Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

7 Million Impacted by Lifeboat Minecraft Community Breach

The accounts of more than 7 million members of the Minecraft community “Lifeboat” have been exposed after a data breach in early 2016.

The accounts of more than 7 million members of the Minecraft community “Lifeboat” have been exposed after a data breach in early 2016.

On Tuesday, security researcher Troy Hunt revealed on Twitter that the millions of accounts were exposed in January, and that he was uploading the data on his website, so that users could check to see if they were exposedin the breach. As usual, the data on his website comes from website breaches which have been made publicly available.

According to another tweet from the researcher, the data leak included email addresses and weakly hashed passwords, meaning that the attackers could decrypt them rather easily. This also means that users who might have been reusing the same password for other accounts could risk further compromise.

The Lifeboat community hosts custom, multiplayer environments of the mobile version of Minecraft, allowing users to engage into new game mods. The Lifeboat systems only keep usernames, hashed passwords and email addresses, which means that no other user data could have leaked following the breach.

What’s interesting, however, is that Lifeboat appears to have not informed users on the breach, and that it didn’t even publicly prompt any password resets. However, Lifeboat reportedly confirmed that it has been aware of the issue since January, while also suggesting that it has quietly prompted password resets to ensure hackers aren’t aware of that.

Moreover, a Lifeboat representative said that they haven’t received reports that people were damaged by the data breach. However, security researchers suggest that the data might be searchable online, meaning that at least accounts with weak passwords might be at risk.

Advertisement. Scroll to continue reading.

Grayson Milbourne, the senior intelligence director at Webroot, told SecurityWeek in an email that the attack shows once again why people should use different passwords for different accounts. He also mentions the fact that Lifeboat themselves tell users to go for short passwords, albeit difficult to guess ones.

“More than likely this was an attack on LifeBoat’s servers which provided access to users’ account information. Lifeboat’s setup guide for Minecraft states the following when selecting a password – ‘we recommend short, but difficult to guess passwords. This is not online banking’,” Milbourne told SecurityWeek.

“Since Lifeboat only keeps usernames, hashed password and email addresses, the amount of data collected is rather limited. Passwords where hashed, but with an easily crackable MD5 hash. This is yet another example of why it is important to use different passwords for different sites. Failing to do so can lead to further account compromise when one is breached. If unique passwords are too much effort, I recommend making sure your primary email uses a unique password from all other online accounts,” he added.

We have contacted Hydreon Corporation (Lifeboat Network is a registered trademark of Hydreon) for a comment on the breach and we will update the article as soon as a reply arrives.

Related: American Express Warns Cardholders of Data Breach

Related: Data Breach at UC Berkeley Impacts 80,000

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

David Cass has joined Grayscale Investments as Chief Risk Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.