Security Alert: Cryptic Informs Users of Database Theft from 2010

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Shawn Zipay
    Managing Communities 24/7
    • Apr 2003
    • 69279

    #1

    Security Alert: Cryptic Informs Users of Database Theft from 2010

    Great, just great. Apparently, another company had their database accessed, only this one happened back on December 2010 and is only now being discovered and publicly known. Yes, the user databases of Cryptic Studios was accessed in 2010 and if you have ever played any of their games in the past two years (City of Heroes, City of Villains, Champions Online, Star Trek Online, and Neverwinter), chances are you were notified via email about this just a few hours ago.

    The unauthorized access included user account names, handles, and encrypted passwords for those accounts. Even though the passwords were encrypted, it is apparent that the intruder has been able to crack some portion of the passwords in this database. All accounts that we believe were present in the database have had the passwords reset, and customers registered to these accounts have been notified via e-mail of this incident.

    While we have no evidence that any other information was taken by the intruder, it is possible that the intruder was able to access additional account information. If they did so, the first and last name, e-mail address, date of birth (if provided to Cryptic Studios), billing address, and the first six digits and the last four digits of credit cards registered on the site may have been accessed. We have no evidence at this time that any data other than the account name, handle, and encrypted password were accessed for any user.


    In response, Cryptic has reset the passwords for those user accounts they believe were affected. I apparently had two accounts that have been reset. If your password was reset, you should have received an email to reset your password. It would probably be in your best interest to change your password to your Cryptic account to something unique.

    More information can be found at the security notice page at Cryptic's website.
  • jimykx
    No, I AM your father!
    • Jan 2010
    • 6641

    #2
    I got the e-mail, yeah. This sucks

    Comment

    • SupaDupaNoodle
      Member
      • Apr 2012
      • 21

      #3
      If only these games companies would spend as much time on their internal security as they do on DRM, then things like this wouldn't happen.

      Comment

      • Linux
        wat da gah?
        • Sep 2026
        • 382

        #4
        Re: Security Alert: Cryptic Informs Users of Database Theft from 2010

        Originally posted by SupaDupaNoodle
        If only these games companies would spend as much time on their internal security as they do on DRM, then things like this wouldn't happen.
        This is the exact reason why I still have a job in the world as a system engineer/information system security person. The problem is that these company don't want to spend the cost/money to effectively security their systems. Many of them use bug/security ridden forums [vBulletin] that are hosted directly on a database that links to many of their other services such as their games/friends database because they want to integrate your game login with their forum system. Overall if games would stop being cheap and using crappy products like vBulletin which HAS been proven many times to be highly security ridden unless constantly monitors/patched they wouldn't have so many problems of these nature.

        Comment

        • papasmurf128
          Member
          • Sep 2026
          • 103

          #5
          good thing my CC info is expired on the account.

          Comment

          Working...