Seems info leaked by DLH is still having effects. The DLH site hacking that led to Russian hackers stealing email id and their DLH accounts and steam keys associated with these accounts means they have email ids and tentative passwords now and if same type of passwords are being used at steam/twitch/bundlesites etc they are all at risk as the hackers are trying to access those. Many users still getting steam cd query attempts at protected accounts [Leaked DLH cd keys to blame] . Now anyone who hasn't changed same used passwords at other accounts like sites/twitch etc are getting hacked wherever possible. Many people now have Twitch accounts compromised with attempts to hack or successful hack. Many users now getting emails by twitch of the same and some reportedly have already lost their accounts.

Change PWs of all your steam associated site accounts used to take free game keys at GAs and sites.

7 years ago*

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

7 years ago
Permalink

Comment has been collapsed.

Same, looks like give more information so everyone understand whats going on is hard...

7 years ago
Permalink

Comment has been collapsed.

Edited and explained in detail.

7 years ago
Permalink

Comment has been collapsed.

That peps logins have been leaked.
And now those accounts that have been leaked has been compromised aka hacked by another person.

7 years ago
Permalink

Comment has been collapsed.

Edited and explained in detail.

7 years ago
Permalink

Comment has been collapsed.

Oh... so maybe that explains why I have been occasionally getting CD query mails recently. I was wondering if I had ninjaed a key and forgot to say Thank you :D

7 years ago
Permalink

Comment has been collapsed.

^

7 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 4 years ago.

7 years ago
Permalink

Comment has been collapsed.

I just got one of those today and was wondering what the story was. This must be it. Good to know, and my password shouldn't be used anywhere else so I hope all my other accounts will be okay. :)

7 years ago
Permalink

Comment has been collapsed.

yeah, I got 2 and was worried!!

7 years ago
Permalink

Comment has been collapsed.

yeop.. i had both my bundlestars and my twitch hacked due to them being same info as dlh. tis a serious one.

7 years ago
Permalink

Comment has been collapsed.

Why keep the same password on any two sites in the age where there are several easy-to-use freeware password managers.

7 years ago
Permalink

Comment has been collapsed.

True, although they don't store master passwords at least. I changed mine after the news, but mine is 31 characters long and vocabulary-proof, so good luck to anyone trying to brute-force it. :D

7 years ago
Permalink

Comment has been collapsed.

yeah, there is certainly no doubt it's more secure then using the same ol' regular password over and over. that's for sure. ^^

7 years ago
Permalink

Comment has been collapsed.

I thought I guessed it, but what I have in my head for mine is only 30 characters.
I bet yours could be bruteforced, just like mine can. We probably think alike so all I would need to do is load a specialized library of certain phrases.

7 years ago
Permalink

Comment has been collapsed.

I doubt. I check the passwords I need to memorise and they are all words that don't exist in any language.

7 years ago
Permalink

Comment has been collapsed.

Frell!
Words that don't exist in our language makes it even more likely to be something I'm thinking of.
Speech in an alien language that can be spoken in English.

7 years ago
Permalink

Comment has been collapsed.

Eh, I mean in any natural or constructed language. Or, to be more understandable, they are google-proof, as no hits come up even if you search in Klingon. :)

7 years ago
Permalink

Comment has been collapsed.

just by saying it is 31 characters, you have way more odd of finding it since we don't need to do 1-30 character pass word and 32 character + long

7 years ago
Permalink

Comment has been collapsed.

Local stored password manager (e.g. Keepass).

7 years ago
Permalink

Comment has been collapsed.

trojan gains access to computer (e.g. Netbus) ;)

7 years ago
Permalink

Comment has been collapsed.

Sure, there's always a way. I just can't believe why people are using or even paying for a cloud based password manager, even more if they reason it with website hacks.

7 years ago
Permalink

Comment has been collapsed.

lol, yeah. like you said though there is always a way, so it really doesn't matter which way you go about it. i mean chances are higher or lower with certain ways of going about it ofc, but overall it makes little diff imo. ^^

edit: there are still some people who get away with using "password" as their password globally and still have yet to have their accounts compromised, and then there are those who use a full 128bit key as their password and consistently are being compromised.

7 years ago*
Permalink

Comment has been collapsed.

I prefer to have a unique password for every account (common sense) and I either memorize them (such as the most commonly used ones) or jot them down in a notepad. Sure, someone could grab my notepad; however, someone hacking my notepad (without something akin to an axe) is... unlikely, lol.

7 years ago
Permalink

Comment has been collapsed.

Two site? I use one password for more than 20 sites and never been hacked -.-

7 years ago
Permalink

Comment has been collapsed.

thanks for the info.

7 years ago
Permalink

Comment has been collapsed.

I don't think people logging in via facebook on DLH are affected 'cause the site just gets some kind of token in addition to the email address as far as I know. ¯\_(ツ)_/¯

7 years ago
Permalink

Comment has been collapsed.

DLH gets what they deserve, you can blame hackers? ¯_(ツ)_/¯

7 years ago
Permalink

Comment has been collapsed.

Well, it's not DLH getting anything, it's the users. The worst that happened to DLH was embarrassment. For everyone else it could mean the loss of a Twitch account they've poured time into, loss of bundle keys or worse.

7 years ago
Permalink

Comment has been collapsed.

Well, if they have poured time into their Twitch account, they probably had some time to set up the two-factor login authentication there.

7 years ago
Permalink

Comment has been collapsed.

You say that, yet I know a lot of people, who lack the money to have a phone that can handle the two step verification.

7 years ago
Permalink

Comment has been collapsed.

Their 2FA uses SMS/text message. The cheapest few-dollar feature phone can receive those. :)

7 years ago
Permalink

Comment has been collapsed.

I meant phone service contract, my bad. :D
Basically for some services the actual service provider will charge you as well. And in my case, they do. And because it's not coming from my own country, they charge a fair bit. Google's message cost me around 20 cents. Since my budget for my phone bills is about 2-3€ per month, this is a large chunk out of it. And if I were to log in every day, which many people do, then it'd come to around 6€.

It might not sound much, but for someone like me, that's way too much :/

7 years ago
Permalink

Comment has been collapsed.

Charging for receiving SMS? o.0
But SMS is free as far as the system operator goes; they are sent in the control signal's holes so they don't cost any money. Charging anything to send them is bad enough but for taxing the receiver is blatant robbery.

7 years ago
Permalink

Comment has been collapsed.

Yup, I agree. It's really annoying.

7 years ago
Permalink

Comment has been collapsed.

ah, makes sense why i received an email from twitch saying someone in russia tried accessing my twitch account

7 years ago
Permalink

Comment has been collapsed.

i got one too

7 years ago
Permalink

Comment has been collapsed.

Thanks for the info !

7 years ago
Permalink

Comment has been collapsed.

Explains this:
Edit: That explain this:

Dear Steam user,
This is an automated message generated by Steam account administration. It is being sent in response to a query made by a Steam user to discover all account names associated with this CD key.

Steam account name: xxxxxxxx

If you requested this query, please use the above account name to log in to Steam. If you cannot remember your password, click on the “Retrieve lost account” button on the Steam login screen.

If you did not request this query, please ignore this message.

Users cannot gain access to your account via the Find Account By CD Key process without access to your email account.

7 years ago*
Permalink

Comment has been collapsed.

Someone knows a CD key of a game you used. He is trying to use it to know your account details or take control. CD key can be a publicly pasted cd key at forums you activated or ninjaed quickly or hacked from a site and hence someone knows the key was used somewhere. Or someone got a used dupe key in a GA and tried tracking account. DLH site hack meant Russians gained info of DLH stored use account names, email ids, passwords and cd keys of all their owned games obtained from DLH and used that info to try and hack anything they could - Steam, Twitch, DLH and other such bundle sites etc. Those exposed email ids and cd keys are still being sued to hack and gain control of steam accounts and hence such emails. Best way to be safe is ensure your email ids main, steam accounts and bundlesites accounts are phone verified and thus solely in your control.

7 years ago*
Permalink

Comment has been collapsed.

Oh, sorry. i'm not asking you to explain. I tried to say that your post explains that email i got from Steam.
Thanks anyway, xd. (not so good at english)

7 years ago
Permalink

Comment has been collapsed.

Its OK. Many people who don't know how it works will know. An additional explanation never harmed anyone. xD

7 years ago
Permalink

Comment has been collapsed.

Used, not sued.

7 years ago
Permalink

Comment has been collapsed.

Lmao they tried accessing my twitch,twitter and some months ago a random russian tried logging in my instagram aswell.... Even tho i have nothing on it,russians are apparently a pain even outside of csgo. BTW my password was randomly generated by dlh.

7 years ago
Permalink

Comment has been collapsed.

meh looks like someone tried to query up one of the steam codes I got from there.. guess I should change my password associated with my email just to be on the safe side, all my passwords are unique for any site I visit though so not too much cause for concern. I suppose if they want to hack my twitter account have at it, all I have on there is a bunch of stupid crap DLH or other giveaway sites requested that I post for my free key..

7 years ago
Permalink

Comment has been collapsed.

Joke on them ... my passowrds are what they gave me by default ...

7 years ago
Permalink

Comment has been collapsed.

I think I authenticated with my Facebook. There's no way they can steal my login info lmao.

7 years ago
Permalink

Comment has been collapsed.

Still unsafe. Delete DLH widget registered in FB app. I read somewhere that is the best course of action.

7 years ago
Permalink

Comment has been collapsed.

They can't intrude my Facebook app unless there's FB exploit, period. That's the benefit of connect feature, just like this site and Steam. If SG gets breached there's no way they can intrude to the respective Steam accounts as well.

If they breach DLH's database and gets my account (in DLH), then it's DLH problem, and that is affecting all DLH users not just people who authenticate with Facebook.

7 years ago
Permalink

Comment has been collapsed.

OK uhhh, what is DLH?

7 years ago
Permalink

Comment has been collapsed.

DLH.net game selling site.

7 years ago
Permalink

Comment has been collapsed.

Thanks, thought it might be an abbreviation for a place I may have used but I've never used them.

7 years ago
Permalink

Comment has been collapsed.

this may explain my twitch account getting hacked a few days ago

7 years ago
Permalink

Comment has been collapsed.

Thanks, i was wondering why someone tried accessing my twitch and getting cd key queries, even if they manage to successfully login to my twitch account, what the hell were they going to do with it anyway? watch a hearthstone stream with it? lol

7 years ago
Permalink

Comment has been collapsed.

Guys if i login with FB, can my account get compromised too (through DLH) ?

7 years ago
Permalink

Comment has been collapsed.

Got one of those mails because of a CD key but I have a completely different password, mail and name there.

7 years ago
Permalink

Comment has been collapsed.

Isn't this what happens after *any * site's username-pw database gets public, people try to use the combinations at other sites as well? The title makes it sound like DLC caused a vulnerability at twitch, while it's just careless users having the same / not changing passwords...

7 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.