Status
Not open for further replies.

Addressing the recent user account hack scare

Dear GBAtemp members and visitors,

It has come to our attention that over the past two days, a person has somehow been able to access a few user accounts on our forums. Shortly after, rumors started blossoming regarding a possible site/forum/database hack or a password leak. After an extensive search into server logs and lookup tools we have no reason to believe that any part of our site has been compromised.

At this point, as several people have suggested already, we believe that the reason this intrusion happened is because another site (an illegal ROM/ISO download site) was recently hacked and the password database was exposed to the public. Since a portion of our members was also registered on that site, possibly using the same password, this could explain the recent scare.

Even though we have no reason to believe our site has been compromised, we have taken a series of measures to reinforce account security on GBAtemp. Firstly, we have reviewed security on the server and all components of our site to make sure everything is up to date and secure. Some components of the forum software have been updated and following this update, one or two add-ons have ceased functioning. If you see anything that isn't working as expected, please use our Site discussions and suggestions forum to report the issue.

At this point, we recommend all our members to change their password and enable two-factor authentication. We are sending out e-mails to all our members to inform them of this situation and to recommend them to change their password. We strongly recommend using a unique and complex password, not just here but on every site you are registered to.

If you have any information that may help us get a better grasp on the situation, please get in touch with a member of the staff. Thank you for your understanding!

The staff
 
I'm not having this issue.
upload_2017-1-12_7-57-18.png
 
Maybe the people with compromised accounts should have their original account banned and can have a new one?
No, I don't think that's a good solution. They'd have to start from scratch, which I don't think many people would want to do...
 
No, I don't think that's a good solution. They'd have to start from scratch, which I don't think many people would want to do...
Carry over ranks/post count? Better than having an account that isn't useable.
 
things like this and the aurora wright github for Luma3DS are what i warned @ShinyMK about with his forced auto-updater
 
as I said in the OP -

Some components of the forum software have been updated and following this update, several addons have ceased functioning. If you see anything that isn't working as expected, please use our Site discussions and suggestions forum to report the issue.
 
I'd suggest people start using a password manager of some kind which supports a password generator.

It may make life a bit harder, but at least it reduces the risk of a hacked site causing worse issues elsewhere.
 
thank you for confirmation.

I should routinely lookup my password account before too late to take action. 2 month ago someone trying logging one of my email account (1 attempt failed, 1 logged), is my fault still used old password (main cause come from leaked data from pp.org and that iso site). i not too worry about it since that email only store my old stuff (not really important) and not compromised my primary account.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum