Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Steam: Attackers Accessed Copy of Backup Files

In November 2011, the Steam gaming platform, in addition to user forums where gaming fans gather to discuss various gaming topics, said that intruders obtained access to its Steam database in addition to the defacing the forums.

In November 2011, the Steam gaming platform, in addition to user forums where gaming fans gather to discuss various gaming topics, said that intruders obtained access to its Steam database in addition to the defacing the forums. At the time, the company said the compromised database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information.

Steam Database HackedAfter the company continued its investigation into the incident, Steam has now come forward with more information, saying that intruders likely obtained a copy of a backup file containing information on Steam transactions that took place between 2004 and 2008. This backup file, the company says, contained user names, email addresses, encrypted billing addresses and encrypted credit card information. The file did not include Steam passwords, they said.

“We do not have any evidence that the encrypted credit card numbers or billing addresses have been compromised. However as I said in November it’s a good idea to watch your credit card activity and statements. And of course keeping Steam Guard on is a good idea as well,” noted Gabe Newell, Founder of Steam parent Valve Corporation, in a blog post.

“We are still investigating and working with law enforcement authorities. Some state laws require a more formal notice of this incident so some of you will get that notice, but we wanted to update everyone with this new information now,” Newell added.

Steam is a gaming platform where gamers can buy and download games and play them from any computer. The Steam service is also backed by a large gaming community on the forums, and many of them use the service to chat as they play. The services support millions of users.

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Cloud Security

VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.