Steam security issue revealed personal info to other users on XMas Day (fixed)

Some stupid posts on the last 2 pages - some people just wanna see the world burn.

How can you unlink Steam from your PP account via the PP Site ? Cant see that option.
 
how does a company like steam have ZERO social media presence for stuff like this? This is extremely laziness or hubris.

Historically, Valve hasn't exactly been a chatty company, but it is possible they are waiting for all of the information and a solution before posting.

Would be nice to see a standard, 'we are aware of the issue and working on a solution,' post.

most of my friend's list is still playing games as usual

nothing-stops-this-train.gif

I just want to buy Sunless Sea and Downwell and check out some legitimate GOTY candidates.
 
So fortunate it doesn't have my existing credit card on the acount. So fortunate.

I hope for all those affected that their credit cards cover everything smoothly and Valve issues a prompt apology and what not.
 
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

Next time, please use a little discretion and source your image. Preferably with a link.
 
So it would probably be good to clarify if you're posting a meme image, if so from where, whether there's any reason to believe this is real or if it's just an edited screenshot, etc.

I agree.

I'm sure there are people out there photoshopping images right now just to create panic.
 
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.
How could they access cc info? I mean, you could only see the last digits.
 
As one of the accounts affected by this (shout-outs to the nice random people on Steam contacting me to chat because they were in my account and looking at my stuff--all seemed like standup, trustworthy guys), the basic information I want to know:

1) Was this a breach, a staff error, or a configuration error that happened due to some unusual hardware cascade situation?
2) How many users were affected?
3) How many people accessed my information?
4) What information did they access?
5) If my address or cc info was even partially exposed, I expect a year or two of credit monitoring
6) If a breach, was my tax information accessed
7) Will I be permitted to change my login username in light of this?

It goes without saying that if purchasing was exposed they should do a full rollback, but I'm not worried about that because that's obvious. More worried about the personal info.

1) You saw the pages people recently visited on their account. So a server problem.
2) Everyone browsing Steam during the problematic period.
3) Depends on which pages you visited, if you didn't enter account info then no one has.
4) See 3
5) Dunno
6) Dunno
7) Probably not

This should be correct.
 
I mean this could easily be shopped...

Or someone is using the sandbox feature that literally allows you to create accounts and push through fake transactions for the sake of testing your PayPal integration in your app/website etc.

Last time I checked all Steam PayPal purchases are titled WWW.Steampowered.com and not STEAMPOWERED.COM

//EDIT: That screen literally says "Sale" and the amount is positive instead of negative.
 
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

It's not spreading panic, it's a realistic scenario. The image could be fake for all we know, but I'm looking at people's CC info on 4chan right now.

Not surprised by that. FFS valve.
 
My thinking exactly.

I know it's easy to jump to conclusions on these matters, but we need confirmation.

Wasn't there a limit on how much you can buy at once? Or at least a Steam Wallet limit (I might have mixed that up if there's one). I vaguely remember hearing something like that.
 
Can someone knowledgeable explain to me how can something like this happen? There's no security fail safe regarding cached data? I find it pretty weird they didn't think this could happen.
 
I guess Steam Guard is working correctly. Was unaware of this Steam fuck up and when I tried logging into my account, I got email from Valve saying there was a login attempt from me (IP address on email is identical to my pc's IP address).

So, I should be ok?

There were some here saying they were viewing details of steamguarded accounts during the breach....so who knows at this point.

Until we get an official statement from valve on what was compromised etc we are all just guessing
 
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

It's not spreading panic, it's a realistic scenario. The image could be fake for all we know, but I'm looking at people's CC info on 4chan right now.

...and people were posting account names in this thread.

Some stupid posts on the last 2 pages - some people just wanna see the world burn.

How can you unlink Steam from your PP account via the PP Site ? Cant see that option.

Then you are fine.
 
So, what excuses explanations do we think Valve will give for how this totally isn't their fault and they therefore owe nothing to those who've had their private information given to random people?
 
I don't give a shit about free games. I care what Valve is going to make to allow me to protect my info if any got out, which is very likely.
 
i dunno about you guys but i can only think of 1 thing that could adequately compensate me for this gross violation of privacy, it begins with a h and ends with a 3. i think you know what im talking about dont you.
 
Next time, please use a little discretion.

Other GAF users were reporting that they were getting steam wallet charged. It's not an unrealistic scenario.

How could they access cc info? I mean, you could only see the last digits.

I have no idea, all I'm seeing is info being posted. Name/Visa/Address/etc. I have an image of a post, of course we don't know how authentic this is.

I will repeat I said it wasn't me and I found people reporting it on /r/Steam. People on GAF have confirmed things can be purchased, whether it is exaggerated or not, or real or not, it's a real scenario even if the image was shopped (and for our sakes I hope it was shopped).
 
Once they have Steam properly working again, I'm removing my CC info and making a dedicated email for Steam only. Fuck this.
Turn on mobile authentication for Steam and/or email so that any prospective hacker has to physically track you down to get into your account
 
Top Bottom