Great, just great. Apparently, another company had their database accessed, only this one happened back on December 2010 and is only now being discovered and publicly known. Yes, the user databases of Cryptic Studios was accessed in 2010 and if you have ever played any of their games in the past two years (City of Heroes, City of Villains, Champions Online, Star Trek Online, and Neverwinter), chances are you were notified via email about this just a few hours ago.
In response, Cryptic has reset the passwords for those user accounts they believe were affected. I apparently had two accounts that have been reset. If your password was reset, you should have received an email to reset your password. It would probably be in your best interest to change your password to your Cryptic account to something unique.
More information can be found at the security notice page at Cryptic's website.
The unauthorized access included user account names, handles, and encrypted passwords for those accounts. Even though the passwords were encrypted, it is apparent that the intruder has been able to crack some portion of the passwords in this database. All accounts that we believe were present in the database have had the passwords reset, and customers registered to these accounts have been notified via e-mail of this incident.
While we have no evidence that any other information was taken by the intruder, it is possible that the intruder was able to access additional account information. If they did so, the first and last name, e-mail address, date of birth (if provided to Cryptic Studios), billing address, and the first six digits and the last four digits of credit cards registered on the site may have been accessed. We have no evidence at this time that any data other than the account name, handle, and encrypted password were accessed for any user.
While we have no evidence that any other information was taken by the intruder, it is possible that the intruder was able to access additional account information. If they did so, the first and last name, e-mail address, date of birth (if provided to Cryptic Studios), billing address, and the first six digits and the last four digits of credit cards registered on the site may have been accessed. We have no evidence at this time that any data other than the account name, handle, and encrypted password were accessed for any user.
In response, Cryptic has reset the passwords for those user accounts they believe were affected. I apparently had two accounts that have been reset. If your password was reset, you should have received an email to reset your password. It would probably be in your best interest to change your password to your Cryptic account to something unique.
More information can be found at the security notice page at Cryptic's website.
Comment