Skip to content

EQ2Wire

EverQuest II News & Commentary

  • Home
  • Featured
    • EQ2Wire’s Kunark Ascending Frequently Asked Questions
    • Guide to Timed Quests in Thalumbra
    • EQ2Wire’s Beastlord Guide || Maximizing your Beastlord!
    • EQ2Wire’s Beastlord Warder Guide || A Field Guide to Warders
    • Guide Archive
      • EQ2Wire’s Terrors of Thalumbra Frequently Asked Questions
      • EQ2Wire Interview: Turning the Corner on Itemization in Tears of Veeshan
      • EQ2Wire Interviews EQ2 Lead Designer Kander
      • EQ2Wire’s Tears of Veeshan Frequently Asked Questions
      • EQ2U Reborn: A New Look and Feel for a New Expansion
      • EQ2Wire: Tears of Veeshan Heroic Zones Preview
      • EQ2Talk Interviews Kyle “Kander” Vallee || An EQ2Wire Transcript
      • Game Update 67: Saved AA Profiles & Advancement Templates
      • Chains of Eternity || Frequently Asked Questions & Zones
      • Chains of Eternity Armor Guide || Drinal’s Steward and Advanced Solo Gear
      • Skyshrine || Frequently Asked Questions & Zones
      • Destiny of Velious || Heroic Armor and Adornment Guide
      • Dethdlr’s Dungeon Group Setup Guide
  • Wire Network
    • Search for EQ2 Characters || EQ2U Advanced Character Search
    • Search for EQ2 Items || EQ2U Advanced Item Search
    • Search for EQ2 Guilds || EQ2U Advanced Guild Search
    • EQ2U: Gear Report for Characters, Guilds, and Alliances
    • Dethdlr’s Adornment Calculator V2
    • Contact Us || EQ2Wire and EQ2U
    • Privacy Policy || EQ2Wire and EQ2U
  • Links
    • Advanced Combat Tracker
    • Beetny’s AA Calculator
    • Dragon’s Armory || The Ultimate Character Optimization Tool
    • EQ2 Wiki
    • EQ2 Zam Archive
    • EQ2Traders
    • EQ2 Furniture || Every house item in EQ2 catalogued
    • EQ-Raiders.com || EQ2 Raid Progression and Strategies
    • EQ2Interface || Customize your EQ2 UI
    • EQ2 MAP || The most popular map addon.
    • Official EQ2 Forums
    • Other Sites
      • CheesePirate Comics
  • Forums
  • Home
  • 2011
  • October
  • 12
  • 33,000 Unauthorized Login Attempts Highlight Password Recyling
  • Uncategorized

33,000 Unauthorized Login Attempts Highlight Password Recyling

Feldon October 12, 2011 5:44 am

If there’s one thing you don’t want to recycle, it’s passwords, as some EverQuest II players found recently out.

I think we’re all guilty of using the same login and password on many different sites such as e-mail, bank websites, and yes our SOE acounts. Recently, attempts were made by outsiders to login to some 33,000 SOE accounts using login and password credentials taken from other websites. SOE and PSN detected these login attempts and have pre-emptively disabled any accounts that matched the login/password credentials stolen from websites not affiliated with Sony. Note: This appears to be unrelated to this May’s SOE/PSN security breach.

But first, a message from the EQ2Wire The Sky is Not Falling So Keep Your Pants On Club:

This is NOT a security breach!

SOE has not been “hacked again”!

DON’T PANIC!

Without further ado, a message from Philip Reitinger, SVP and Chief Information Security Officer, Sony Group:

We want to let you know that we have detected attempts on Sony Entertainment Network, PlayStation Network and Sony Online Entertainment (“Networks”) services to test a massive set of sign-in IDs and passwords against our network database.   These attempts appear to include a large amount of data obtained from one or more compromised lists from other companies, sites or other sources.   In this case, given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks.  We have taken steps to mitigate the activity.

Less than one tenth of one percent (0.1%) of our PSN, SEN and SOE audience may have been affected.  There were approximately 93,000 accounts globally (PSN/SEN: approximately 60,000 accounts; SOE: approximately 33,000) where the attempts succeeded in verifying those accounts’ valid sign-in IDs and passwords, and we have temporarily locked these accounts.  Only a small fraction of these 93,000 accounts showed additional activity prior to being locked.  We are currently reviewing those accounts for unauthorized access, and will provide more updates as we have them.  Please note, if you have a credit card associated with your account, your credit card number is not at risk.  We will work with any users whom we confirm have had unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet.

As a preventative measure, we are requiring secure password resets for those PSN/SEN accounts that had both a sign-in ID and password match through this attempt.   If you are in the small group of PSN/SEN users who may have been affected, you will receive an email from us at the address associated with your account that will prompt you to reset your password.

Similarly, the SOE accounts that were matched have been temporarily turned off.  If you are among the small group of affected SOE customers, you will receive an email from us at the address associated with your account that will advise you on next steps in order to validate your account credentials and have your account turned back on.

We want to take this opportunity to remind our consumers about the increasingly common threat of fraudulent activity online, as well as the importance of having a strong password and having a username/password combination that is not associated with other online services or sites.   We encourage you to choose unique, hard-to-guess passwords and always look for unusual activity in your account.

Tags: account security security

Continue Reading

Previous: October 12, 2011 Update Notes
Next: Yahoo: Unauthorized Access Hits Sony PSN, SOE Accounts

7 thoughts on “33,000 Unauthorized Login Attempts Highlight Password Recyling”

  1. Rhajiid says:
    October 12, 2011 5:53 am at 5:53 am

    It’s kinda funny: I have two accounts, one of them being locked (probably due to that) yesterday. That account has a) a unique name, that I do not use anywhere else; b) a unique password, that I do not use anywhere else; c) a strong password; d) login and password do not have any link/info to my person/game/chars, etc. … thank god those “other sources” where the attackers get their information from are anywhere, but not at all the SOE servers! 😀

    Log in to Reply
  2. bbdirge says:
    October 12, 2011 11:22 am at 11:22 am

    Same thing Rhajiid. My account has a unique name I do not use anywhere else and the pw is also unique. My pw was not guessed which is why my account was temporarily “locked” but not actually accessed. The ones that were accessed are still locked. Mine is not. But as I said, my pw and username are both absolutely 100% unique, only used for my EQ2 account. It is impossible the information was obtained somewhere else.

    Log in to Reply
  3. Aeyri says:
    October 12, 2011 2:05 pm at 2:05 pm

    Were either of you perhaps still using the same password for your EQ2 account that you were using before the security breach this past Spring?

    If so, perhaps what happened is that some folks finally managed to get their hands on the data from that breach (and/or finally managed to break the password encryption algorithm) and decided to use it to mass attack accounts. The reason most of the attempts failed would then be because most people (including myself) switched to a completely different password after the attack.

    If you are using a completely different password now than you were then, I’m not sure.

    Log in to Reply
  4. bbdirge says:
    October 12, 2011 2:18 pm at 2:18 pm

    Using a completely different password than I’ve ever used before. Not a pw I have used for any account. Until now I’ve never had any breeches into my account and from what Sony told me nobody actually got into my account this time it just got locked due to failed attempts to get into it. (from my understanding) What they told me could be incorrect. I’m concerned about the way they are describing this incident, making it sound as though the accounts affected were only those who use their username/pw in other places because it isn’t accurate as I can account for. My username/pw are absolutely unique to my sony account and I have never used either anywhere else. I can’t discount a possibility that the people who got hit might have something on their computers that somehow transmitted username and/or pw information on that way. I have ran virus/spyware searches on my computer just to be safe and it has a clean bill of health. I will say I am glad my account was simply locked until I contacted Sony to sort it out because to me that means their security is doing far better than it was doing in the spring. But the reports being sent out that the attacks came from another site that somehow got our usernames/pw is not truthful. I can’t say it came from Sony, but it can’t be discounted given that I for one have never used either of mine elsewhere. I really have no theories as to what could have happened but the report doesn’t fit how my information could have been accessed.

    Log in to Reply
  5. Claviarm says:
    October 12, 2011 8:19 pm at 8:19 pm

    @BBDirge: Well, you said that access to your account wasn’t gained, so that means someone tried your account name with some other password. Even though /you/ don’t use that account name anywhere else, some other guy might happen to have an account with that name somewhere, and if that site was breached and the data applied to EQ2, we’d see the results we’re seeing–someone attempted to log in to that account but didn’t have the right password.

    So unless the account name is something unlikely to ever be used by anyone anywhere, this would line up with SOE’s story, wouldn’t it?

    Log in to Reply
  6. bbdirge says:
    October 12, 2011 8:32 pm at 8:32 pm

    It’s a made up word so I don’t know how likely it is someone else has it as an account name for something else (anything is possible)… I’m still at a loss. I’m not saying I’m perfect and untouchable, just saying that my username definitely wasn’t grabbed from me using it anywhere else. I hope they figure it out and that this doesn’t happen again. I am glad that (for what is seems is the majority of those affected) their accounts weren’t actually accessed due to the wrong passwords being used.

    Log in to Reply
  7. Froak says:
    October 13, 2011 1:59 am at 1:59 am

    pretty much every decent network is setup to detect massive failed login attempts and put a stop to it, even if this happened before they got hacked we would see the exact same outcome. sony is basicly trying to prove that their network is secure again – tho this is a very poor attempt at gaining access to accounts, whoever did this is fairly un-skilled – and people are blowing it way out of proportion. less than 1/10 of 1% – 00.1% of their accounts were attempted. who knows maybe sony did it themselfs to get some cred back? :p

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Related Stories

Epilogue: A Tale of One Writer
  • General
  • Uncategorized

Epilogue: A Tale of One Writer

September 30, 2015 8:57 pm
Get An In-Game Glider Mount from Buying a SOE Game Shirt from J!NX
  • Uncategorized

Get An In-Game Glider Mount from Buying a SOE Game Shirt from J!NX

November 14, 2014 9:04 am 7
EverQuest II, EverQuest Next Teams Looking for Coders!
  • Uncategorized

EverQuest II, EverQuest Next Teams Looking for Coders!

May 7, 2013 6:50 am 5

Donate to EQ2Wire

Archives

Stay in Touch

EQ2 Server Status

Loading...
Daybreak Games Server Status

CP

  • Log in
  • Entries RSS

Spam Blocked

3,898,369 spam blocked by Akismet

You may have missed

EQ2Wire: Aug 13 2008-September 8 2017
  • Commentary

EQ2Wire: Aug 13 2008-September 8 2017

September 9, 2017 12:01 am 183
Update Notes: Wednesday September 6, 2017
  • EQ2
  • Game Updates & Maintenance

Update Notes: Wednesday September 6, 2017

September 6, 2017 10:00 am
Massively Overpowered: Guide to EverQuest II’s Days of Summer Reward Event
  • EQ2

Massively Overpowered: Guide to EverQuest II’s Days of Summer Reward Event

September 1, 2017 11:59 am
Bonus XP & 25% OFF Marketplace for Members from September 1-5!
  • Daybreak Cash
  • EQ2
  • Live Events

Bonus XP & 25% OFF Marketplace for Members from September 1-5!

August 31, 2017 8:08 pm 5
Copyright © All rights reserved. | DarkNews by AF themes.