PDA

View Full Version : MASSIVE Steam Christmas security breach! [User info possibly comprimised]


Scarlett.
25-12-2015, 09:52 PM
http://i.kinja-img.com/gawker-media/image/upload/s--4-xUeZBJ--/lbgbbpzoxqx3ap060smg.png

Steam faced something of a catastrophe this afternoon, giving players across the world access to the personal information in other people’s accounts. It’s not yet clear how this happened, but it’s a doozy. Call it the Steam Winter Fail.

Various players across the world logged into their Steam clients today to find that their homepage displaying Russian or another random language. When they checked the “account info” section of Steam, the digital store showed them another user’s account, complete with e-mail addresses, buying history, and other private information. Merry Christmas!

UPDATE (4:30pm): Valve has shut down the Steam store, presumably until they fix this problem.

Original article follows:

Going to Steam’s website would also grant you access to a random user’s account. Based on some rudimentary testing I did this afternoon on my own Steam client, it seemed like trying to view purchase histories and licenses would give you access to other random accounts as well.

http://i.kinja-img.com/gawker-media/image/upload/s--jh6IaNcQ--/c_scale,fl_progressive,q_80,w_800/ztmaxmbv0hztbpabuisp.png

The account that my client accessed was using Steam Guard, the tool Valve provides to help prevent unauthorized account access. So clearly that hasn’t helped.

We’ve reached out to Valve for more information and will keep updating you guys as we learn more.

Kotaku