Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Cryptic Hacked

C_CarmichaelC_Carmichael Member UncommonPosts: 21

Received notification today via email, and later confirmed on the STO website by the devs, that a security breach occured, and personal information was accessed.

For more information, see the security notification here:

http://www.crypticstudios.com/securitynotice

Comments

  • KehdarKehdar Member UncommonPosts: 441

    Same here :(

  • darkbamydarkbamy Member UncommonPosts: 111

    sigh...here we go....again >_<

  • BreezeycoukBreezeycouk Member Posts: 82

    Yeah read it and weep!!!!!!!!!!!!!!!:

     


    IMPORTANT CUSTOMER SERVICE NOTIFICATION REGARDING UNAUTHORIZED ACCESS



     

    News



    04.25.2012






    strong
    {
    color: white;
    }


    At Cryptic Studios, your privacy and security is important. As part of our ongoing efforts to monitor and enhance security, we recently detected evidence of an unauthorized access to one of our user databases. The unauthorized access occurred in December 2010, and evidence of this has just been uncovered due to increased security analysis.

    The unauthorized access included user account names, handles, and encrypted passwords for those accounts. Even though the passwords were encrypted, it is apparent that the intruder has been able to crack some portion of the passwords in this database. All accounts that we believe were present in the database have had the passwords reset, and customers registered to these accounts have been notified via e-mail of this incident.

     

    So you were hacked back in Dec 2010 and only now you found out and let us know and changed our passwords....

     

    Jeez - It is me or what ????  Didn't anyone learn from $OE ?????

     

    When are you people going to wake up ????

     

    Oh - And you changed my password and don't direct me to this post at all ???

    (Heaven forbid that I should change my email address in over 4 years of playing after giving you $249.00 for a life time membership)

    Then you go on to say :

     

    While we have no evidence that any other information was taken by the intruder, it is possible that the intruder was able to access additional account information. If they did so, the first and last name, e-mail address, date of birth (if provided to Cryptic Studios), billing address, and the first six digits and the last four digits of credit cards registered on the site may have been accessed. We have no evidence at this time that any data other than the account name, handle, and encrypted password were accessed for any user.

     

    Yeah and that fills me with a warm and fuzzy feeling of security....  Guess where I am going first thing in morning............

     

    EDIT:  Oh - and now after being loged out all night due to emergency maintenance of the database and when you finally allow me to attempt to login and then tell me my login failed (without telling me why....) and I raise a support ticket via email (cos I can't raise one through my account - cos you haven't told me why I can't login.........) I get this:

    Your question has been received. You should expect a response from us within 3-4 business days.

    Seriously people - Is it me or does CS just suck now ???

    (And they wonder why people won't pay for games......)






  • WoopinWoopin Member UncommonPosts: 1,012

    Originally posted by darkbamy

    sigh...here we go....again >_<

    Happened years ago they only just noticed.

    image

  • ShardWarriorShardWarrior Member Posts: 290

    Originally posted by Breezeycouk

    While we have no evidence that any other information was taken by the intruder, it is possible that the intruder was able to access additional account information. If they did so, the first and last name, e-mail address, date of birth (if provided to Cryptic Studios), billing address, and the first six digits and the last four digits of credit cards registered on the site may have been accessed. We have no evidence at this time that any data other than the account name, handle, and encrypted password were accessed for any user.

    This is evidence that Cryptic/PWE are not PCI Compliant (https://www.pcisecuritystandards.org/).  Were enough customers to file a formal complaint, Cryptic could have their ability to accept credit card payments suspended by the banks.

  • BreezeycoukBreezeycouk Member Posts: 82

     

    You know what really gets my goat about this is that I still haven't heard back on how to reset my password and this isn't mentioned anywhere else on any of the Cryptic / Perfect World / Star Trek Online web sites / portals / support pages / forums etc...

    Who is going to go to the Cryptic website home page or news page when you have an issue with a specific game when you have quick links to "support" ??????

    I mean if I haven't come here then I wouldn't know what was going on...

    Are they like $OE and have something bigger to hide and this is just enough to cover them ?

     

    On another note they ask us to be vigilent regarding email / bank statements etc but this happened over 15 months ago - the damage is surely done by now ???? !!!! ????

     

    Jeez - Is it really just me???

     

    image

  • darkbamydarkbamy Member UncommonPosts: 111

    Originally posted by Woopin

    Originally posted by darkbamy

    sigh...here we go....again >_<

    Happened years ago they only just noticed.

     

    really?

     

    wow thats just bad

  • ShardWarriorShardWarrior Member Posts: 290

    Originally posted by Breezeycouk

     You know what really gets my goat about this is that I still haven't heard back on how to reset my password and this isn't mentioned anywhere else on any of the Cryptic / Perfect World / Star Trek Online web sites / portals / support pages / forums etc...

    Try here http://forums.startrekonline.com/showthread.php?t=268025

  • ZekiahZekiah Member UncommonPosts: 2,483

    2010? Just figured it out? Ouch lol.

    "Censorship is never over for those who have experienced it. It is a brand on the imagination that affects the individual who has suffered it, forever." - Noam Chomsky

  • Agent_JosephAgent_Joseph Member UncommonPosts: 1,361
    it happen in December 2010...OMFG and they reset passwords today...LOL...
  • BreezeycoukBreezeycouk Member Posts: 82

    Well it looks like I am not the only one struggling to get back in - It takes a day for them to respond to each email and when they do they don't give you the whole story.

     

    Now I'm up to them asking to call me to reset everything if I can supply more information to prove I am me.

     

    Problem is:

    I'm not in the US ( Couldn't you have picked that up from my email address and the fact that you should have this info on my account.....)

    Yeah - Like I still have the original debit card I used 3 years ago to purchase the product.

    Yeah - Like I still have the original install key 3 years after the event now you have moved to a download of client

     

    It seems I am not the only one suffering these problems  (See the Cryptic forum....)

     

    Would it be wrong for me to suggest that this is a precursor to the game being closed for Cryptic players or is that me just being paranoid???

     

  • OrphesOrphes Member UncommonPosts: 3,039

    I have spent the last 30 minutes on 3 password reset, user name reminder from Perfect World.

    I'm not getting in.

     

    They are stupid and thank god I am not going to actually play the game. :(

    I'm so broke. I can't even pay attention.
    "You have the right not to be killed"

  • eyeswideopeneyeswideopen Member Posts: 2,414

    Yet another example of why I refuse to buy or play any game that requires a credit card to be entered at any time. From this thread, it seems many people have yet to learn that lesson.

    I prefer games that accept game cards. Therefore, you not only don't have to give any real payment info, but you also don't have to give any real info at all since your name, address, birthdate, etc. don't have to be matched to the card like a CC.

    -Letting Derek Smart work on your game is like letting Osama bin Laden work in the White House. Something will burn.-
    -And on the 8th day, man created God.-

Sign In or Register to comment.