{"id":7532,"date":"2016-08-12T05:08:03","date_gmt":"2016-08-12T09:08:03","guid":{"rendered":"https:\/\/kasperskydaily.com\/uk\/?p=7532"},"modified":"2019-11-22T10:09:48","modified_gmt":"2019-11-22T10:09:48","slug":"dota-2-hack","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.uk\/blog\/dota-2-hack\/7532\/","title":{"rendered":"Dota 2 forums leak 2 million passwords"},"content":{"rendered":"<p>On August 9, 2016, LeakedSource <a href=\"https:\/\/www.leakedsource.com\/blog\/dota\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">revealed<\/a> that almost 2,000,000 accounts on the <a href=\"http:\/\/dev.dota2.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">official Dot<\/a><a href=\"http:\/\/dev.dota2.com\/\" target=\"_blank\" rel=\"noopener nofollow\">a<\/a><a href=\"http:\/\/dev.dota2.com\/\" target=\"_blank\" rel=\"noopener nofollow\"> 2 forum<\/a> were compromised. What does that mean for you?<\/p>\n<p>If you are not into Dota 2, it won\u2019t affect you at all. But, given the stats, you\u2019ve probably played it at least once or twice. Dota 2 is one of the most popular online multiplayer games, with <a href=\"https:\/\/www.reddit.com\/r\/DotA2\/comments\/4nq2ix\/dota_2_now_has_over_13_million_active_monthly\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">more than 13,000,000<\/a> unique players per month and <a href=\"http:\/\/steamcharts.com\/app\/570#All\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">about 600,000<\/a> per day. For many, Dota 2 became synonymous with MOBA, aka Multiplayer Online Battle Arena, and Dota is probably the first thing that comes to mind when someone mentions online gaming.<\/p>\n<p>With so many players all over the world, it\u2019s not surprising that Dota 2 has a huge fan community. Fans don\u2019t just play the game, they also spend a lot of time talking about it and watching the championships. By the way, the main annual Dota 2 event, <a href=\"http:\/\/www.dota2.com\/international\/overview\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">The International<\/a>, is happening right now and has just reached semifinals stage. When we say Dota 2 is big, we mean really big: The prize pool for this year\u2019s The International is more than $20,000,000.<\/p>\n<p><strong>Passwords?<\/strong><\/p>\n<p>Where there is money, there are cyber-criminals. And so the Dota 2 official forum was hacked. It happened on July 10, 2016, and resulted in the leakage of a database with almost 2 million records containing user names and IDs, e-mails, IP addresses, and \u2014 you guessed it \u2014 passwords.<\/p>\n<p>The hack happened silently \u2014 nobody noticed it at the time, and the community didn\u2019t learn about until August 9, the second day of The International.<\/p>\n<p>Valve, the owner and creator of Dota 2, claims that the stolen database contains only forum accounts and that no Steam accounts were compromised. But Valve is still to blame for the incident: As the Inquirer <a href=\"http:\/\/www.theinquirer.net\/inquirer\/news\/2467582\/dota-2-dev-forum-breach-sees-two-million-user-records-lifted\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">notes<\/a>, the passwords were stored using MD5 hashing with salt, and MD5 is now widely considered outdated. Case in point: LeakedSource was able to convert over 80 per cent of the hacked passwords to their plain text values.<\/p>\n<p>The hack is bad on its own, but it could have even worse consequences. Users tend to reuse logins and passwords. Remember when Mark Zuckerberg\u2019s Twitter account was hijacked using the password that was leaked in the <a href=\"https:\/\/www.kaspersky.co.uk\/blog\/linkedin-password-leak\/7204\/\" target=\"_blank\" rel=\"noopener\">LinkedIn hack<\/a>? The same thing is bound to happen (or has already happened) here. Some of the user names and passwords on the forum probably match the user names and passwords for their Steam accounts. So we would not be surprised to see a spike in Steam account hijacking.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/Steam?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Steam<\/a> stealers: your account is their target: <a href=\"https:\/\/t.co\/37rshJ1Fay\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/37rshJ1Fay<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gaming?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#gaming<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gamesafe?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#gamesafe<\/a> <a href=\"https:\/\/t.co\/hqFzlrJvCa\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/hqFzlrJvCa<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/709740379223007232?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">March 15, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><strong>What if they get me?<\/strong><\/p>\n<p>We hope that nothing bad has happened to your accounts, but here are a few tips to ensure they continue to stay safe and sound.<\/p>\n<ol>\n<li>If you are a Dota 2 forum user, change your password there. Remember to make it <a href=\"https:\/\/password.kaspersky.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">strong enough<\/a>.<\/li>\n<\/ol>\n<ol start=\"2\">\n<li>Check to see if LeakedSource <a href=\"https:\/\/www.leakedsource.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">has information about your account<\/a>. If so, you\u2019ll probably want to delete it.<\/li>\n<\/ol>\n<ol start=\"3\">\n<li>If you have used the same password anywhere else, change all of your passwords. And learn how to handle them properly \u2014 we have a <a href=\"https:\/\/www.kaspersky.co.uk\/blog\/passwords-are-like-underwear\/6484\/\" target=\"_blank\" rel=\"noopener\">blog post<\/a> about that for you.<\/li>\n<\/ol>\n<ol start=\"4\">\n<li>To further protect your Steam account, enable two-factor authentication using <a href=\"https:\/\/support.steampowered.com\/kb_article.php?l=english&amp;ref=4020-ALZM-5519#enablephone\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Steam Guard<\/a>.<\/li>\n<\/ol>\n<ol start=\"5\">\n<li>After you have completed those four critical steps, it\u2019s a good idea to get educated about other threats in the world of computer games. We \u2014 wait for it \u2014 have <a href=\"https:\/\/www.kaspersky.co.uk\/blog\/steam-scam\/6774\/\" target=\"_blank\" rel=\"noopener\">a post about that<\/a> as well.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>A Dota 2 forum breach has leaked 2 million accounts. The consequences are meaningful.<\/p>\n","protected":false},"author":696,"featured_media":7533,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2026],"tags":[1584,163,1101,187,164,1585],"class_list":{"0":"post-7532","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-dota-2","10":"tag-gaming","11":"tag-leaks","12":"tag-passwords","13":"tag-steam","14":"tag-valve"},"hreflang":[{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/dota-2-hack\/7532\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/dota-2-hack\/7509\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/dota-2-hack\/7508\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/dota-2-hack\/8942\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/dota-2-hack\/8774\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/dota-2-hack\/12749\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/dota-2-hack\/2332\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/dota-2-hack\/12767\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/dota-2-hack\/5986\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/dota-2-hack\/5243\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/dota-2-hack\/8457\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/dota-2-hack\/12276\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/dota-2-hack\/12749\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/dota-2-hack\/12767\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/dota-2-hack\/12767\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.uk\/blog\/tag\/dota-2\/","name":"Dota 2"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/7532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=7532"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/7532\/revisions"}],"predecessor-version":[{"id":17668,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/7532\/revisions\/17668"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media\/7533"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=7532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=7532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=7532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}