Epic Games reportedly hit by 189GB hack, including login and payment info (www.rockpapershotgun.com)
from Carighan@lemmy.world to games@lemmy.world on 29 Feb 2024 09:19
https://lemmy.world/post/12545769

The report comes from Cyber Daily, who also broke the news of last year’s confirmed hack attack on Insomniac Games. The site claims that new ransomware group Mogilevich are the culprits, as per the screencap of a darkweb posting above, and that the hackers are now trying to get Epic or another party to pay up for the return of the data, with a deadline of 4th March.

Epic, however, say that they’ve yet to see any proof that a ransomware attack has taken place. “We are investigating but there is currently zero evidence that these claims are legitimate,” a spokesperson told Eurogamer this morning.

#games

threaded - newest

Risk@feddit.uk on 29 Feb 2024 11:21 next collapse

In the situation that payment details are leaked - I presume one must cancel the associated card?

Carighan@lemmy.world on 29 Feb 2024 11:50 next collapse

Hrm, depends. Usually in modern online payment systems it should be impossible for the debitor to have the CVC of the card and hence leaked information could not make actual payments from it, but it could spam the card’s number with bogus payments to continuously keep it being blocked.

In any case if you’re affected I would recommend asking your bank how to proceed, just to be on the safe side.

elvith@feddit.de on 29 Feb 2024 12:46 next collapse

On the other hand, when steam had a leak a few years ago (where you could see other people’s account details after logging in instead of yours) my credit card got exchanged automatically by the bank, as they saw that I had used it to buy games on steam - even though in this „leak“ only the last 4 digits were leaked and nothing more

webhead@lemmy.world on 29 Feb 2024 14:48 collapse

That’s not a requirement. You can make payments without one though the odds of approval aren’t great. If the actual real card numbers got leaked, you need to cancel that card. Also if they actually leaked REAL card numbers, Epic is going to be in deep shit with the card brands.

This article has no real details though so we’ll see. I kind of doubt this is legit.

dai@lemmy.world on 29 Feb 2024 15:10 collapse

I guess the answer is money, but why would you do any handling of card details in-house. Having a third party process transactions passes to some degree ensuring security onto said third party.

I’d still doubt any risk of full card details being leaked unless the hack goes much deeper than just Epic.

Fredselfish@lemmy.world on 29 Feb 2024 13:09 next collapse

Good thing Epic doesn’t have my card information because I only use it for the free games. Now if this was steam I be worried.

themeatbridge@lemmy.world on 29 Feb 2024 13:54 next collapse

That was my thought, too.

SuckMyWang@lemmy.world on 01 Mar 2024 11:28 collapse

But you’ll get free credit checks for a year so nothing to fear

Risk@feddit.uk on 01 Mar 2024 10:59 next collapse

I’m not sure if I’ve ever entered mine either. I ought to go check…

Blackmist@feddit.uk on 01 Mar 2024 11:12 collapse

I can’t see any listed in the Manage Payment Management section.

I assume I never saved them, when I bought Outer Wilds years ago.

9715698@lemmy.world on 01 Mar 2024 11:14 collapse

It’s almost surprising, for good shitty EGS is, that they don’t makes you save a payment method to check out the free games.

HeyJoe@lemmy.world on 29 Feb 2024 14:09 next collapse

For me I started using a service called Privacy a few years ago and haven’t looked back so far. It’s changed how I handle all online transactions. It let’s you create virtual cards that are either good once or forever and once it’s used by that merchant it’s tied to them. So if someone ever did try to charge you that wasn’t that exact merchant it gets blocked. You can set daily, and monthly limits as well and pause the card or close it whenever. So I would use this virtual card for the payment on epic and then this happens and all I do is close it out and open a new one. So far I did have 1 place that had my card charged from a place that wasn’t them. The cool part is you know who almost screwed you because of the card thats being used. It was a local pizza place and I called to let them know they probably got hacked.

jaykay@lemmy.zip on 29 Feb 2024 14:19 collapse

You can’t sound more like an ad haha

HeyJoe@lemmy.world on 29 Feb 2024 20:11 collapse

My bad lol. It is really great though!

Jakeroxs@sh.itjust.works on 29 Feb 2024 23:16 collapse

One used to have a similar thing before they got bought out by Walmart and started dropping features 🙃

catloaf@lemm.ee on 29 Feb 2024 15:06 collapse

No, when you store your card, it doesn’t actually store the whole card details. It communicates with the payment processor and when the card is approved, it gets back a token that says “this card is valid”, so in the future they just have to send that token and the payment processor says “yup I know the card you’re talking about”.

At least that’s how it’s supposed to be. You’re really not supposed to store card info yourself.

TheQuietCroc@lemmy.world on 29 Feb 2024 15:27 next collapse

My last role was in payment processing and this is exactly how we did it.

BURN@lemmy.world on 29 Feb 2024 18:47 collapse

Mine was too. We still had a couple systems using the old methods, but mostly had moved to the token system.

You also just get laid off? They took out ~50% of the payments department at my last job

TheQuietCroc@lemmy.world on 01 Mar 2024 14:27 collapse

Nah, got laid off last March.

mox@lemmy.sdf.org on 29 Feb 2024 17:42 next collapse

That’s the ideal, but not always the case. Last time I read the PCI rules, merchants could (still) handle/store card details just as they could before the hands-off approach existed; it just required someone to attest that precautions were taken. I’m sure you can guess how foolproof that is.

mnemonicmonkeys@sh.itjust.works on 29 Feb 2024 22:39 next collapse

At least that’s how it’s supposed to be. You’re really not supposed to store card info yourself.

Don’t forget that we’re talking about a company that took 3 years to add a shopping cart to their store

piecat@lemmy.world on 01 Mar 2024 11:30 collapse

Just don’t use a debit card?

Credit cards have all sorts of consumer protections if the card gets stolen.

[deleted] on 01 Mar 2024 15:39 collapse

.

moody@lemmings.world on 29 Feb 2024 14:27 next collapse

Situations like this are why I never save my payment information anywhere.

TheIllustrativeMan@lemmy.world on 01 Mar 2024 16:26 collapse

I use a CC, so I really don’t give a shit if someone steals my number.

Last time my card got skimmed it was $0 and <30 seconds to fix, including hold time. They don’t fuck around when you’re reporting stolen info, because legally it’s their money, not yours.

phi1997@kbin.social on 29 Feb 2024 12:02 next collapse

Glad I never made an account there

DarkGamer@kbin.social on 29 Feb 2024 12:45 collapse

Free games in exchange for identity theft. No thanks.

pivot_root@lemmy.world on 01 Mar 2024 01:55 collapse

Press F for all those people who decided to pay for shit on that platform because of the holiday 25% off voucher. Saved $15 in exchange for random unauthorized charges in the future.

Dark_Arc@social.packetloss.gg on 29 Feb 2024 15:12 next collapse

Press X to doubt.

Carighan@lemmy.world on 29 Feb 2024 16:22 collapse

Nah, use Mastodon or Bluesky 😜

Dark_Arc@social.packetloss.gg on 29 Feb 2024 22:22 collapse

I hate this… 😂

atocci@kbin.social on 29 Feb 2024 13:12 next collapse

If I only have an account through Xbox login, and my only payment method is PayPal, what kind of risks are there?

ColonelPanic@lemm.ee on 29 Feb 2024 17:57 collapse

You’re fine unless something happens to PayPal.

notannpc@lemmy.world on 29 Feb 2024 19:30 next collapse

cyberplace.social/…/112010182183098717

Trustworthy infosec folks seem to suggest that this ransomeware group is full of shit. I suppose we will see though.

Kusimulkku@lemm.ee on 01 Mar 2024 00:00 next collapse

189GB hack

That’s how we’re quantifying them now??

Patches@sh.itjust.works on 01 Mar 2024 01:49 next collapse

They stole half a copy of the latest Call Of Duty

piecat@lemmy.world on 01 Mar 2024 11:28 collapse

Is that street value?

Pocketyeti@lemmy.world on 01 Mar 2024 01:33 next collapse

I mean oh no, my library of free games…

woelkchen@lemmy.world on 01 Mar 2024 16:27 collapse

Gosh, what happens to my payment info in such a case?

nutsack@lemmy.world on 01 Mar 2024 15:50 next collapse

it’s all good. this sort of thing happens constantly

SRo@lemmy.dbzer0.com on 01 Mar 2024 16:28 collapse

Hahaha fuck epic