Status
Not open for further replies.

Addressing the recent user account hack scare

Dear GBAtemp members and visitors,

It has come to our attention that over the past two days, a person has somehow been able to access a few user accounts on our forums. Shortly after, rumors started blossoming regarding a possible site/forum/database hack or a password leak. After an extensive search into server logs and lookup tools we have no reason to believe that any part of our site has been compromised.

At this point, as several people have suggested already, we believe that the reason this intrusion happened is because another site (an illegal ROM/ISO download site) was recently hacked and the password database was exposed to the public. Since a portion of our members was also registered on that site, possibly using the same password, this could explain the recent scare.

Even though we have no reason to believe our site has been compromised, we have taken a series of measures to reinforce account security on GBAtemp. Firstly, we have reviewed security on the server and all components of our site to make sure everything is up to date and secure. Some components of the forum software have been updated and following this update, one or two add-ons have ceased functioning. If you see anything that isn't working as expected, please use our Site discussions and suggestions forum to report the issue.

At this point, we recommend all our members to change their password and enable two-factor authentication. We are sending out e-mails to all our members to inform them of this situation and to recommend them to change their password. We strongly recommend using a unique and complex password, not just here but on every site you are registered to.

If you have any information that may help us get a better grasp on the situation, please get in touch with a member of the staff. Thank you for your understanding!

The staff
 

Patxinco

Riding a Shooting Star
Member
Joined
Apr 18, 2011
Messages
847
Trophies
1
XP
2,227
Country
Spain
Wow, first notice about the issue, hope the hacked accounts get back to his original owners...

As someone suggests up here, get a pasword manager, it's just 1 minute more and it's hella secure, or get the 2FA too

Thanks @Costello for your information, some forum admins should learn from you...
 

MarioMasta64

hi. i make batch stuff and portable shiz
Member
Joined
Dec 21, 2016
Messages
2,297
Trophies
0
Age
26
Website
github.com
XP
2,094
Country
United States
Wow, first notice about the issue, hope the hacked accounts get back to his original owners...

As someone suggests up here, get a pasword manager, it's just 1 minute more and it's hella secure, or get the 2FA too

Thanks @Costello for your information, some forum admins should learn from you...
here have some safety rJOK12G7aM7424Rg1%MI (i agree)
 
  • Like
Reactions: Patxinco

MarioMasta64

hi. i make batch stuff and portable shiz
Member
Joined
Dec 21, 2016
Messages
2,297
Trophies
0
Age
26
Website
github.com
XP
2,094
Country
United States
i just got logged out o.o also apparently powerfirm is an older version of a9lh so meh some powerfirm / rxtools fanboy seems to hate that a9lh and luma3ds took its place.
 

vedekandy

Member
Newcomer
Joined
Jul 5, 2007
Messages
11
Trophies
0
XP
230
Country
Netherlands
Thanks for the heads up - this kind of thing happens all over the place all the time, but at least they're good enough here to warn us/keep us informed. Easier to spend 2 minutes changing a password now than getting screwed over later down the line without knowing!
 

MarioMasta64

hi. i make batch stuff and portable shiz
Member
Joined
Dec 21, 2016
Messages
2,297
Trophies
0
Age
26
Website
github.com
XP
2,094
Country
United States
Thanks for the heads up - this kind of thing happens all over the place all the time, but at least they're good enough here to warn us/keep us informed. Easier to spend 2 minutes changing a password now than getting screwed over later down the line without knowing!
indeed,
 

Sonic Angel Knight

Well-Known Member
Member
Joined
May 27, 2016
Messages
14,397
Trophies
1
Location
New York
XP
12,922
Country
United States
I was about to question why the site has two administrators, but now i don't think i should, is obvious for help. Just not many sites i know have more than one on the same rank.:unsure:
 

JordenNixNix

Well-Known Member
Member
Joined
Feb 11, 2012
Messages
233
Trophies
0
XP
275
Country
Belgium
Thanks for the mail to inform me about the problem.
How can I change my password when I used to login with Facebook on this site?

If I go to two-side verification panel, I must give my current password, but It always fails. (even when I give in my Facebook password).
Is there an alternative to change my password + since I login with Facebook, is my Facebook-page vulnerable as well?
 

InsaneNutter

Well-Known Member
Member
Joined
Dec 26, 2007
Messages
1,080
Trophies
2
Age
37
Location
Yorkshire, UK
Website
digiex.net
XP
3,187
Country
You really should have a unique password for everything you sign up to online. That way if a site gets hacked such as a forum its not a big deal to you personally, change your password and move on.

You can also enter your email address on https://haveibeenpwned.com/ and it will show you which data breaches your email address / password have been included in.

For some context i've been included in some pretty large data breaches:
  • Adobe
  • Dropbox
  • Epic Games
  • MoDaCo
  • OVH
  • Plex
  • Trillian
  • vBulletin
If it can happen to Adobe and Dropbox, then it could happen to anyone.

Enabling Two Factor Authentication on modern sites which support is really helps too, even if someone obtains your username and password its pretty much useless to them unless you use the same password everywhere.
 
  • Like
Reactions: atomsk

MarioMasta64

hi. i make batch stuff and portable shiz
Member
Joined
Dec 21, 2016
Messages
2,297
Trophies
0
Age
26
Website
github.com
XP
2,094
Country
United States
Thanks for the notice. Make sure you use different passwords for each site. @Costello any chance of enabling 2-factor on the site?
its already enabled goto settings.

--------------------- MERGED ---------------------------

You really should have a unique password for everything you sign up to online. That way if a site gets hacked such as a forum its not a big deal to you personally, change your password and move on.

You can also enter your email address on https://haveibeenpwned.com/ and it will show you which data breaches your email address / password have been included in.

For some context i've been included in some pretty large data breaches:
  • Adobe
  • Dropbox
  • Epic Games
  • MoDaCo
  • OVH
  • Plex
  • Trillian
  • vBulletin
If it can happen to Adobe and Dropbox, then it could happen to anyone.

Enabling Two Factor Authentication on modern sites which support is really helps too, even if someone obtains your username and password its pretty much useless to them unless you use the same password everywhere.

i see .3.
 

Attachments

  • Screenshot from 2017-01-12 04-22-35.png
    Screenshot from 2017-01-12 04-22-35.png
    97.6 KB · Views: 160

MarioMasta64

hi. i make batch stuff and portable shiz
Member
Joined
Dec 21, 2016
Messages
2,297
Trophies
0
Age
26
Website
github.com
XP
2,094
Country
United States
Everyone except me it seems.
Maybe it would help if you all posted in the thread for the issue your OS and Browser + version
Might help pin down the cause.
Linux Mint 18.1 latest firefox (it didnt happen till after the breach) im assuming the reloaded the site as alot of the layouts and such have turned like the old-er gbatemp
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Look at you holding tiny things