More than 1 million accounts from retro gaming site Emuparadise compromised
Full article546 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
This breach only is the latest exposure of user information to affect a prominent gaming site.
A security incident at Emuparadise, a website where users can play classic video games, has exposed information belonging to 1.1 million accounts, according to breach-tracking site Have I Been Pwned.
An April 2018 breach on the vBulletin forum section of Emuparadise resulted in the compromising of 1.1 million email addresses, IP addresses, and username and passwords as salted MD5 hashes, according to a Have I Been Pwned announcement. The data was provided to Have I Been Pwned by DeHashed.com, which tracks when user credentials are exposed in large data breaches.
The 19-year-old Emuparadise has called itself “the biggest retro gaming website on Earth” by offering nostalgia-laced titles that debuted on old consoles like the Nintendo 64, Super Nintendo, Sega Genesis and others. Few details about the incident immediately were available, though Bleeping Computer reports that the data was for sale on the dark web dating back to January 2019, when it was paired with information apparently stolen from Minecraft databases, the online game Dueling Network, and a handful of other popular services.
The breach is only the latest to affect a prominent gaming site. The industry, with its large customer base and ever-growing list of popular sites, can be an appealing target for hackers.
https://twitter.com/Merilethal/status/1137715179343536128
Emuparadise did not respond to a request for comment Monday.
The security firm Check Point last year disclosed three vulnerabilities to Epic Games, maker of the hugely popular “Fortnite.” Attackers could have exploited weaknesses in Fortnite’s single sign-on protocol to steal a user’s access token, potentially rendering millions of accounts vulnerable. Hackers could have abused this account access to make in-game purchases and monitor players in their homes without detection, according to Check Point. The bugs were patched within weeks.
In January, a hack at Town of Salem, a browser-based role playing game, involved more than 7.6 million email addresses. Information apparently pilfered from that game also was included in the files for sale on the dark web.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/emuparadise-breach-retro-gaming-site-have-i-been-pwned/