Steam cache overload exploit reveals personal data, no CC or account info compromised

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#1  Edited By deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

Okay, so I don't know what happened to Steam, but this is a major issue right now, potentially putting 125 million accounts at risk.

When you log in from the Steam client, you will find that the home page language may be changed, or your personalized wishlists or purchase lists are not being displayed. If you attempt to click on 'Account Information' in the client, you are taken to an account information page for some other account. You get shown sensitive information, such as their purchase history, payment method, Steam wallet balance (which you get access to), and more. Steam Guard accounts are not safe from this glitch.

Guys, this is not good.

WHAT DO YOU DO?

@R10nu said:
@charizard1605 said:

I actually can't access my Steam account at all right now- my credit card is on there, how do I get it removed from there?

Plus I'm worried someone will go through my history and remove games from my library...

Steamstat guys recommend logging the **** out and not touching Steam until the problem is sorted.

@R10nu said:
@charizard1605 said:

Logging out from just the client, or the webstore and mobile app too?

Everything.

https://twitter.com/SteamDB

Log out of Steam on all devices, wait it out, and hope your account doesn't get exploited.

UPDATE

Valve has taken Steam offline for now. Let's hope the damage is contained.

UPDATE 2

You just search for Steam account page, and then click on Cached.

It's pretty serious now.

So... erm, damn it, I really hope no one has access to my account.

Update 3: Valve has issued a statement regarding today's issues.

"Steam is back up and running without any known issues," a Valve spokesperson told GameSpot. "As a result of a configuration change earlier today, a caching issue allowed some users to randomly see pages generated for other users for a period of less than an hour. This issue has since been resolved. We believe no unauthorized actions were allowed on accounts beyond the viewing of cached page information and no additional action is required by users."

http://www.gamespot.com/articles/steam-issue-allowing-access-to-other-users-account/1100-6433371/

Avatar image for m3dude1
m3dude1

2334

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#2 m3dude1
Member since 2007 • 2334 Posts

this shit happens at least once a month.

Avatar image for altivera
Altivera

101

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#3 Altivera
Member since 2015 • 101 Posts

Good thing I don't use Steam.

Avatar image for CountBleck12
CountBleck12

4726

Forum Posts

0

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

#4 CountBleck12
Member since 2012 • 4726 Posts

I think the safest precaution is not do anything when navigating the Steam Client, not even logging out. Just sort out your personal information outside Steam if you have credit cards or PayPal information.

Steam did really **** up.

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#5 lostrib
Member since 2009 • 49999 Posts

Well there's no way around it, valve fucked up bad.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#6 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@CountBleck12 said:

I think the safest precaution is not do anything when navigating the Steam Client, not even logging out. Just sort out your personal information outside Steam if you have credit cards or PayPal information.

Steam did really **** up.

I actually can't access my Steam account at all right now- my credit card is on there, how do I get it removed from there?

Plus I'm worried someone will go through my history and remove games from my library...

Avatar image for deactivated-583e460ca986b
deactivated-583e460ca986b

7240

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#8  Edited By deactivated-583e460ca986b
Member since 2004 • 7240 Posts

I'm not touching it. I don't have any pay info stored thankfully. But email addresses, phone numbers and other personal info is out in the open.

PSN is also down.

Xbox Live is running like a champ though...........

Edit: PSN is back for me. WTF PC?????????

Avatar image for R10nu
R10nu

1679

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#10 R10nu
Member since 2006 • 1679 Posts

@charizard1605 said:

I actually can't access my Steam account at all right now- my credit card is on there, how do I get it removed from there?

Plus I'm worried someone will go through my history and remove games from my library...

Steamstat guys recommend logging the **** out and not touching Steam until the problem is sorted.

Avatar image for CountBleck12
CountBleck12

4726

Forum Posts

0

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

#11 CountBleck12
Member since 2012 • 4726 Posts

@charizard1605 said:
@CountBleck12 said:

I think the safest precaution is not do anything when navigating the Steam Client, not even logging out. Just sort out your personal information outside Steam if you have credit cards or PayPal information.

Steam did really **** up.

I actually can't access my Steam account at all right now- my credit card is on there, how do I get it removed from there?

Plus I'm worried someone will go through my history and remove games from my library...

Unfortunately, I don't have an answer to that.

I don't think you should worry too much about the games, the stuff on your inventory or gifts on the other hand...

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#12  Edited By deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@R10nu said:
@charizard1605 said:

I actually can't access my Steam account at all right now- my credit card is on there, how do I get it removed from there?

Plus I'm worried someone will go through my history and remove games from my library...

Steamstat guys recommend logging the **** out and not touching Steam until the problem is sorted.

Logging out from just the client, or the webstore and mobile app too?

Avatar image for ImBatman-
ImBatman-

1279

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#13 ImBatman-
Member since 2013 • 1279 Posts

This is even worse than the PSN breach. This is a nice Christmas gift for thieves. You just have to hope you don't have any money on your account or whoever gets in is a nice person.

Avatar image for n64dd
N64DD

13167

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#14 N64DD
Member since 2015 • 13167 Posts

And so it begins, I'm having no problems with steam currently?

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#15 lostrib
Member since 2009 • 49999 Posts

Fortunately I don't store payment info online for any of these services (steam, PSN) but it's still worrisome for people to have access to my account info. Unfortunately I'm away from my desktop so the only options I have is mobile or via browser on my laptop but I'm not sure it would help anything. I have steam guard set for my email only

Avatar image for R10nu
R10nu

1679

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#17  Edited By R10nu
Member since 2006 • 1679 Posts
@charizard1605 said:

Logging out from just the client, or the webstore and mobile app too?

Everything.

https://twitter.com/SteamDB

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#18 clyde46
Member since 2005 • 49061 Posts

****! What do I do?

Avatar image for CountBleck12
CountBleck12

4726

Forum Posts

0

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

#19 CountBleck12
Member since 2012 • 4726 Posts
@lostrib said:

I have steam guard set for my email only

Apparently even Steam Guard can't keep you safe.

Avatar image for deactivated-583e460ca986b
deactivated-583e460ca986b

7240

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#20 deactivated-583e460ca986b
Member since 2004 • 7240 Posts

@Slashkice: Yeah that's what everyone at Gaf is experiencing. I'm not even gonna turn my PC on or touch Steam. This is crazy!

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#21 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@R10nu said:
@charizard1605 said:

Logging out from just the client, or the webstore and mobile app too?

Everything.

Thank you, I've done that now.

Jesus, I really hope none of my shit gets exploited. What the ****, Valve.

@Slashkice said:

I can't even log in from the web, it just shows me a different person's account each time. Holy shit.

Yeah, according to @R10nu, the best bet is to just log out from everything and wait this out, and hope your account doesn't get exploited :/

@lostrib said:

Fortunately I don't store payment info online for any of these services (steam, PSN) but it's still worrisome for people to have access to my account info. Unfortunately I'm away from my desktop so the only options I have is mobile or via browser on my laptop but I'm not sure it would help anything. I have steam guard set for my email only

Anyone you know/trust you could tell to log out for you?

---

My question right now is: why is Steam still up? Why have they not taken it offline? This is as major an emergency as there can be for an online storefront.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#22 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@clyde46 said:

****! What do I do?

Log the **** out. On every single device you own.

Avatar image for ImBatman-
ImBatman-

1279

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#23 ImBatman-
Member since 2013 • 1279 Posts

I don't understand what not logging in would help with. Seems like it's meant to protect others from you, not you from others.

Avatar image for Butcer2
Butcer2

75

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#24 Butcer2
Member since 2010 • 75 Posts

@charizard1605 said:
@R10nu said:
@charizard1605 said:

Logging out from just the client, or the webstore and mobile app too?

Everything.

Thank you, I've done that now.

Jesus, I really hope none of my shit gets exploited. What the ****, Valve.

@Slashkice said:

I can't even log in from the web, it just shows me a different person's account each time. Holy shit.

Yeah, according to @R10nu, the best bet is to just log out from everything and wait this out, and hope your account doesn't get exploited :/

@lostrib said:

Fortunately I don't store payment info online for any of these services (steam, PSN) but it's still worrisome for people to have access to my account info. Unfortunately I'm away from my desktop so the only options I have is mobile or via browser on my laptop but I'm not sure it would help anything. I have steam guard set for my email only

Anyone you know/trust you could tell to log out for you?

---

My question right now is: why is Steam still up? Why have they not taken it offline? This is as major an emergency as there can be for an online storefront.

Valve is a extremely incompetent company, ive been saying this for years

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#25  Edited By clyde46
Member since 2005 • 49061 Posts

@charizard1605 said:
@clyde46 said:

****! What do I do?

Log the **** out. On every single device you own.

I havr payment info stored, cant access it!

Avatar image for Heil68
Heil68

60718

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#26 Heil68
Member since 2004 • 60718 Posts

This is type of stuff Sony gets railed for or console sin general, lets see the hermits step up here. :D

anyways PSN has a nice Flash sale going on if you want me to post list with links,

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#27 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@clyde46 said:

I havr payment info stored, cant access it!

Same. And shit in my inventory too, I am pretty sure :/

@ImBatman- said:

I don't understand what not logging in would help with. Seems like it's meant to protect others from you, not you from others.

I think the idea is if everyone logs out, or if most users log out, the potential number of exploits goes down. Or something.

Avatar image for MonsieurX
MonsieurX

39858

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#28 MonsieurX
Member since 2008 • 39858 Posts

@m3dude1 said:

this shit happens at least once a month.

lolno

Avatar image for lamprey263
lamprey263

44618

Forum Posts

0

Wiki Points

0

Followers

Reviews: 10

User Lists: 0

#29  Edited By lamprey263
Member since 2006 • 44618 Posts

I hope my credit card isn't on there. I don't know if I have a current card on their or not, I haven't bought anything since getting a new card so hopefully it didn't do one of those auto updates to my card info when I got issued a new one. Anyhow, I remember saying similar last time there was a major security concern, when things stabilize I'm gonna go make sure all that shit is wiped off my account.

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#30 clyde46
Member since 2005 • 49061 Posts

According to Twitter, Steam is currently down.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#31 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@clyde46: ... so, we're screwed.

Avatar image for ImBatman-
ImBatman-

1279

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#32 ImBatman-
Member since 2013 • 1279 Posts

@Heil68: This is worse than anything PSN has encountered. We're at the mercy of others right now. They need to shut down the servers ASAP to prevent further damage.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#33 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@lamprey263 said:

I hope my credit card isn't on there. I don't know if I have a current card on their or not, I haven't bought anything since getting a new card so hopefully it didn't do one of those auto updates to my card info when I got issued a new one.

Steam doesn't auto update. Personal experience.

Avatar image for Heil68
Heil68

60718

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#34 Heil68
Member since 2004 • 60718 Posts

It seems my games are still there being listed, cant navigate to my account info though. Guess I'll log out.

Avatar image for CountBleck12
CountBleck12

4726

Forum Posts

0

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

#35 CountBleck12
Member since 2012 • 4726 Posts

@charizard1605 said:
@clyde46 said:

I havr payment info stored, cant access it!

Same. And shit in my inventory too, I am pretty sure :/

@ImBatman- said:

I don't understand what not logging in would help with. Seems like it's meant to protect others from you, not you from others.

I think the idea is if everyone logs out, or if most users log out, the potential number of exploits goes down. Or something.

I don't think this is entirely the case though, for some unfathomable reason I was in someone's account who appeared not to be online. That's the weird part.

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#36 clyde46
Member since 2005 • 49061 Posts

Tried reloading my profile page, got an error so maybe Steam has been taken offline.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#37 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

Alright, Steam has been taken down apparently.

Avatar image for deactivated-5a7fcf5e55c95
deactivated-5a7fcf5e55c95

2103

Forum Posts

0

Wiki Points

0

Followers

Reviews: 16

User Lists: 0

#38 deactivated-5a7fcf5e55c95
Member since 2011 • 2103 Posts

Oh gosh, I just launched Steam before I saw this... Better log off.

Avatar image for R10nu
R10nu

1679

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#39 R10nu
Member since 2006 • 1679 Posts

@charizard1605 said:

Yeah, according to @R10nu, the best bet is to just log out from everything and wait this out, and hope your account doesn't get exploited :/

I got that info from steamstat, updated my previous post with a link to their twitter.

@ImBatman- said:

I don't understand what not logging in would help with. Seems like it's meant to protect others from you, not you from others.

If you're not logged in, your account info is not cached, so other people shouldn't be able to stumble into it.

That's the theory so far at least, no one knows for sure yet.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#40 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@R10nu: Thank you! I have added your posts and links to the OP. You have been most helpful.

---

As of right now, Steam is offline.

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#41 clyde46
Member since 2005 • 49061 Posts

@Heil68 said:

This is type of stuff Sony gets railed for or console sin general, lets see the hermits step up here. :D

anyways PSN has a nice Flash sale going on if you want me to post list with links,

Sony stored users info in plain text, this is a major account glitch. Either way though, its still bad, very bad.

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#42 clyde46
Member since 2005 • 49061 Posts

@R10nu: Thats what we're assuming but I was looking at someone elses account that wasn't online and his last purchase was two days ago.

Avatar image for deactivated-5a7fcf5e55c95
deactivated-5a7fcf5e55c95

2103

Forum Posts

0

Wiki Points

0

Followers

Reviews: 16

User Lists: 0

#43 deactivated-5a7fcf5e55c95
Member since 2011 • 2103 Posts

So go offline and log off is okay right?

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#44 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts
@clyde46 said:
@Heil68 said:

This is type of stuff Sony gets railed for or console sin general, lets see the hermits step up here. :D

anyways PSN has a nice Flash sale going on if you want me to post list with links,

Sony stored users info in plain text, this is a major account glitch. Either way though, its still bad, very bad.

They're both terrible and they are both incompetent.

Avatar image for bunchanumbers
bunchanumbers

5709

Forum Posts

0

Wiki Points

0

Followers

Reviews: 11

User Lists: 0

#45 bunchanumbers
Member since 2013 • 5709 Posts

I don't even know where to begin. Even PC betrays me? Looks like I"m Wii U only from here on out!

Avatar image for clyde46
clyde46

49061

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#46 clyde46
Member since 2005 • 49061 Posts

@PikminWorld said:

So go offline and log off is okay right?

No.

It seems that this is coming from what Steam was knocked offline earlier in the day, when it came back it went all screwy. I'm guessing its an automated process.

Avatar image for deactivated-5d6bb9cb2ee20
deactivated-5d6bb9cb2ee20

82724

Forum Posts

0

Wiki Points

0

Followers

Reviews: 56

User Lists: 0

#47 deactivated-5d6bb9cb2ee20
Member since 2006 • 82724 Posts

@PikminWorld said:

So go offline and log off is okay right?

Apparently.

We have no official word on this yet, so this is all conjecture, but... yeah.

Avatar image for Heil68
Heil68

60718

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#48 Heil68
Member since 2004 • 60718 Posts

So it begins,,lol

"The current status of the @steam_games office..."

link

Avatar image for topgunmv
topgunmv

10880

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#49  Edited By topgunmv
Member since 2003 • 10880 Posts

This is pretty fucked up.

Avatar image for Heil68
Heil68

60718

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#50 Heil68
Member since 2004 • 60718 Posts

@bunchanumbers said:

I don't even know where to begin. Even PC betrays me? Looks like I"m Wii U only from here on out!

lol