Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Steam: Attackers Accessed Copy of Backup Files

In November 2011, the Steam gaming platform, in addition to user forums where gaming fans gather to discuss various gaming topics, said that intruders obtained access to its Steam database in addition to the defacing the forums.

In November 2011, the Steam gaming platform, in addition to user forums where gaming fans gather to discuss various gaming topics, said that intruders obtained access to its Steam database in addition to the defacing the forums. At the time, the company said the compromised database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information.

Steam Database HackedAfter the company continued its investigation into the incident, Steam has now come forward with more information, saying that intruders likely obtained a copy of a backup file containing information on Steam transactions that took place between 2004 and 2008. This backup file, the company says, contained user names, email addresses, encrypted billing addresses and encrypted credit card information. The file did not include Steam passwords, they said.

“We do not have any evidence that the encrypted credit card numbers or billing addresses have been compromised. However as I said in November it’s a good idea to watch your credit card activity and statements. And of course keeping Steam Guard on is a good idea as well,” noted Gabe Newell, Founder of Steam parent Valve Corporation, in a blog post.

“We are still investigating and working with law enforcement authorities. Some state laws require a more formal notice of this incident so some of you will get that notice, but we wanted to update everyone with this new information now,” Newell added.

Steam is a gaming platform where gamers can buy and download games and play them from any computer. The Steam service is also backed by a large gaming community on the forums, and many of them use the service to chat as they play. The services support millions of users.

Written By

For more than 10 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Artificial Intelligence

Two new surveys stress the need for automation and AI – but one survey raises the additional specter of the growing use of bring...

Application Security

Password management firm LastPass says the hackers behind an August data breach stole a massive stash of customer data, including password vault data that...