Friday, February 10th 2012
Valve Asks Users to Keep An Eye On Their Credit Card Usage
In November 2011, Valve admitted that its Steam forums were hacked, and some user data including encrypted credit card information and hashed passwords were stolen, and that pending investigation, it asked users to change their Steam passwords. Valve noted that at that time, it had not seen any evidence of encrypted data being hacked. Today, Valve issued an update to all its Steam members via e-mail, where it notified them that investigation is still in progress, that Valve is taking help of external agencies to investigate, and that it still sees no evidence of encrypted credit card data being tampered with. As a note of caution, though, it asked users to keep an eye on their credit card activity and statements.
The transcript of Valve's email to Steam users follows.
The transcript of Valve's email to Steam users follows.
Dear Steam Users and Steam Forum Users
We continue our investigation of last year's intrusion with the help of outside security experts. In my last note about this, I described how intruders had accessed our Steam database but we found no evidence that the intruders took information from that database. That is still the case.
Recently we learned that it is probable that the intruders obtained a copy of a backup file with information about Steam transactions between 2004 and 2008. This backup file contained user names, email addresses, encrypted billing addresses and encrypted credit card information. It did not include Steam passwords.
We do not have any evidence that the encrypted credit card numbers or billing addresses have been compromised. However as I said in November it's a good idea to watch your credit card activity and statements. And of course keeping Steam Guard on is a good idea as well.
We are still investigating and working with law enforcement authorities. Some state laws require a more formal notice of this incident so some of you will get that notice, but we wanted to update everyone with this new information now.
Gabe
28 Comments on Valve Asks Users to Keep An Eye On Their Credit Card Usage
The only kind of purchase that won't overdraw your account is if it's swiped physically. Making purchases online and EFT's will still overdraw your account. How do I know? I accidentally overdrew my account with an online purchase even though I used my debit card. They refunded me the charge because of a misunderstanding, but the new regulation clearly states it only prevents overdraws from an actual swipe of the card.
Edit: Also, as far as I know this is a standard regulation set down by the government. It's part of the opt-in/opt-out overdraw legislature.
PayPal is a PITA and many will flame the hell out someone using their services, however none of your credit card/debit card information is forwarded to online retailers.
I don't use CC or paypal for STEAM, so I don't care, nothing to be lost. But checking billing statements is always a good idea.
I get charged by the utility company for bloody rainfall, in land drainage charges, for example. Talking to my neighbours, very few even knew that was a charge.
Now you going have people putting plastic sheets over there houses and yard when it rains loool.
O yeah no email here either. Which if true they only sent them to who might of been had id stolen would mean there not telling the whole truth.
american server but australian customer - why send me an email?