Steam security issue revealed personal info to other users on XMas Day (fixed)

I believe the payment information page does show the full address and unobscured phone number if that information is saved on the account. I think it'll only show the last 4 digits of the card number and the CCV field will be empty because that needs to be entered for every purchase.
 
Does everyone on steam need to fill in their 3 number safety code for CC purchases?

no, if you have a CC saved you can just buy it without doing anything else than clicking a button. but it would go on your account anyway, its not like people would be stealing it

dick move, sure, but it would be fixable
 
I believe the payment information page does show the full address and unobscured phone number if that information is saved on the account. I think it'll only show the last 4 digits of the card number and the CCV field will be empty because that needs to be entered for every purchase.

If you have steam wallet balance though, they can use that right? As that doesn't require any code inputs, just a tickbox.
 
So is Steam down now? I wasn't charged for anything, unlinked my PayPal account through PayPal, and changed my PayPal password. I just want to play my games in offline mode.

You did all the right things if it is true that the issue is due to caching issues.
 
It seems like you overreacted, but I guess it's good that this one potentially negative experience helps you rationalize your overreaction.

It didn't stop me from getting the games I wanted. Amazon, and GOG sell steam codes. I've never really wanted a steam only purchase after that game so I was unaffected by avoiding steam (Divinity OS). Street Fighter V will be the next thing I'll need steam for maybe. Amazon sell steam money codes. <3 amazon's customer service, and EA's too.
 
At least in the second part you should be safe, but is possible that people got your personal data: adress, phone, mail, account name.

So you should keep vigilant, regarding at least accounts who might use the same mail, for example.

Thanks, what a massive disaster... I'm afraid of login in to remove these information.
 
Just so I'm clear on this, if it's true some people got purchases made, it had to have been through Steam itself, right? Now that they pulled the plug, if I haven't had anything purchased on my account, then other than the last 4 digits of my cc being potentially exposed, I'm no longer at risk?
 
I saw that some people were able to enter game/software licences on the same account details page with remove next to some games.

Can some licences be actually removed?

As far as we know, it's just a caching error so no account changes can be made.

There have been some varying reports however, currently we are discussing the validity of charges being applied to people's accounts.

People were able to see the full phone numbers and addresses.

I didn't see any either, maybe someone browsing caches or /v can confirm.

LdhpdaZ.png


However, that information came from a community moderator.
 
Hopefully I'm good. I haven't bought anything in over a year, which means it's my old CC on there. It'd get denied real quick.

Best of luck to anyone who this is affecting.
 
i think it`s scary that google can cache the Steam account page with all our informations... !!!
Google probably has a info page detailing everything that must be done by companies to keep this from happening, so it's not really their fault in this case, it's still Valve's.
 
How can I unlink a paypal account?

1. click the cog wheel in the upper right corner when logged in.
2. scroll down and look for a link like button with preapproved payments then click.
3. under the dropdown menu click on active and then click go.
4. click the one from steam and cancel it.

This is why I quoted that Steam forum member.
 
Go to paypal, sign in, press the gear icon in the top-right corner, scroll to pre-approved payments, click, click on Valve Corp, click cancel

Thanks, I'll do that right now. I might unlink my Paypal account from my bank/cards because I don't use them anyway.

What an absolute fucking shitshow.
 
no, if you have a CC saved you can just buy it without doing anything else than clicking a button. but it would go on your account anyway, its not like people would be stealing it

dick move, sure, but it would be fixable

I'm asking this because EU citizens (or at least I) have to fill in the 3 number code every time.
So that should mean that CC purchases aren't even a problem here.


PS.So what do we "Corp. apologists" get when half of the fear mongering here is false?
 
I removed the PayPayl thing from the website but I'm not sure if I ever used my credit card directly.. don't want to log in now to check

Steam was open when this thread was made and I saw the profile page of another user
 
I wish that third parties weren't doing Valve's job, but it's still appreciated.
 
As far as we know, it's just a caching error so no account changes can be made.

There have been some varying reports however, currently we are discussing the validity of charges being applied to people's accounts.



I didn't see any either, maybe someone browsing caches or /v can confirm.

LdhpdaZ.png


However, that information came from a community moderator.
A bit coincidental for just a caching error to happen on Christmas day when it's been OK all year round.
 
As far as we know, it's just a caching error so no account changes can be made.

There have been some varying reports however, currently we are discussing the validity of charges being applied to people's accounts.



I didn't see any either, maybe someone browsing caches or /v can confirm.

LdhpdaZ.png


However, that information came from a community moderator.

A guy from IGN is even saying he has had charges to his account. Perhaps he is mistaken, but I'm doubting it.
 
I don't know about you guys but I'm thoroughly entertained for the evening. May be because I never saved Credit Card Info on Steam. I also hope that worse that happens here is some spam emails.
 
Does everyone on steam need to fill in their 3 number safety code for CC purchases?

Yes. Which makes me think the people posting charges to their steam account were just charged late for something they bought earlier. I've had steam charges take a couple of days to hit. Still, all the other shit leaked is a social engineering nightmare.
 
Top Bottom