89 Million Steam Accounts at Risk of Hackers' Ploys

A report suggests that the details of 89 million Steam accounts are up for sale on the dark web, with hackers potentially exploiting accounts without two-factor authentication or those with unchanged passwords. This could lead to users losing access to their collection of PC games, receiving phishing messages, or having their accounts hijacked. The information comes from a LinkedIn post by Underdark AI, referencing a post on a black market forum by Machine1337, who allegedly offered the account details for $5,000.

Key Takeaways:

  • The alleged Steam data breach involves 89 million user records, roughly two-thirds of all Steam accounts, being sold for over $5,000 on a black market forum.
  • The breach is attributed to an external service that Steam relies on, Twilio, being targeted, rather than a direct breach of Steam itself.
  • The leaked data includes real-time SMS logs, message contents, delivery status, metadata, and routing costs related to two-factor authentication (2FA) codes.
  • The attackers have backend access to Twilio's systems, likely through a compromised Twilio user account or API key, allowing them to send phishing messages or intercept 2FA codes.
  • Users without two-factor authentication, or with unchanged passwords, are at a higher risk of having their accounts accessed or hijacked.
  • The Steam community has been warned about the breach, and users are advised to enable two-factor authentication, monitor their email for suspicious activity, change their Steam password, and beware of phishing attempts.

Statistics:

  • 89 million: The number of Steam accounts potentially at risk due to the alleged data breach.
  • $5,000: The price allegedly offered by the black market forum user, Machine1337, for the 89 million Steam account details.
  • 2/3: The proportion of Steam accounts reportedly affected by the breach.
  • 643 million: The total number of Steam accounts, used to calculate the impact of the breach (Source: Steam Community).
  • 2-factor authentication (2FA): A security measure that uses a second form of verification, such as a code sent to a user's phone via SMS, to protect accounts from unauthorized access.

Sources:

  • Underdark AI's LinkedIn post referencing the black market forum post by Machine1337.
  • MellowOnline1's X post on the alleged Steam data breach and advice for keeping accounts safe.
  • Steam Sentinels post on the alleged Steam data breach and actions to take to protect accounts.
  • TechRaptor's news article on the discovery of a shady Russian market for asset-flip games.