Crytic studio hacked???

Permabanned
Joined
15 May 2006
Posts
4,107
Location
London
http://crypticstudios.com/securitynotice

IMPORTANT CUSTOMER SERVICE NOTIFICATION REGARDING UNAUTHORIZED ACCESS

News
04.25.2012


At Cryptic Studios, your privacy and security is important. As part of our ongoing efforts to monitor and enhance security, we recently detected evidence of an unauthorized access to one of our user databases. The unauthorized access occurred in December 2010, and evidence of this has just been uncovered due to increased security analysis.

The unauthorized access included user account names, handles, and encrypted passwords for those accounts. Even though the passwords were encrypted, it is apparent that the intruder has been able to crack some portion of the passwords in this database. All accounts that we believe were present in the database have had the passwords reset, and customers registered to these accounts have been notified via e-mail of this incident.

While we have no evidence that any other information was taken by the intruder, it is possible that the intruder was able to access additional account information. If they did so, the first and last name, e-mail address, date of birth (if provided to Cryptic Studios), billing address, and the first six digits and the last four digits of credit cards registered on the site may have been accessed. We have no evidence at this time that any data other than the account name, handle, and encrypted password were accessed for any user.

We are continuing to investigate this incident, and are taking even further action to strengthen our systems and redouble our security vigilance and protections. For your own security, we encourage you to be especially aware of e-mail and postal mail scams that ask for personal or sensitive information. Cryptic will not contact you in any way, including by e-mail, asking for your credit card number, social security number, or any other personally identifiable information. If you use the same password for other accounts, especially financial accounts or accounts with personal information, we strongly recommend that you change them.
 
As a result of routine security checks and upgrades, we have discovered that certain of your account information, including your password, may have been accessed by an unauthorized party.

For your security, we've reset the password on your account. You can recover your password via the "forgot password" link on the official Star Trek Online or Champions Online web sites:

Yeah Cryptic Studios...

http://www.crypticstudios.com/securitynotice

I got an email from them as well, no idea when or why I created an account with them - have never played anything they've made.
 
Same as d_brennen, got an email from Cryptic even though I'm sure I've never played any of their games before, very strange. :/
 
I played Star trek Online and got this email today, I have changed all my passwords since I last played it so I should be safe.
 
got an email too, but said they have reset the password, not that i am bothered never play STO or champions online, tried em for 20 minutes then removed them.
 
As a result of routine security checks and upgrades, we have discovered that certain of your account information, including your password, may have been accessed by an unauthorized party.

Seems legit. (from an email i got from Cryptic)
 
Hyperlink fail.

https://www.startrekonline.com/user/password leads to http://click.email.perfectworld.com/?qs=<insert_random_string_here>
https://www.champions-online.com/user/password leads to http://click.email.perfectworld.com/?qs=<insert_random_string_here>

The real URLs are probably used for tracking but it goes against everything people are taught to protect themselves against phishing attacks.

I noticed that, but i never click links in emails out of habit...
 
Hyperlink fail.

https://www.startrekonline.com/user/password leads to http://click.email.perfectworld.com/?qs=<insert_random_string_here>
https://www.champions-online.com/user/password leads to http://click.email.perfectworld.com/?qs=<insert_random_string_here>

The real URLs are probably used for tracking but it goes against everything people are taught to protect themselves against phishing attacks.

Yes, I got this email, noticed the links weren't pointing to the right place, added it to spam and ignored it.
Good work, Cryptic!
 
At first i thought it was a fake, due to all the grammar mistakes (normally i don't car about grammar but when it's from a company with a message like that it helps when it's correct)

and as above the links, but yeah...
 
The cryptic hack was real and they have sent legitimate emails to their customers. I think it has also spawned a wave of phishing mails to be sent out supposedly from cryptic about the same thing.
 
Back
Top Bottom