Battle.net got hacked

Posted by Nick Gammon on Sat 11 Aug 2012 09:58 AM — 3 posts, 16,833 views.

Australia Forum Administrator #0
Apparently Blizzard's Battle.Net servers were hacked and account details for millions of customers stolen:

http://www.bbc.com/news/technology-19207276

Blizzard's own announcement:

http://sea.blizzard.com/en-sg/securityupdate.html

Quote:

This week, our security team found an unauthorized and illegal access into our internal network here at Blizzard.

...

For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed.


Well, thanks for telling me, Blizzard. NOT.

I haven't had any email from Blizzard to notify me of this breach of security.

I'm just supposed to stumble across this announcement am I?

I know, if we don't tell anyone it hasn't happened, right?
Germany #1
At least they admitted it this time. Last time they had a mass of account hacking incidents, they blamed the victims, then stealth-patched it.

Of course in this case their servers were actually compromised, rather than people using an in-game exploit, so it's a lot harder to just sweep it under the rug.
Amended on Mon 13 Aug 2012 12:09 PM by KaVir
Australia Forum Administrator #2
I still haven't got an official email from them. On their forum some posters claim it is "very hard" for Blizzard to email everyone, and that it is preferable just to put notes on social networking sites.

This is just so ridiculous I wonder they aren't embarrassed to type it. Every couple of months I get an email from Blizzard announcing something or other. Surely announcing they got hacked and you should change your password, would be a high-priority email?

And as I pointed out on their forum, it is all very well to say "change your personal question/answer" but say you originally used "what is your mother's maiden name?" as the personal question, and answered truthfully, then now the hackers know the answer. I can't change my mother's maiden name. (That could be used to hack into a different site).

Some people have suggested that you just make up random answers (eg, my mother's maiden name might be "wgOWh]\_H!&9") but what is the point of that? If I forget my password I'll probably forget some made-up answer to the personal question.