Swords, shields and magic were not enough to fend off an attack that compromised tens of thousands of North American accounts for the popular online game League of Legends.
How many victims? More than 120,000.
What type of personal information? First and last names, usernames, email addresses and salted password hashes. Roughly 120,000 transaction records compiled prior to July 2011 were accessed, which contain “hashed” and “salted” credit card numbers.
What happened? Hackers gained access to the North American servers for Riot Games, the League of Legends developer and publisher.
What was the response? An investigation is ongoing. Riot Games sent emails to affected players, who will be required to change their passwords to stronger ones that are harder to guess. Riot Games is adding new security features, including email verification and two-factor authentication.
Quote: “We are taking appropriate action to notify and safeguard affected players,” said Riot Games CEO Brandon Beck and President Marc Merrill in the post. “We’re sincerely sorry about this situation. We apologize for the inconvenience and will continue to focus on account security going forward.”
Source: beta.na.leagueoflegends.com, League of Legends, “Important Security Update and Password Reset,” Aug. 20, 2013.