{"id":12767,"date":"2016-08-12T09:00:59","date_gmt":"2016-08-12T13:00:59","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=12767"},"modified":"2019-11-15T06:54:33","modified_gmt":"2019-11-15T11:54:33","slug":"dota-2-hack","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/dota-2-hack\/12767\/","title":{"rendered":"DotA 2 forums leak 2 million passwords"},"content":{"rendered":"<p>On August 9, 2016, LeakedSource <a href=\"https:\/\/www.leakedsource.com\/blog\/dota\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">revealed<\/a> that almost 2,000,000 accounts on the <a href=\"http:\/\/dev.dota2.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">official Dota 2 forum<\/a> were compromised. What does that mean for you?<\/p>\n<p>If you are not into Dota 2, it won\u2019t affect you at all. But, given the stats, you\u2019ve probably played it at least once or twice. Dota 2 is one of the most popular online multiplayer games, with <a href=\"https:\/\/www.reddit.com\/r\/DotA2\/comments\/4nq2ix\/dota_2_now_has_over_13_million_active_monthly\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">more than 13,000,000<\/a> unique players per month and <a href=\"http:\/\/steamcharts.com\/app\/570#All\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">about 600,000<\/a> per day. For many, Dota 2 became synonymous with MOBA, aka Multiplayer Online Battle Arena, and Dota is probably the first thing that comes to mind when someone mentions online gaming.<\/p>\n<p>With so many players all over the world, it\u2019s not surprising that Dota 2 has a huge fan community. Fans don\u2019t just play the game, they also spend a lot of time talking about it and watching the championships. By the way, the main annual Dota 2 event, The International, is happening right now and has just reached semifinals stage. When we say Dota 2 is big, we mean really big: The prize pool for this year\u2019s The International is more than $20,000,000.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2016\/08\/06021730\/dota-2-live.jpg\"><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2016\/08\/06021730\/dota-2-live.jpg\" alt=\"DotA 2 forums leak 2 million passwords\" width=\"1280\" height=\"840\" class=\"aligncenter size-full wp-image-12768\"><\/a><\/p>\n<h3>Passwords? <a href=\"https:\/\/hydra-media.cursecdn.com\/dota2.gamepedia.com\/3\/38\/pud_ability_hook_04.mp3\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Get over here!<\/a><\/h3>\n<p>Where there is money, there are cybercriminals. And so the Dota 2 official forum was hacked. It happened on July 10, 2016, and resulted in the leakage of a database with almost 2 million records containing user names and IDs, e-mails, IP addresses, and \u2014 you guessed it \u2014 passwords.<\/p>\n<p>The hack happened silently \u2014 nobody noticed it at the time, and the community didn\u2019t learn about until August 9, the second day of The International.<\/p>\n<p>Valve, the owner and creator of Dota 2, claims that the stolen database contains only forum accounts and that no Steam accounts were compromised. But Valve is still to blame for the incident: As the Inquirer notes, the passwords were stored using MD5 hashing with salt, and MD5 is now widely considered outdated. Case in point: LeakedSource was able to convert over 80 per cent of the hacked passwords to their plaintext values.<\/p>\n<p>The hack is bad on its own, but it could have even worse consequences. Users tend to reuse logins and passwords. Remember when Mark Zuckerberg\u2019s Twitter account was hijacked using the password that was leaked in the <a href=\"https:\/\/www.kaspersky.com\/blog\/linkedin-password-leak\/12146\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn hack<\/a>? The same thing is bound to happen (or has already happened) here. Some of the user names and passwords on the forum probably match the user names and passwords for their Steam accounts. So we would not be surprised to see a spike in Steam account hijacking.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/Steam?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Steam<\/a> stealers: your account is their target: <a href=\"https:\/\/t.co\/37rshJ1Fay\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/37rshJ1Fay<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gaming?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#gaming<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gamesafe?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#gamesafe<\/a> <a href=\"https:\/\/t.co\/hqFzlrJvCa\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/hqFzlrJvCa<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/709740379223007232?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">March 15, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h3><a href=\"https:\/\/hydra-media.cursecdn.com\/dota2.gamepedia.com\/e\/e1\/Timb_move_07.mp3\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">What if they get me?<\/a><\/h3>\n<p>We hope that nothing bad has happened to your accounts, but here are a few tips to ensure they continue to stay safe and sound.<\/p>\n<p>1. If you are a Dota 2 forum user, change your password there. Remember to make it <a href=\"https:\/\/password.kaspersky.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">strong enough<\/a>.<\/p>\n<p>2. Check to see if LeakedSource <a href=\"https:\/\/www.leakedsource.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">has information about your account<\/a>. If so, you\u2019ll probably want to delete it.<\/p>\n<p>3. If you have used the same password anywhere else, change all of your passwords. And learn how to handle them properly \u2014 we have a <a href=\"https:\/\/www.kaspersky.com\/blog\/passwords-are-like-underwear\/10645\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">blog post<\/a> about that for you.<\/p>\n<p>4. To further protect your Steam account, enable two-factor authentication using <a href=\"https:\/\/support.steampowered.com\/kb_article.php?l=english&amp;ref=4020-ALZM-5519#enablephone\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Steam Guard<\/a>.<\/p>\n<p>5. After you have completed those four critical steps, it\u2019s a good idea to get educated about other threats in the world of computer games. We \u2014 <a href=\"https:\/\/hydra-media.cursecdn.com\/dota2.gamepedia.com\/6\/68\/Wdoc_killspecial_01.mp3\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">wait for it<\/a> \u2014 have <a href=\"https:\/\/www.kaspersky.com\/blog\/stealing-steam-accounts\/11560\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">a post about that<\/a> as well.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DotA 2 forum breach leaks 2 million accounts, probably has consequences<\/p>\n","protected":false},"author":696,"featured_media":12769,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[1767,647,961,187,164,1768],"class_list":{"0":"post-12767","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-dota-2","9":"tag-gamers","10":"tag-leaks","11":"tag-passwords","12":"tag-steam","13":"tag-valve"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/dota-2-hack\/12767\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/dota-2-hack\/7509\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/dota-2-hack\/7532\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/dota-2-hack\/7508\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/dota-2-hack\/8942\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/dota-2-hack\/8774\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/dota-2-hack\/12749\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/dota-2-hack\/2332\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/dota-2-hack\/5986\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/dota-2-hack\/5243\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/dota-2-hack\/8457\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/dota-2-hack\/12276\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/dota-2-hack\/12749\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/dota-2-hack\/12767\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/dota-2-hack\/12767\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/dota-2\/","name":"DotA 2"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/12767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=12767"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/12767\/revisions"}],"predecessor-version":[{"id":30188,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/12767\/revisions\/30188"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/12769"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=12767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=12767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=12767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}