Mobafire League of Legends Build Guides Mobafire League of Legends Build Guides
's Forum Avatar

EU NE and W: League of Legends Account Security...

Creator: wRAthoFVuLK
June 9, 2012 12:11am
13 posts page 1 of 2 Forums » General Discussion » EU NE and W: League of Legends Account Security Alert
Permalink | Quote | PM | +Rep | Commend by wRAthoFVuLK » June 9, 2012 12:11am | Report
Keeping player information secure is very important to Riot. That's why we're sorry to share that hackers accessed some player account information.

Scope

After thorough and urgent investigation with help from independent security experts, we have determined:

Hackers gained access to certain personal player data contained in certain EU West and EU Nordic & East databases ; as a security precaution, we're emailing all players on these platforms
The most critical data accessed included email address, encrypted account password, summoner name, date of birth, and – for a small number of players – first and last name and encrypted security question and answer
Absolutely no payment or billing information of any kind was included in the breach
Even though we store passwords in encrypted form only, our security investigation determined that more than half of the passwords were simple enough to be at risk of easy cracking.

Our actions:

We've fixed the specific security issue that hackers exploited.
Over the next 24 hours, we'll be notifying all EUW and EUNE players via email; although only a portion of players might have been affected, we consider broader notification a good security precaution.
We'll be updating this post with the latest on this situation and will monitor comments here for questions that require further clarification.
Our investigation into this issue is ongoing – we've hired experts and are working with the relevant authorities to more thoroughly understand causes, culprits, and preventative measures to make future breaches less likely.
We've redirected teams to quickly implement new security measures that will help improve the safety of your data.
We'll continue to invest in security measures, including password hashing and data encryption, state-of-the-art firewalls, SSL, security ninjas, and other security measures to make your info safer. We've been humbled by this experience and know that nothing guarantees the security of Internet-connected systems such as League of Legends. We can simply promise to try our very best to protect your data.
Please change your passwords

Please immediately change your account password by visiting the account management page at https://euw.leagueoflegends.com/account, then clicking "change password." If you use the same password for accounts on other services, you should change those passwords as well.
Please use a good password. We compared encrypted password hashes and discovered that 11 passwords were shared by over 10,000 players each. A double-digit percentage of individuals had the same password as at least one other person. We encourage you to:
-Keep it unique -- use a different password for each important account
-Make it long -- at least 8 characters
-Mix it up -- use letters, numbers, and special characters
Hackers often send phishing emails to addresses that are captured in data thefts, so please be extra vigilant about emails containing attachments or links.
We're sorry

Brandon and I want to sincerely and personally apologize to you for this situation. We take your privacy and security seriously, and we're working diligently to improve it for the better.

Thank you,

Marc Merrill
Brandon Beck


quoted from http://euw.leagueoflegends.com/news/league-legends-account-security-alert

Thanks to TRUeLM, Plastictree, Scrax, Xiaowiriamu, foggy12, JahGFX, jhoijhoi, msrobinson, JEFFY40HANDS, Nyoike, MissMaw, and me :) for the sigs!
wRAthoFVuLK's Forum Avatar

Awards Showcase
Show more awards
wRAthoFVuLK
<Altruistic Artist>
Posts: 10851
Joined: Jan 17th, 2011
Rep: Renowned (535)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by Mastarwe » June 9, 2012 1:19am | Report
I guess it had to happen, not really possible for a big game to go unnoticed.
I'm back!
Mastarwe's Forum Avatar

Mastarwe
<Member>
Posts: 421
Joined: Dec 22nd, 2010
Rep: Notable (41)
Profile
Permalink | Quote | PM | +Rep | Commend by caucheka » June 9, 2012 3:00am | Report
yeah, given enough determination and time, nothing is safe from being hacked.

at least its good that there is no billing information that was apparently hacked into and stolen.
I like things that make me feel stupid. - Ken Levine
caucheka's Forum Avatar

Awards Showcase
Show more awards
caucheka
<Veteran>
Posts: 8290
Joined: May 18th, 2010
Rep: Prominent (197)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by Mowen » June 9, 2012 4:35am | Report
You know, I saw that and thought it was a hacker trying to get me to type in my username / password because I have gotten one of those for LoL before. :P
Thanks to GrandMasterD for my sig!
Mowen's Forum Avatar

Awards Showcase
Show more awards
Mowen
<Production Coordinator>
Posts: 6333
Joined: Nov 7th, 2010
Rep: Renowned (580)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by Wayne3100 » June 9, 2012 4:39am | Report
Changed my password already. Good thing they apparently didnt get any payment or billing information.

Thanks to MissMaw for the signature!
Wayne3100's Forum Avatar

Awards Showcase
Show more awards
Wayne3100
<Community Manager>
Posts: 7148
Joined: Aug 3rd, 2011
Rep: Esteemed (481)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by Malin » June 9, 2012 4:42am | Report
:@
i dont wanna change my pw.. when i do i always forget it
👌👌👌👌👌👌 pc master race 👌👌👌👌👌👌
Malin's Forum Avatar

Awards Showcase
Show more awards
Malin
<Member>
Posts: 377
Joined: Jan 29th, 2012
Rep: Notable (34)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by caucheka » June 9, 2012 4:43am | Report
Mowen wrote:

You know, I saw that and thought it was a hacker trying to get me to type in my username / password because I have gotten one of those for LoL before. :P


funny enough, i got spam emails of change your password for battle.net 2.0 right before **** hit the fan too.
I like things that make me feel stupid. - Ken Levine
caucheka's Forum Avatar

Awards Showcase
Show more awards
caucheka
<Veteran>
Posts: 8290
Joined: May 18th, 2010
Rep: Prominent (197)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by IceCreamy » June 9, 2012 4:52am | Report
Will do it right away, thanks for the heads up.

DuffTime wrote:
ok ok plz carry me omg
i was only waiting for you to ask

Temzilla wrote:
Too hot to be icecream.

Luther3000 wrote:
He looks like a hair gel advert on legs

Toshabi wrote:
Icecreamy, with hair as slick and smooth as the ocean waves of Cocobana
IceCreamy's Forum Avatar

Awards Showcase
Show more awards
IceCreamy
<Moderator>
Posts: 5981
Joined: Aug 14th, 2011
Rep: Esteemed (450)
Blog   |   Profile
Permalink | Quote | PM | +Rep | Commend by Wintermond » June 9, 2012 6:43am | Report
Got one email from Riot and one from Last.fm today concerning data leaks. :f

El Psy Congroo.


|You can't spell slaughter without laughter.|

Wintermond's Forum Avatar

Wintermond
<Scout>
Posts: 3204
Joined: Nov 18th, 2010
Rep: Prominent (189)
Profile
Permalink | Quote | PM | +Rep | Commend by lekko » June 9, 2012 10:45am | Report
I cant acces the homepage to change my pw, so any advice to what i should do now?
lekko's Forum Avatar

lekko
<Member>
Posts: 3
Joined: Sep 18th, 2011
Profile

Quick Reply:

Guest commenting is currently disabled, please log in or sign up to respond!