Valve Finally Issues A Statement On Cache Leak Issues During Holidays

Valve explains exactly what happened.

Posted By | On 02nd, Jan. 2016

steam

Last week the Steam store was struck by a potentially debilitating flaw- a cache overload that displayed other users’ account information to users, leaking information such as the users’ billing address, the last four digits of their credit card numbers, their Steam wallet amount, their email ID, and the last few digits of their phone number on record.

So far, Valve has remained silent on this issue, and many had expected that the famously reticent company would forego an official statement this time around too. However, they have posted a lengthy statement on the Steam forums, explaining exactly what happened, and apologizing for their oversight.

Here is a summary of what happened and how Valve fixed it.

On December 25th, a configuration error resulted in some users seeing Steam Store pages generated for other users. Between 11:50 PST and 13:20 PST store page requests for about 34k users, which contained sensitive personal information, may have been returned and seen by other users.

The content of these requests varied by page, but some pages included a Steam user’s billing address, the last four digits of their Steam Guard phone number, their purchase history, the last two digits of their credit card number, and/or their email address. These cached requests did not include full credit card numbers, user passwords, or enough data to allow logging in as or completing a transaction as another user.

If you did not browse a Steam Store page with your personal information (such as your account page or a checkout page) in this time frame, that information could not have been shown to another user.

Valve is currently working with our web caching partner to identify users whose information was served to other users, and will be contacting those affected once they have been identified. As no unauthorized actions were allowed on accounts beyond the viewing of cached page information, no additional action is required by users.

The Steam Store was the target of a DoS attack which prevented the serving of store pages to users. Attacks against the Steam Store, and Steam in general, are a regular occurrence that Valve handles both directly and with the help of partner companies, and typically do not impact Steam users. 

In response to this specific attack, caching rules managed by a Steam web caching partner were deployed in order to both minimize the impact on Steam Store servers and continue to route legitimate user traffic. During the second wave of this attack, a second caching configuration was deployed that incorrectly cached web traffic for authenticated users. This configuration error resulted in some users seeing Steam Store responses which were generated for other users.

Once this error was identified, the Steam Store was shut down and a new caching configuration was deployed. 

We apologize to everyone whose personal information was exposed by this error, and for interruption of Steam Store service.

Well, good on them for coming clean. I only hope that they reach out to those who were affected, and work with them to secure their information and data.


Tagged With: , ,

Amazing Articles You Might Want To Check Out!

Keep On Reading!

PS6 Portable Has a 15W 3nm SoC, Runs PS5 Games in Lower Resolution – Rumor

PS6 Portable Has a 15W 3nm SoC, Runs PS5 Games in Lower Resolution – Rumor

The handheld's performance is allegedly "somewhere between Xbox Series S and PS5" and "tapes out" a few months...

Clair Obscur: Expedition 33, Towerborne, Dredge, and More Headline Game Pass in Late April/Early May

Clair Obscur: Expedition 33, Towerborne, Dredge, and More Headline Game Pass in Late April/Early May

Titles like Sniper Elite 5, The Last Case of Benedict Fox, Kona 2: Brume, and Have a Nice Death will leave the...

Skull and Bones Kicks Off Year 2 Season 1 With Major Content Update

Skull and Bones Kicks Off Year 2 Season 1 With Major Content Update

The second year of Skull and Bones is kicking things off with a host of new content, including a new ship and ...

Destiny 2: The Edge of Fate Reveal Announced for May 6th

Destiny 2: The Edge of Fate Reveal Announced for May 6th

Bungie is seemingly gearing up to reveal the next expansion for its looter shooter, which is scheduled to drop...

Baldur’s Gate 3 – Patch 8 is Out Now on Consoles and PC

Baldur’s Gate 3 – Patch 8 is Out Now on Consoles and PC

The final update for Larian Studios' critically acclaimed D&D role-playing game adds Photo Mode, cross-play, n...

Warhammer 40,000: Space Marine 2 Patch 7.0 Out Now, Includes New Boss Fight and Weapon

Warhammer 40,000: Space Marine 2 Patch 7.0 Out Now, Includes New Boss Fight and Weapon

The update includes a new PvE mission that pits players against a fearsome new boss as they try and rescue a T...