Today i was added on Steam by a nice user who sent me my login info, password included, for Indiegala. It was apparently posted on some website i have never heard of (bhf.io) along with my Steam account name and maybe other info.
He said it is possibly because of this DLH.net info leak which i know nothing of, the leak, i mean.
Anyways, i changed my password there but i just wanted to leave what little info i have on the matter for you all. And if you have more info on the matter please share :)

6 years ago

Comment has been collapsed.

The DLH.net leak was in July 2016 and exposed 3.3M users, it included email adresses, passwords, birth dates and steam keys.
Source: HaveIBeenPwned.com

6 years ago
Permalink

Comment has been collapsed.

Thanks.
I guess i don't really see the correlation between DLH and Indie Gala but it was the info I was given..

6 years ago
Permalink

Comment has been collapsed.

Type in your email there and will list if it was in other things. I lost hundreds of games when my Indie Gala account was accessed.

6 years ago
Permalink

Comment has been collapsed.

Aww man that sucks.
Thankfully i don't have any unused keys or any useful CC info there.

6 years ago
Permalink

Comment has been collapsed.

The correlation is that too many people use the same email address and password for multiple web sites, so when one gets hacked, all their other accounts are also vulnerable. You should never use the same password on any site. Every password should be unique. Period. Use a password manager to keep track of them all, so you only have to remember one, a master password, in your head.

Also, on sites that provide the capability, turn on 2-factor Authentication (2FA). It adds an additional barrier to hackers, so that even if your password is compromised, they still can't log in.

6 years ago
Permalink

Comment has been collapsed.

You're right and it's great advice, i did receive an email from IG a few days ago saying that someone tried to login to my account, of course with their authenticator dealy, i was sent a "confirm it was me" code but at the time i dismissed the message, but kept it. Then after receiving the warning from this user, when I logged in to change the password the IP in the email was the same address as the unauthorized attempt so that is a bit confusing.

6 years ago*
Permalink

Comment has been collapsed.

I have heard about this from someone else about a week ago. The guy got added by a person, who told them the password they used on IndieGala (which is also the old password they used on some other sites). Probably the password was acquired from IndieGala or other sites. Site that has the password is bhf.io

6 years ago
Permalink

Comment has been collapsed.

Yeah, this person told me the info was posted on that site.

6 years ago
Permalink

Comment has been collapsed.

Closed 6 years ago by Sicknate.