Possible data breach

Announcements made here about the game and the company.

Re: Possible data breach

Postby flossiebell » Wed Jan 02, 2019 2:46 pm

So our payment information is safe, right? All we have to do is change our Town of Salem password? All of this is making me very nervous... :?
flossiebell
Newbie
Newbie
 
Posts: 2
Joined: Sat Mar 28, 2015 5:58 am

Re: Possible data breach

Postby Achilles » Wed Jan 02, 2019 2:47 pm

TurdPile wrote:
Tusillody wrote:
shapesifter13 wrote:We never saw an email from dehashed. We looked at our email account, and saw nothing from them.



Really? I mean, really?


Achilles wrote:
I'm sorry that this all happened and wasn't responded to quickly enough but people were on vacation spending time with their families (and his emails went to our spam filter).


This dev team's damage control is about as good as their security.


There's two different timelines here that you guys are mixing up. When it was first mentioned, they saw no emails; ergo, they never saw the email. The emails were only seen last night after really digging for it, and it was found to be in the spam folder; I mean... how often do you check your spam folder? I check mine maybe twice a month... if that.

The timeline is this:
1. Called by a sketchy private number that wouldn't speak over voice and only via email, claiming U GOT HAXED! (man, if I had a dollar for every email that said I got hacked... I'd be rich).
2. Doesn't get an email (didn't check spam, obviously). Chalked it up to yet another scammer try to extort money.
3. Breach is publicized.
4. Scrutinizing the email inbox, they find them tucked away in spam. (I personally confirmed that pwn and dehashed by default both went to my junk folder. I use hotmail, they use gmail).
5. Now they are aware of the legitimacy of the breach.

This is what I'm gathering the timetable to be, feel free to correct me Blake/Josh/Brandon if this is incorrect.


Yeah exactly what happened. In hindsight definitely wish I had checked the spam folder and regret how everything turned out.
User avatar
Achilles
Developer
Developer
 
Posts: 1038
Joined: Sat Feb 08, 2014 5:02 pm

Re: Possible data breach

Postby Alicitzen » Wed Jan 02, 2019 2:48 pm

BrainDeadRaven378 wrote:But is my money and all that safe?

Even the slightest bit of looking at what got out would tell you.
Discord: Alicitzen#1312
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
User avatar
Alicitzen
Valentines 2017
Valentines 2017
 
Posts: 7991
Joined: Mon Mar 10, 2014 10:56 am
Location: Chaldea

Re: Possible data breach

Postby shapesifter13 » Wed Jan 02, 2019 2:55 pm

We are working to send emails out to all the users affected currently.
shapesifter13
Developer
Developer
 
Posts: 4681
Joined: Fri Jan 02, 2015 4:55 pm

Re: Possible data breach

Postby Varanus » Wed Jan 02, 2019 2:55 pm

CatgirlMaple wrote:Also every time I navigate to a new page my browser tries to download a .swf file from this site

What the fuck

Embedded youtube video in Dash's sig
You were expecting a decent signature...

BUT IT WAS ME! DIO!
User avatar
Varanus
FM Lead Moderator
FM Lead Moderator
 
Posts: 698
Joined: Fri Mar 06, 2015 10:08 am
Location: Lurking

Re: Possible data breach

Postby TurdPile » Wed Jan 02, 2019 2:56 pm

CatgirlMaple wrote:Also every time I navigate to a new page my browser tries to download a .swf file from this site

What the fuck


Yeah a particular browser tries to download a youtube video from someone's signature.

EDIT: Apparently Dash's
I have mostly rescinded my role as Admin.

All previous contact should instead be redirected to Flavorable.

If your inquiry doesn't directly have to do with Trial 2.0 or TrialBot, then please refrain from messaging.

Thank you.
User avatar
TurdPile
Vampire
Vampire
 
Posts: 8900
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Possible data breach

Postby Alicitzen » Wed Jan 02, 2019 3:01 pm

CatgirlMaple wrote:
KatiyaKramer wrote:
CatgirlMaple wrote:It's been a week since thus event occurred and I've yet to receive an email from BlankMediaGames informing me that my data is compromised.

What's up guys?

They only just learned about the breach overnight and are investigating it and preparing for an email. There have been developer updates throughout the thread that have stated this exact information.

Cool. I should have received an email last night.

I just heard that my password was compromised from this website just half an hour ago by someone banned from this website.

ohhh noooo the amount of characters in your password got leeeaaakkkeeddd what ever are yooouuu to dooooooo
oh wait even with that there like shit all that can be done with it you would actually need to worry about


CatgirlMaple wrote:And this dash person should change their signature to something that doesn't download files to peoples computers?

use a better browser
Discord: Alicitzen#1312
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
User avatar
Alicitzen
Valentines 2017
Valentines 2017
 
Posts: 7991
Joined: Mon Mar 10, 2014 10:56 am
Location: Chaldea

Re: Possible data breach

Postby TurdPile » Wed Jan 02, 2019 3:02 pm

CatgirlMaple wrote:And this dash person should change their signature to something that doesn't download files to peoples computers?


It's not a signature issue, its an issue with your browser not wanting to play youtube videos for whatever reason. Guessing your browser isn't up to date.
I have mostly rescinded my role as Admin.

All previous contact should instead be redirected to Flavorable.

If your inquiry doesn't directly have to do with Trial 2.0 or TrialBot, then please refrain from messaging.

Thank you.
User avatar
TurdPile
Vampire
Vampire
 
Posts: 8900
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Possible data breach

Postby S0me0ne23 » Wed Jan 02, 2019 3:04 pm

CatgirlMaple wrote:And this dash person should change their signature to something that doesn't download files to peoples computers?

dash is jord btw
User avatar
S0me0ne23
Lookout
Lookout
 
Posts: 83
Joined: Fri Dec 05, 2014 10:25 pm

Re: Possible data breach

Postby Alicitzen » Wed Jan 02, 2019 3:07 pm

Dash2 wrote:
CatgirlMaple wrote:And this dash person should change their signature to something that doesn't download files to peoples computers?

Yeah totally my fault for using the YouTube tag 4Head

:roflcopter: @turdpile
why isnt 4Head in the emotes yanked from twitch
Discord: Alicitzen#1312
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
User avatar
Alicitzen
Valentines 2017
Valentines 2017
 
Posts: 7991
Joined: Mon Mar 10, 2014 10:56 am
Location: Chaldea

Re: Possible data breach

Postby TurdPile » Wed Jan 02, 2019 3:18 pm

Alicitzen wrote:
Dash2 wrote:
CatgirlMaple wrote:And this dash person should change their signature to something that doesn't download files to peoples computers?

Yeah totally my fault for using the YouTube tag 4Head

:roflcopter: @turdpile
why isnt 4Head in the emotes yanked from twitch


Funny enough, I was thinking the same thing
I have mostly rescinded my role as Admin.

All previous contact should instead be redirected to Flavorable.

If your inquiry doesn't directly have to do with Trial 2.0 or TrialBot, then please refrain from messaging.

Thank you.
User avatar
TurdPile
Vampire
Vampire
 
Posts: 8900
Joined: Tue Feb 11, 2014 10:25 am
Location: Massachusetts

Re: Possible data breach

Postby lalasex » Wed Jan 02, 2019 3:40 pm

LMAO why this gets attacked? Like those spambots and NOW THIS


probs because this game have worst community ever tbh
RIP Town of Salem 2017-2018

You will not be remembered


Image
User avatar
lalasex
Transporter
Transporter
 
Posts: 103
Joined: Mon May 14, 2018 5:15 am
Location: Russia

Re: Possible data breach

Postby YFYDB » Wed Jan 02, 2019 3:59 pm

oki guys.
I have a question related to the stolen data.

If i have purchased something, what kind of data do the hackers have? What exactly? What is my bank-number (anyhow it's called), that is just the number, that you need to pay me, but nothing more; the report of the payment; the easy way how to get into my bank account?
My avatar is a random picture found in the internet.
User avatar
YFYDB
Witch
Witch
 
Posts: 41
Joined: Thu Aug 03, 2017 9:08 am

Re: Possible data breach

Postby ICECLIMBERS » Wed Jan 02, 2019 4:07 pm

what a quality thread
Spoiler: Image

in the distance the shelves
rode three shadows of blue
User avatar
ICECLIMBERS
[Forum Mafia VII] Winner
[Forum Mafia VII] Winner
 
Posts: 3080
Joined: Wed Nov 19, 2014 11:50 pm
Location: Eastern Time

Re: Possible data breach

Postby YFYDB » Wed Jan 02, 2019 4:14 pm

Ooff, it's a good news.

But... Well then, i am a paranoic. Okey, they have exact info about my account inside the game. Activity info if i remember the name well. So, is it possible, that if a player played several hundreds of games, they might analize the data against hacked player and use the info from analyse to blackmail?


Well, it makes sense. You might have revealed some mental diseases while playing, but no one cared, and now hackers put it all together, and blackmail you by your e-mail (spam emails).
My avatar is a random picture found in the internet.
User avatar
YFYDB
Witch
Witch
 
Posts: 41
Joined: Thu Aug 03, 2017 9:08 am

Re: Possible data breach

Postby Varanus » Wed Jan 02, 2019 4:16 pm

I guess factory resetting is one way of making sure your browser is updated
You were expecting a decent signature...

BUT IT WAS ME! DIO!
User avatar
Varanus
FM Lead Moderator
FM Lead Moderator
 
Posts: 698
Joined: Fri Mar 06, 2015 10:08 am
Location: Lurking

Re: Possible data breach

Postby ICECLIMBERS » Wed Jan 02, 2019 4:24 pm

Most users ever online was 9984 on Wed Jan 02, 2019 3:39 pm

ok then

so when you send the email to everybody informing them of this (NUDGE) can you not include a link to this i don't want to die under heavy traffic
Spoiler: Image

in the distance the shelves
rode three shadows of blue
User avatar
ICECLIMBERS
[Forum Mafia VII] Winner
[Forum Mafia VII] Winner
 
Posts: 3080
Joined: Wed Nov 19, 2014 11:50 pm
Location: Eastern Time

Re: Possible data breach

Postby LevinSnakesRise » Wed Jan 02, 2019 4:24 pm

YFYDB wrote:Ooff, it's a good news.

But... Well then, i am a paranoic. Okey, they have exact info about my account inside the game. Activity info if i remember the name well. So, is it possible, that if a player played several hundreds of games, they might analize the data against hacked player and use the info from analyse to blackmail?


Well, it makes sense. You might have revealed some mental diseases while playing, but no one cared, and now hackers put it all together, and blackmail you by your e-mail (spam emails).

I doubt that the amount of games you have, TP, MP, etc would be of any value to anyone.
Please contact BMG with any questions regarding your account issues;
support@blankmediagames.zendesk.com

Thanks.
User avatar
LevinSnakesRise
Site Admin
Site Admin
 
Posts: 16789
Joined: Thu Aug 07, 2014 9:45 pm
Location: USA

Re: Possible data breach

Postby ICECLIMBERS » Wed Jan 02, 2019 4:27 pm

ICECLIMBERS wrote:
Most users ever online was 9984 on Wed Jan 02, 2019 3:39 pm

ok then

so when you send the email to everybody informing them of this (NUDGE) can you not include a link to this i don't want to die under heavy traffic

OK nevermind, I don't see a notification in game so ???
Spoiler: Image

in the distance the shelves
rode three shadows of blue
User avatar
ICECLIMBERS
[Forum Mafia VII] Winner
[Forum Mafia VII] Winner
 
Posts: 3080
Joined: Wed Nov 19, 2014 11:50 pm
Location: Eastern Time

Re: Possible data breach

Postby LevinSnakesRise » Wed Jan 02, 2019 4:28 pm

ICECLIMBERS wrote:
ICECLIMBERS wrote:
Most users ever online was 9984 on Wed Jan 02, 2019 3:39 pm

ok then

so when you send the email to everybody informing them of this (NUDGE) can you not include a link to this i don't want to die under heavy traffic

OK nevermind, I don't see a notification in game so ???

I'm assuming DDoS is taking place, as cloudflare protection kicked in.

Unless they're pooling everyone's emails together to send out mass emails, and it triggered the protection. Doubtful, but an even more reasonable explanation would be everyone accessing it at once.
Please contact BMG with any questions regarding your account issues;
support@blankmediagames.zendesk.com

Thanks.
User avatar
LevinSnakesRise
Site Admin
Site Admin
 
Posts: 16789
Joined: Thu Aug 07, 2014 9:45 pm
Location: USA

Re: Possible data breach

Postby JamesD28 » Wed Jan 02, 2019 4:31 pm

⚠ Not secure | blankmediagames.com/phpbb/index.php

Has the site always been not secure or is it getting pwned again?
I swear I remember this place normally having a certificate
Image

I can't find my FM record
You probably don't care anyway
User avatar
JamesD28
[Forum Mafia XIV] Winner
[Forum Mafia XIV] Winner
 
Posts: 1870
Joined: Mon Aug 01, 2016 1:30 pm

Re: Possible data breach

Postby flossiebell » Wed Jan 02, 2019 4:33 pm

Dash2 wrote:All payments go through PayPal so it's not like they know any of that stuff unless they conveniently decide to hack PayPal


What if we pay through Apple? Will our Apple information be safe as well?
flossiebell
Newbie
Newbie
 
Posts: 2
Joined: Sat Mar 28, 2015 5:58 am

Re: Possible data breach

Postby maggieryan27 » Wed Jan 02, 2019 4:34 pm

So what can someone do with my IP, I know it has my location and stuff but is there any way I can protect it without a VPN?
maggieryan27
Newbie
Newbie
 
Posts: 1
Joined: Mon Jul 03, 2017 11:26 am

Re: Possible data breach

Postby LevinSnakesRise » Wed Jan 02, 2019 4:40 pm

maggieryan27 wrote:So what can someone do with my IP, I know it has my location and stuff but is there any way I can protect it without a VPN?

Depends on if you have a static IP or not. If you unplug your modem and wait a few minutes, then you can check and see if your IP has been changed. If so, then you don't really need to do anything otherwise to change it.

You also can use proxies, but I wouldn't rely on them. and they don't offer what VPNs do.
Please contact BMG with any questions regarding your account issues;
support@blankmediagames.zendesk.com

Thanks.
User avatar
LevinSnakesRise
Site Admin
Site Admin
 
Posts: 16789
Joined: Thu Aug 07, 2014 9:45 pm
Location: USA

Re: Possible data breach

Postby Flavorable » Wed Jan 02, 2019 4:41 pm

maggieryan27 wrote:So what can someone do with my IP, I know it has my location and stuff but is there any way I can protect it without a VPN?


People can't do anything with your IP, except technically use your pc for a DDos attack if you have extremely lax router/modem security. Most ISPs use dynamic IP-addresses nowadays anyway, so if you don't feel secure, try contacting them and asking them how to reset your IP.
No reply to your support ticket after 15 business days? PM me with your ticket number.

You may PM me for clarifications on appeal verdicts, but keep in mind the verdict will not change.

Do you have 151+ games played and want to help rid the community of toxic players and gamethrowers? Join the Trial System today: https://www.blankmediagames.com/Trial/#start

Also, check out the Trial System Discord Server: https://discord.gg/K5SnyJS
User avatar
Flavorable
Global Moderator
Global Moderator
 
Posts: 9337
Joined: Thu Apr 28, 2016 3:24 am
Location: Netherlands

PreviousNext

Return to Announcements

Who is online

Users browsing this forum: No registered users and 13 guests