PDA

View Full Version : Valve Held For Ransom by Hacker



Spiegel
Thu, 04-19-2007, 06:27 PM
Not sure if this is real or not yet as Valve has not released any information denying or confirming the information. I have found that the original site the hacker used has been suspended. Here are some quotes from the articles.


Valve held for Ransom By Hacker
Thurs 19th Apr, 2007 @ 11:34:30pm

A hacker who calls himself Maddox is currently holding Valve for ransom. The hacker in question has released screen shots of the internal admin system along with detailed user account information and tips on setting up Cybercafe which is usually an option only for actually Cybercafe's.

The screen shots appear to be legitimate, with lists of CyberCafe accounts, error logs and some credit card data with blacked out numbers.

Maddox was quoted as saying, "If you [Valve] want me to remove these files you can e-mail me at (address removed) and I prefer you come with something good unless you want me to expose ALL of the customers their information."

He's also threatening to create a spreadsheet of all Valve's user base credit card data and to release it onto the web, which could effect millions of Valve customers that have purchased games online through Steam.

Valve has yet to publicly respond to the threat with no mention of the incident on its own website and nothing in it's forums either. Chances are they're already deep in contact with law enforcement and trying their best to to ensure their user base maintains as little knowledge of what's at stake with their own personal information as possible.

Quoted from DailyTech, "It seems that VALVe is being held for ransom. If this is true, VALVe may be in trouble, as California Senate Bill 1386 requires that credit card holders be informed of any breach of their information, and MaddoxX already knows exactly how much money they have available.

According to a posting made on an anti-STEAM website, MaddoxX has bypassed VALVe's security system and accessed a significant chunk of data, including:

* Screenshots of internal VALVe web pages
* A portion of VALVe's Cafe directory
* Error logs
* Credit card information of customers
* Financial information on VALVe"

Sources:
Source 1 (http://www.theinquirer.net/default.aspx?article=39032)
Source 2 (http://www.dailytech.com/STEAM+Hacked+User+Credit+Cards+May+be+at+Risk/article6972.htm)

What do yall think of this... interesting situation?

Assertn
Thu, 04-19-2007, 09:32 PM
Source 2 says:


Update 04/19/2007: Doug Lombardi, director of marketing at Valve, contacted DailyTech with the following statement:

There has been no security breach of Steam. The alleged hacker gained access to a third-party site that Valve uses to manage the commercial partners in its Cyber Café program. This Cyber Café billing system is not connected to Steam. We are working with law enforcement agencies on this matter, and encourage anyone with more information to e-mail us at Catch_A_Thief@valvesoftware.com.

Spiegel
Thu, 04-19-2007, 10:41 PM
Well I guess it is settled then. Interesting I guess. I figured it was a hoax, Just was wondering were he got the web interface from. At first I figured he just made it himself or modeled it after someting else. Kinda wish he had gotten into the steam site, except for the whole peoples CC#'s being spread... but since it didn't happen, oh well.

itadakimasu
Tue, 04-24-2007, 09:55 AM
sometimes i feel like i'm being held hostage when i goto play a game of counterstrike and my favorite server has a hacker ruinning the game, and i seem like the only person from 20 people who notices and wants to ban him after 60 consecutive headshots in just a couple minutes.. *sigh*

BioAlien
Tue, 04-24-2007, 10:17 AM
I believe it really did happen.
Maddox posted those stuff on his forum
http://emp.damage-web.net/

The website is now suspended(probably forced to close by valve) but before that it was a forum, about nosteam.
He had posted those "proof" of him hacking valve, even the credit card number of 3 person.
I saw them.
There was even a download available to get the cafe thing watever (i downloaded it, i didn't understand a shit from it, i deleted it).

So now.. i'm worried about the security of the credit card i used to purchase Half-life 2 episode 1.
Valve are asshole to have kept those! They are supposed to remove them from their database after the purchase has been done!