Steam security issue revealed personal info to other users on XMas Day (fixed)

This was posted 30 minutes ago, haven't seen it here.

CXGnCgvWYAIQhvT.png:large


https://steamcommunity.com/discussions/forum/0/458604254431478327/

Is that an employee? It just says community moderator
 
Glad I never save my cc info on anything.

Same, I always re-type it in. It only takes 10 sec and you can at least feel semi-secure that it's not stored somewhere although it probably is anyway. I get why people who do lots of purchases on steam like cases would keep cc info there though. They shouldn't have to worry about this sort of thing.
 
It's unclear at this point, but ultimately with store credit it's no big deal because Valve could rollback the charges (obviously if they don't rollback charges associated with this, they're toast). The issue with credit cards, besides the information exposure, is that someone could get overdrafted or hurt if the payment actually posts before the rollback happens.

OK thanks. I've made purchases with PayPal and now unlinked via the PayPal account page.

It's just I had a fair amount of credit to buy a few games over the sale.

What a shitty situation. I really hope people are not affected in the way you mention.
 
It isn't that far fetched, but the problem is that when you're posting stuff second hand and you don't offer a source, no one has a chain of trust, and it creates panic. There's no doubt this is serious and if the payment thing is true then it's a big deal, but when you just breathlessly repeat stuff you see online you can contribute to miscommunication about what actually happened. My account is one of the ones that was affected by this, so you can understand that I'm nervous -- but it doesn't help me if I don't know what's going on. It's absolutely Valve's responsibility to communicate this to me, but in the mean time we should be vigilant about whose stories we choose to repost. This is much better because you have a source and you are being clear about it.

Stump were you actively using Steam when people were being logged into your account on Steam or were you just idling?
 
I've been keeping my gmail open hoping not to see a "Thank you for your Purchase" email. Guess I'm just the paranoid type.

Same, also does that email pop up if people use money in your wallet? presume it does. So far ive had nothing from my bank or email say moneys been taken so thats good atleast.
 
Canceled steam as pre approved on paypal site

Now we drink whisky and hope for the best
 
I haven't logged in to Steam in a couple days, and I haven't kept up with this at all. My wife saw it on Buzzfeed and told me.

Do I need to change my email password or anything like that?
 
Potentially compromise an account, versus citing the limited information we have so people are aware of what is going on?

I don't know man, you might have trouble backing your argument up.

Posting factual information thats personally relevant and unexpected behaviour in a strange and distressing situation, versus cherry-picking sources and claiming knowledge thats repeatedly being disputed many times by trusted users on this very site for the purpose of damage control rather than clear communication.

One is instinctive and reactionary, not meaning to compromise data.
The other is deliberate and knowingly promoting disputed claims as fact.

how about not doing both and quitting the slapfight until we actually know what's going on?
 
no charges so far and everything has gone down for me now. I only have my pay pal linked and there's been no charges so far. think thats 2-factored out that wazoo anyway
 
The guy posting that isn't working for valve, he's a reddit mod inbetween.

But yes, valve isn't doing themselves any favors by not saying anything about this directly.
Valve may not have anyone with access to the PR credentials. Engineers should be on call always, PR not necessarily. (Not forgiving Valve or giving them a pass, just trying to understand why)
 
I had gotten a new CC in June, after the summer sale. I didn't purchase anything else on steam until the winter sale started. I know for sure that I had my original CC info stored, but I can't remember if I told Steam to save the info for my current one when I used it the other day.

During last winter's sale my bank actually put a hold on my card because multiple Steam purchases within a few days was an unusual purchasing pattern and sent up red flags. I had to call my bank to authorize those purchases. The fact that my bank is on top of it and has those kinds of measures in place is comforting in case of the very unlikely chance that my account was one of the ones leaked.

My Steam e-mail is pretty much just my spam email and the phone number stored there is out of date. So it's not as bad as it could have been. But that's beside the point. The point is that some people's privacy has been violated and there is absolutely no excuse for it. Valve better try to compensate for this.

Also, it's worth mentioning that when I went to the profile of the guy whose account I was originally redirected to, his page was flooded with comments from people alerting him to the fact that he'd been compromised and trying to message him. The fact that so many people were trying to do the right thing in the face of something like this, instead of taking advantage of it, I think says volumes about the community.
 
Man I'm so happy that I had a bad steam experience where I vowed never to buy directly from steam again (lagged when putting money in my wallet and steam customer service never replied to me when I wanted to take the second deposit back out).

Screw you valve customer service.

Thank you valve customer service!

Good thing I always set my Status to offline

What's the benefit of this? It stops cache?
 
Wow, what a mess. The responsible thing to do would be to take Steam offline, so as to limit the blast radius. Lack of communication from Valve up until this point has been disappointing.
 
Top Bottom