Encrypted data possibly stolen in Valve hack

Powered by SC Magazine
 

Hacked database contained 35 million user records.

Hackers likely stole encrypted credit card data and data in an attack on gaming company Valve last November.

Attackers were originally thought to have only defaced the company's website forum but Techworld revealed hackers accessed its user database that contained details of some 35 million people including user names, billing addresses, details of game purchases and email addresses.

Valve managing director Gabe Newell said in a message to the forum community there was no evidence that encrypted credit card numbers or personally identifying information was taken.

“We are still investigating,” he said. “I am truly sorry this happened, and I apologise for the inconvenience,” Newell said.

But in an email to Steam users, Newell said it was "probable" that attackers "obtained a copy of a backup file with information about Steam transactions between 2004 and 2008”.

He said the possibility that sensitive transaction data was decrypted should not be excluded.

“The good news is that the credit card details were properly protected as required by PCI, but that's probably not good enough for rebuilding the reputation of the Steam service," SafeNet UK sales director Aydin Ucbasaran said.

He said cryptographic digital keys should be stored in an isolated  hardware-based repository.

“This will not only remove the likelihood of hackers stealing the digital keys, but will also ensure the organisation maintains full control of encrypted data even if it falls into the hands of cyber criminals.”

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


Encrypted data possibly stolen in Valve hack
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3111

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 993

Vote