It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
It appears to be Steam got hacked lol
http://www.gameinformer.com/b/news/archive/2015/12/25/psa-steam-is-having-security-issues-extent-as-yet-unclear.aspx
Cache server got messed up under load due to an incorrect configuration or something and started sending cached pages that contained unique customer info. No hack.
Just gonna dropt this reddit link here. At this point it seems like this whole thing was caused but a misconfiguration on valves side. There is no indication of a hack so far.
To be on the safe side you should unlink your Paypal and/or credit card, change your password both on Steam, your mail connected to Steam and Paypal.
Jesus, for all the billions Steam rakes in, they're still as amateur as it gets.
TB got a video up about this

https://www.youtube.com/watch?v=x80VOkFwsL0
Who would want to hack steam? And for what purpose...?!?
https://www.reddit.com/r/Steam/comments/3ya734/lets_try_to_stop_some_of_this_misinformation/
https://www.youtube.com/watch?v=T9Et2U2kPmE
i expect a huge amount of spam and scam to come in my mail box now...
but i cant change my mailbox's password (old isp and discontinued service contract...)
avatar
Mr. D™: TB got a video up about this

https://www.youtube.com/watch?v=x80VOkFwsL0
For once he had something important to say.
I wish Simon were still around to update us on the legal stuff...

Does anyone know if the various information commissions such as the EU or the UK's ICO have jursidiction over this to impose fines? They've done it to many organisations that aren't incorporated in that country, but Valve are always slippery on obeying local laws.
avatar
Djaron: i expect a huge amount of spam and scam to come in my mail box now...
but i cant change my mailbox's password (old isp and discontinued service contract...)
Sheesh, change emails already, it's a matter of time till you're going to get serious issues if you don't have full control over it.


avatar
wpegg: I wish Simon were still around to update us on the legal stuff...

Does anyone know if the various information commissions such as the EU or the UK's ICO have jursidiction over this to impose fines? They've done it to many organisations that aren't incorporated in that country, but Valve are always slippery on obeying local laws.
I guess the question is if they can be held accountable for bugs. It's not like they intentionally/willfully allowed information to be leaked.

From the sound of it, they were supposed to have CC#'s and Phone#'s censored, which they are, on the account detail page, however due to the caching error people were able to see the autofill of people who had a CC linked (not the CC#), so they could see their billing info, which included the phone number.

So that one could be a problem for them, though only for people who had the CC linked.
Post edited December 26, 2015 by Pheace
when people become lazy and get mad when something bad happen.

interesting how log it took the steam error is mentioned here
avatar
Pheace: I guess the question is if they can be held accountable for bugs. It's not like they intentionally/willfully allowed information to be leaked.

From the sound of it, they were supposed to have CC#'s and Phone#'s censored, which they are, on the account detail page, however due to the caching error people were able to see the autofill of people who had a CC linked (not the CC#), so they could see their billing info, which included the phone number.

So that one could be a problem for them, though only for people who had the CC linked.
That they can be held responsible for bugs is without doubt. Many companies have been fined under such circumstances. It's considered the company's responsibility to not have the bugs.

I think the issue is jurisdiction.
Post edited December 26, 2015 by wpegg