass & use a key instead of a password, store the key on a USB drive and hide it?
e: ignore the key on a usb thing, I thought you were worried about having to remember the master password, I must learn to read some day.
last edited by Whoop at 18:33:28 11/Nov/11
Posted 06:56pm 11/11/11
The company said hackers obtained access to a database that included user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information.
Posted 07:13pm 11/11/11
Does this affect people who don't save their CC details when purchasing through steam I wonder.