Epic Games hacked, hundreds of thousands of logins stolen
According to a representative from LeakedSource.com, an alleged data dump of accounts from Unreal Engine and Epic games are being traded on the darkweb and underground communities.These data dumps consist of 530,590 leaked user accounts from the Unreal Engine forum and 277,944 leaked user accounts from the Epic Games forum.
Our recommendation (last updated in June 2016) is to use a password storage system called PBKDF2, and the hash HMAC-SHA-256, salted with at least 16 bytes, stretched with at least 20,000 iterations.
Information exposed by the attack includes email addresses, dates of birth and private messages exchanged on the site.
A recent data breach at Epic Games may have been avoided if the company had simply installed a security patch. ‘ Those with accounts exclusively on the Unreal Engine and current Unreal Tournament fora, meanwhile, do not need to reset their passwords and can continue using the site as normal.
Also, we believe a compromise of our legacy forums covering Infinity Blade, UDK, previous Unreal Tournament games, and archived Gears of War forums revealed email addresses, salted hashed passwords and other data entered into the forums.
Otherwise, accounts created before July 2015 would be at risk of password recovery, too, assuming the crooks plundered the forum databases.
A hacker has stolen hundreds of thousands of logins associated with the gaming giant Epic Games, CBS partner and technology website ZDNet reported.
More than 808,000 accounts were reportedly compromised.
When contacting Epic Games regarding this breach, I was forwarded to an announcement that they have posted on their site regarding the compromise.
The anonymous attackers targeted the vBulletin forum software on August 11, according to the website Leaked Source, which has been in contact with the hackers. Although it’s unclear which vulnerability was exploited in the that breach, vBulletin recently issued patches for a problem that could allow an attachment to exploit a system for vBulletin versions 3.8.7 and up.
Change your Epic passwords, even if Epic thinks you don’t need to. Children grow up and leave home.