Something went wrong. Try again later

Giant Bomb News

156 Comments

Valve Admits Steam Intrusion, No Current Evidence of Fraud

Just to be safe, you might want to change your password.

Steam's message boards were compromised Sunday, and it's been investigating since.
Steam's message boards were compromised Sunday, and it's been investigating since.

It’s one thing when a message board gets compromised, it’s quite another when it’s one of the most popular services amongst PC users.

An unidentified user or group of users gained access to the Steam message boards on Sunday, and subsequently “obtained access to a Steam database in addition to the forums,” the company said today.

The statement, signed by founder Gabe Newell, claims the company has found no evidence of credit card fraud, but recommends users to monitor their financial accounts closely. Even if you didn’t have an account on the Steam message boards, Valve recommends changing your password.

“I am truly sorry this happened, and I apologize for the inconvenience,” said Newell.”

Users accessed “a Steam database in addition to the forums” that had user names, hashed and salted passwords, game purchases, email addresses, billing addresses, and encrypted credit card information.There is currently no evidence the credit card information has been decrypted, and Valve is “still investigating.”

Only a few message board accounts were reportedly compromised, and they “do not know of any compromised Steam accounts” at this time.

Basically, change your password. If Valve issues further updates, I’ll let you know.

Patrick Klepek on Google+

156 Comments

Avatar image for deactivated-5e60061752a57
deactivated-5e60061752a57

752

Forum Posts

96

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Good call in blowing the horn on this before everyone dove into Skyrim.

Avatar image for w00ties
w00ties

191

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By w00ties

@BisonHero said:

@Ares42 said:

Hmm, went to change password and got "Steam cannot process your request" error repeatedly =/

I believe it gives you that error even if their servers are fine, but you're typing in your password incorrectly.

Yes. I typed in the wrong password a few times and got "Steam cannot process your request" and was told to try again later. I realized that I was trying an extremely old (and unused) password, but once I realized what my current password was it let me in immediately.

Avatar image for platzkart
platzkart

210

Forum Posts

488

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By platzkart

Oh man some fuckers are getting introduced to Gabe's knife collection tonight.

Avatar image for coakroach
coakroach

2499

Forum Posts

27

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By coakroach

What kind of dick attacks Steam?

Avatar image for fistfulofmetal
fistfulofmetal

763

Forum Posts

2

Wiki Points

0

Followers

Reviews: 2

User Lists: 29

Edited By fistfulofmetal

I cant figure out how to change my password...

Avatar image for ben_h
Ben_H

4833

Forum Posts

1628

Wiki Points

0

Followers

Reviews: 1

User Lists: 5

Edited By Ben_H

I use Paypal for Steam purchases, but I changed my password anyway just to be safe. I have 155 games and I don't want to risk it. I have never used the Steam forum anyway.

Avatar image for endrzgame
EndrzGame

325

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By EndrzGame
Avatar image for dezinus
Dezinus

745

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 15

Edited By Dezinus

I admit, my steam password was pretty weak anyway. About time I changed that.

Avatar image for ravenlight
Ravenlight

8057

Forum Posts

12306

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Ravenlight

@Brian333 said:

!@#@U#!@#*!#%*!#@(@#!*(&*@*@@10_**&^%@!&!

That seems like a pretty secure password

Avatar image for monkeyman04
Monkeyman04

2885

Forum Posts

10

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

Edited By Monkeyman04

@Fistfulofmetal: you go into the steam client and then go to steam settings and on the first tab there is a button to change password. I'm sure there is another way, but that's the way i changed mine.

Avatar image for fistfulofmetal
fistfulofmetal

763

Forum Posts

2

Wiki Points

0

Followers

Reviews: 2

User Lists: 29

Edited By fistfulofmetal

@Monkeyman04:

ah... i was trying to do it on the steam website. thanks

Avatar image for deactivated-5e49e9175da37
deactivated-5e49e9175da37

10812

Forum Posts

782

Wiki Points

0

Followers

Reviews: 0

User Lists: 14

If it was any other company people would be losing their shit.
 
Valve (and Steam more accurately) has won complete infallibility not by making great games, and not by creating a good platform for games... but because they sold people a bunch of good games for like 2 fucking dollars.  THAT'S the real reason people have a Steam boner.

Avatar image for krenor
Krenor

473

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Krenor

@Enigma777 said:

Hey guys, remember when Sony got hacked and people were saying this would never happen to a "proper" service like Steam?

Yeah and it hasn't happened yet, remember unlike Steam, Sony did not encrypt any of the passwords.

Avatar image for mikkaq
MikkaQ

10296

Forum Posts

52

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By MikkaQ

It's not even letting me change my password and says the service is unavailable. Way to give me a near-heart-attack and then sustain the tension. I can't deal with this shit, I already went through the PS3 debacle.

Avatar image for platzkart
platzkart

210

Forum Posts

488

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By platzkart

@Brodehouse said:

If it was any other company people would be losing their shit. Valve (and Steam more accurately) has won complete infallibility not by making great games, and not by creating a good platform for games... but because they sold people a bunch of good games for like 2 fucking dollars. THAT'S the real reason people have a Steam boner.

Oh cool dude thanks for letting me know why I have the opinions I have.

Because I have been fucking mystified up to now.

Avatar image for clonedzero
Clonedzero

4206

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Clonedzero

changed my password. made sure credit card info wasn't saved. made sure steam guard is on.

well thats all i can do really. hopefully its not too bad for people, myself included.

Avatar image for brackynews
Brackynews

4385

Forum Posts

27681

Wiki Points

0

Followers

Reviews: 5

User Lists: 48

Edited By Brackynews

@coakroach said:

What kind of dick attacks Steam?

The kind that wants active and recent account information of four million users that like to buy things.

So, professional dicks. :(

Avatar image for rekt_hed
Rekt_Hed

958

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 8

Edited By Rekt_Hed
@Vitor said:

http://www.eurogamer.net/articles/2011-11-10-valve-confirms-steam-security-breach

According to Eurogamer, they stole a lot more than just forum stuff.

Possible Credit Card info leaked amongst other things.

Thank god Ive never saved my credit card info on steam.  Been so tempted a number of times to save some hassle but after my PS3 incident at least this hack means I wont have to get a new credit card again.
 
Hackers ffs Valve has got to be the one games company out of all of them that doesnt deserve to be hacked the most.
 
If this is still for the lulz then im pretty sure youve failed cause its just not funny.
Avatar image for penguindust
penguindust

13129

Forum Posts

22

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By penguindust

They sent an email with a security code when I tried to log in. I changed mine, too. I don't want a repeat of the trouble I had from my Microsoft account getting hacked.

Avatar image for fram
fram

2132

Forum Posts

5

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By fram

I'm at work at the moment, so I don't have access to the Steam client. I can't seem to find a way to change my password through the browser. I can log in, delete my saved credit card info, but no password change option?

Anyone have any ideas?

Avatar image for tourgen
tourgen

4568

Forum Posts

645

Wiki Points

0

Followers

Reviews: 4

User Lists: 11

Edited By tourgen

great. time to start checking my CC account online daily because yet another CC processor can't keep their systems secure.

Avatar image for white
white

1697

Forum Posts

47

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By white

If only I can change my credit card number with a form like my password.

Avatar image for enigma777
Enigma777

6285

Forum Posts

696

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By Enigma777

@Krenor said:

@Enigma777 said:

Hey guys, remember when Sony got hacked and people were saying this would never happen to a "proper" service like Steam?

Yeah and it hasn't happened yet, remember unlike Steam, Sony did not encrypt any of the passwords.

Somehow I doubt that's going to stop the hackers.

Avatar image for jmfinamore
jmfinamore

1092

Forum Posts

16

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By jmfinamore

@Brodehouse said:

If it was any other company people would be losing their shit. Valve (and Steam more accurately) has won complete infallibility not by making great games, and not by creating a good platform for games... but because they sold people a bunch of good games for like 2 fucking dollars. THAT'S the real reason people have a Steam boner.

This is kinda true, the first part anyway. Let's be honest, if this happened to Origin, people would be going nuts.

Avatar image for nights
nights

676

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By nights

Sweet, it says my password can't be changed.

Avatar image for n7
N7

4159

Forum Posts

23

Wiki Points

0

Followers

Reviews: 4

User Lists: 2

Edited By N7
@HarlequinRiot said:

@Brodehouse said:

If it was any other company people would be losing their shit. Valve (and Steam more accurately) has won complete infallibility not by making great games, and not by creating a good platform for games... but because they sold people a bunch of good games for like 2 fucking dollars. THAT'S the real reason people have a Steam boner.

This is kinda true, the first part anyway. Let's be honest, if this happened to Origin, people would be going nuts.

People don't really even need a reason to hate Origin at this point. It's like the step-child among programs. Because it exists, people hate it.
Avatar image for vitor
vitor

3088

Forum Posts

51

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By vitor

@EndrzGame said:

@Vitor said:

http://www.eurogamer.net/articles/2011-11-10-valve-confirms-steam-security-breach

According to Eurogamer, they stole a lot more than just forum stuff.

Possible Credit Card info leaked amongst other things.

What Eurogamer is reporting is the same that GB and all the other web sites are reporting.

Point me to the section in the GB article where it comments on the unofficial internal memo Gabe sent round Valve suggesting that credit card information was also accessed.

Avatar image for gs_dan
GS_Dan

1438

Forum Posts

68

Wiki Points

0

Followers

Reviews: 15

User Lists: 1

Edited By GS_Dan

But the hackers are standing up for consumer liberty, right guys?

...guys?

Avatar image for 2headedninja
2HeadedNinja

2357

Forum Posts

85

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By 2HeadedNinja

@Brodehouse said:

If it was any other company people would be losing their shit. Valve (and Steam more accurately) has won complete infallibility not by making great games, and not by creating a good platform for games... but because they sold people a bunch of good games for like 2 fucking dollars. THAT'S the real reason people have a Steam boner.

People don't like steam because of 2 dollar games but because steam offers great customer service. Discounts are just a part of that.

Avatar image for korwin
korwin

3919

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By korwin

@coakroach said:

What kind of dick attacks Steam?

Organized Crime. The contents of that database is worth a lot of money.

Avatar image for lego_my_eggo
lego_my_eggo

1532

Forum Posts

259

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By lego_my_eggo

@Krenor said:

@Enigma777 said:

Hey guys, remember when Sony got hacked and people were saying this would never happen to a "proper" service like Steam?

Yeah and it hasn't happened yet, remember unlike Steam, Sony did not encrypt any of the passwords.

Based on what Patrick posted they have a similar setup to what Sony had, encrypted credit card info and hashed passwords. Either way im sure our steam accounts are safe.

Avatar image for swick
Swick

266

Forum Posts

699

Wiki Points

0

Followers

Reviews: 2

User Lists: 6

Edited By Swick

This alarmist sentimant on most of these headlines is a bit misleading. Most are saying something like, Security Breach -- Password and Credit Card Information Stolen. While that's technically true, it's still encrypted information, which is usually explained in the body of the article.

I appreciate that Giantbomb stated the facts up front. Well done once again.

Avatar image for endrzgame
EndrzGame

325

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By EndrzGame

@Vitor said:

@EndrzGame said:

@Vitor said:

http://www.eurogamer.net/articles/2011-11-10-valve-confirms-steam-security-breach

According to Eurogamer, they stole a lot more than just forum stuff.

Possible Credit Card info leaked amongst other things.

What Eurogamer is reporting is the same that GB and all the other web sites are reporting.

Point me to the section in the GB article where it comments on the unofficial internal memo Gabe sent round Valve suggesting that credit card information was also accessed.

"Users accessed “a Steam database in addition to the forums” that had user names, hashed and salted passwords, game purchases, email addresses, billing addresses, and encrypted credit card information.There is currently no evidence the credit card information has been decrypted, and Valve is “still investigating.”

It's in that tricky 5th paragraph. It wasn't an 'unofficial internal memo'. That's verbatim word for word the message you receive as soon as you log into Steam or try to access the forums.

Avatar image for deactivated-589cf9e3c287e
deactivated-589cf9e3c287e

1984

Forum Posts

887

Wiki Points

0

Followers

Reviews: 16

User Lists: 4

@Swick:Whatever, someone spent $92.50 of my money on Red Kings poker. I personally would love to thank Giant Bomb for telling me this. Otherwise, what else could've been stolen?

Avatar image for whatthegeek
whatthegeek

79

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By whatthegeek

A couple months back, there was a chargeback on my steam account due to an error on Paypal's part. When attempting to get the issue resolved with Steam support, I received conflicting advice from different reps, and at least one of them felt completely comfortable talking down to me as though I were a thief, despite the hundreds of dollars worth of transactions that went of without a hitch. My account was suspended.... twice, despite the fact that I did everything they asked of me.

Personally, I'm going to treat them with the same dignity and respect they treated me with when I had an issue that wasn't directly my fault. Hey Valve, get it fixed. There's no excuse for this - even though it's not your fault, you certainly deserve to be raked over the coals for it. Sure, it's not like you hacked your own service, but come on - you were asking for it, and this is clearly your fault. I expect you to take measures to protect my credit card information, and my identity. If you don't, I'll stop spending money with you. Even if you do, I still might stop doing business with you on a whim.

Alright, in case it was lost on anyone, that was (mostly) sarcasm. /Still, a company that demands their customers follow every rule to the letter without any allowance for exceptions, and special circumstances should expect nothing other than ire when something like this happens to them.

Avatar image for ley_lines
Ley_Lines

313

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Ley_Lines

I used paypal, so I should be fine, right?

Avatar image for video_game_king
Video_Game_King

36563

Forum Posts

59080

Wiki Points

0

Followers

Reviews: 54

User Lists: 14

Edited By Video_Game_King

Well, it seems that not buying anything on Steam has finally paid off. Now if only I could get my Steam library under control.

Avatar image for bisonhero
BisonHero

12793

Forum Posts

625

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By BisonHero

@w00ties said:

@BisonHero said:

@Ares42 said:

Hmm, went to change password and got "Steam cannot process your request" error repeatedly =/

I believe it gives you that error even if their servers are fine, but you're typing in your password incorrectly.

Yes. I typed in the wrong password a few times and got "Steam cannot process your request" and was told to try again later. I realized that I was trying an extremely old (and unused) password, but once I realized what my current password was it let me in immediately.

Yeah, I also did exactly what you just described. It's a very misleading error message.

Avatar image for tebbit
tebbit

4659

Forum Posts

861

Wiki Points

0

Followers

Reviews: 3

User Lists: 6

Edited By tebbit
@Parsnip
Well, at least it's hashed and encrypted, unlike PSN was.
But PSN was hashed and encrypted.
Avatar image for swick
Swick

266

Forum Posts

699

Wiki Points

0

Followers

Reviews: 2

User Lists: 6

Edited By Swick

@c0l0nelp0c0rn1: I'm sorry to hear that. What else could have been stolen? Well, lots. But whether anybody cares is a different story. My comment was intended to highlight that Giantbomb stuck to the complete truth rather than going for a bigger headline.

Avatar image for subjugation
Subjugation

4993

Forum Posts

963

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Subjugation
hashed and salted passwords

That made me hungry.

Avatar image for dustpan
Dustpan

1781

Forum Posts

32518

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By Dustpan

Changed my password right after this happened.

Avatar image for stubee
Stubee

411

Forum Posts

102

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Stubee
@Shmio yep, and Half Life episode 3
Avatar image for koobz
koobz

431

Forum Posts

3093

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By koobz

@Subjugation said:

hashed and salted passwords

That made me hungry.

Me too :'(

Avatar image for mordeaniischaos
MordeaniisChaos

5904

Forum Posts

-1

Wiki Points

0

Followers

Reviews: 5

User Lists: 5

Edited By MordeaniisChaos

@Ares42 said:

Hmm, went to change password and got "Steam cannot process your request" error repeatedly =/

You can thank Bethesda for that one.

Avatar image for ahmadmetallic
AhmadMetallic

19300

Forum Posts

-1

Wiki Points

0

Followers

Reviews: 1

User Lists: 11

Edited By AhmadMetallic
@GS_Dan said:

But the hackers are standing up for consumer liberty, right guys?

...guys?

'fcourse
Avatar image for vhold
vhold

577

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By vhold

Password changed. Just do it.

Avatar image for themasterds
TheMasterDS

3018

Forum Posts

7716

Wiki Points

0

Followers

Reviews: 1

User Lists: 31

Edited By TheMasterDS

Sounds like it's not likely my password was in there, I'm not gonna bother changing it. What's the worst that can happen?

Avatar image for zithe
Zithe

1060

Forum Posts

2761

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Zithe

How about companies stop storing my fucking credit card information? I always go in and remove it when I am able to (can't figure out how on Steam). My security is way more important to me than my ability to buy something in one or two clicks. It shouldn't even be legal for them to remember that shit.

Edit: Well I figured out how to remove my card but I guess it's too bad I didn't find this before.