• Contact Us
  • Login
Upgrade
Tech News Hero
Advertisement
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
Tech News Hero
No Result
View All Result
Home News

The Gathering’ game maker exposed 452,000 players’ account data – TechNewHero

by technewshero
November 16, 2019
in News
0
Share on FacebookShare on Twitter

The maker of Magic: The Gathering has confirmed that a security lapse exposed the data on hundreds of thousands of game players.

The game’s developer, the Washington-based Wizards of the Coast, left a database backup file in a public Amazon Web Services storage bucket. The database file contained user account information for the game’s online arena. But there was no password on the storage bucket, allowing anyone to access the files inside.

The bucket is not believed to have been exposed for long — since around early-September — but it was long enough for U.K. cybersecurity firm Fidus Information Security to find the database.

A review of the database file showed there were 452,634 players’ information, including about 470 email addresses associated with Wizards’ staff. The database included player names and usernames, email addresses, and the date and time of the account’s creation. The database also had user passwords, which were hashed and salted, making it difficult but not impossible to unscramble.

None of the data was encrypted. The accounts date back to at least 2012, according to our review of the data.

A formatted version of the database backup file, redacted, containing 452,000 user records. (Image: TechNewHero)

Fidus reached out to Wizards of the Coast but did not hear back. It was only after TechNewHero reached out that the game maker pulled the storage bucket offline.

Bruce Dugan, a spokesperson for the game developer, told TechNewHero in a statement: “We learned that a database file from a decommissioned website had inadvertently been made accessible outside the company.”

“We removed the database file from our server and commenced an investigation to determine the scope of the incident,” he said. “We believe that this was an isolated incident and we have no reason to believe that any malicious use has been made of the data,” but the spokesperson did not provide any evidence for this claim.

“However, in an abundance of caution, we are notifying players whose information was contained in the database and requiring them to reset their passwords on our current system,” he said.

Harriet Lester, Fidus’ director of research and development, said it was “surprising in this day and age that misconfigurations and lack of basic security hygiene still exist on this scale, especially when referring to such large companies with a userbase of over 450,000 accounts.”

“Our research team work continuously, looking for misconfigurations such as this to alert companies as soon as possible to avoid the data falling into the wrong hands. It’s our small way of helping make the internet a safer place,” she told TechNewHero.

The game maker said it informed the U.K. data protection authorities about the exposure, in line with breach notification rules under Europe’s GDPR regulations. The U.K.’s Information Commissioner’s Office did not immediately return an email to confirm the disclosure.

Companies can be fined up to 4% of their annual turnover for GDPR violations.

Previous Post

WhatsApp in 2019: All the New Features the Chat Service Added This Year

Next Post

This Flossing Toothbrush Cleans Your Teeth Twice as Good

technewshero

technewshero

Related Posts

Fluence, the energy storage systems developer, is now worth over $1 billion after QIA investment – TechCrunch
News

Fluence, the energy storage systems developer, is now worth over $1 billion after QIA investment – TechCrunch

by technewshero
January 13, 2021
Elon Musk says SpaceX will attempt to recover Super Heavy rocket by catching it with launch tower – TechCrunch
News

Elon Musk says SpaceX will attempt to recover Super Heavy rocket by catching it with launch tower – TechCrunch

by technewshero
January 14, 2021
2020 will change the way we look at robotics – TechCrunch
News

2020 will change the way we look at robotics – TechCrunch

by technewshero
January 15, 2021
An earnest review of a robotic cat pillow – TechCrunch
News

An earnest review of a robotic cat pillow – TechCrunch

by technewshero
January 16, 2021
Trump vetoes major defense bill, citing Section 230 – TechNewHero
News

Trump vetoes major defense bill, citing Section 230 – TechNewHero

by technewshero
December 24, 2020
Next Post

This Flossing Toothbrush Cleans Your Teeth Twice as Good

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Most Popular

IoT home security camera allows hackers to listen in over HTTP

July 31, 2019
Lenovo Tab P11 is an Android version of its great Chromebook Duet 2-in-1

Lenovo Tab P11 is an Android version of its great Chromebook Duet 2-in-1

January 12, 2021

Razer’s iPhone 11 case keeps your phone cool during intense gaming sessions

September 11, 2019

Browse by Category

  • Apps
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • News
  • PC & Laptops
  • Security
  • Social
Tech News Hero

© 2020 Tech News Hero.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© 2020 Tech News Hero.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?