Battle.net Compromised, Blizzard Says Investigation Is Ongoing

by Mike Bendel on August 9, 2012 @ 3:44 pm


Blizzard’s issued a security announcement on Battle.net – the interconnected network that powers its Starcraft, Diablo, and Warcraft family of titles – stating that an intrusion has been identified by the company’s security team.

Currently, there’s no evidence to suggest that “financial information such as credit cards, billing addresses, or real names were compromised.” A list of email addresses for Battle.net users was accessed in all regions apart from China. Additionally, for North American accounts, the personal security question was accessed, along with information relating to Mobile and Dial-In Authenticators.

The breach also exposed “cryptographically scrambled versions of Battle.net passwords (not actual passwords) for players on North American servers.” The company is recommending that users change their password on Battle.net now as a precaution.

For those on North American servers, Blizzard says it will force a reset of all secret questions and answers through an automated process in the coming days. Mobile authenticator users will also be prompted to update their authenticator software.

The full statement is over on Blizzard’s site.

Follow this author on .

Read more: Watch_Dogs Dated for November 19 / 22, Rumor: Nvidia Readying GeForce Titan Ultra, Diablo III on the PS3: Reduced Mob Density, Rumor: Nvidia Prepping Slimmed Down GK110 With 5GB VRAM, Possible GTX 780?, Castlevania: Lords of Shadow Turns Up In Steam Registry Along With Achievements

Comments
FrozenIpaq says:

Considering the move to the Real-money auction house in D3 this was more or less going to happen at some point. Hopefully it's nothing too damaging.

This part infuriates me the most:

We also know that cryptographically scrambled versions of Battle.net passwords (not actual passwords) for players on North American servers were taken.

I'm tired of having my password stolen. This is about the 4rd - 5th time I've had my password compromised by a site.... I'm running out of passwords!

EDIT: And this happened on August 4th, and a ton of information was compromised. Great job Blizzard...really good job. Security Questions and Answers were also compromised (and those weren't hashed).

x3sphere says:

I'm surprised they left everything running when re-securing it. I mean, that's understandable if it's a minor thing but that doesn't seem to be the case here, considering what was accessed.

Also, yeah, 5 days to notify users... they probably wanted to determine the extent of the breach but still, seeing as Battle.net stores financial data, the turnaround time should have been quicker.

MenaceInc says:

Thankful that I've different passwords for everything >.<

Trigun says:

Oh Blizz

you say:

Login with your username and password below. New User?