Results 1 to 5 of 5

Thread: Creative Labs forum data breach

  1. #1
    Senior Member AGTDenton's Avatar
    Join Date
    Jun 2009
    Location
    Bracknell
    Posts
    2,708
    Thanks
    992
    Thanked
    833 times in 546 posts
    • AGTDenton's system
      • Motherboard:
      • MSI MEG X570S ACE MAX
      • CPU:
      • AMD 5950x
      • Memory:
      • 32GB Corsair something or the other
      • Storage:
      • 1x 512GB nvme, 1x 2TB nvme, 2x 8TB HDD
      • Graphics card(s):
      • ASUS 3080 Ti TuF
      • PSU:
      • Corsair RM850x
      • Case:
      • Fractal Design Torrent White
      • Operating System:
      • 11 Pro x64
      • Internet:
      • Fibre

    Exclamation Creative Labs forum data breach

    Recently I've been receiving Emails telling me of several unsuccessful login attempts and my account is locked for x hours.
    This has been for the likes of Origin & Epic Games so far. I wont know about the sites that don't take intrusion seriously.
    Actually in the case of EA they managed to get in, but I was quick enough to save it whilst it was happening.

    The data breach has likely come from Creative Labs's forum which they have now shutdown and permanently closed by the looks of it.
    I have been signed up to it for years potentially well over a decade, just one of those sites you forget about.

    I'm signed up to a web service called 'Have I been Pwned' which informed me that my Email has been compromised. It now makes some sense as to why I've been receiving odd intrusion attempt emails.
    https://haveibeenpwned.com/PwnedWebsites#Creative

    There will probably be official news about it tomorrow. But if anyone believes they might have been signed up to Creative Labs forums at one point or another it will be worth changing important logins that may use the same password. If you believe you are also signed up to any other vBulletin based forums they may also be out of date and breached at any time.
    This is the 1st time that I've noticed anything so soon after the event.
    Last edited by AGTDenton; 08-06-2018 at 12:40 AM.

  2. #2
    Senior Member AGTDenton's Avatar
    Join Date
    Jun 2009
    Location
    Bracknell
    Posts
    2,708
    Thanks
    992
    Thanked
    833 times in 546 posts
    • AGTDenton's system
      • Motherboard:
      • MSI MEG X570S ACE MAX
      • CPU:
      • AMD 5950x
      • Memory:
      • 32GB Corsair something or the other
      • Storage:
      • 1x 512GB nvme, 1x 2TB nvme, 2x 8TB HDD
      • Graphics card(s):
      • ASUS 3080 Ti TuF
      • PSU:
      • Corsair RM850x
      • Case:
      • Fractal Design Torrent White
      • Operating System:
      • 11 Pro x64
      • Internet:
      • Fibre

    Re: Creative Labs forum data breach

    Hopefully the Hexus forums are up to date (which I believe you are because this was known about last year). It seems Creative Labs got a little sloppy.

    https://haveibeenpwned.com/PwnedWebs...gencyVBulletin < is likely to be the same or related hack...

  3. #3
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,935
    Thanks
    171
    Thanked
    384 times in 311 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC

    Re: Creative Labs forum data breach

    Personally I would inform the ICO first. https://ico.org.uk/ Now with GDPR there is a mandatory 72 hour breach notification and if it turns out they have been sloppy then they might be looking at a decent size fine. It will take a good number of prosecutions before the last incompetent dregs of the corporate world take security seriously.
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  4. #4
    Senior Member AGTDenton's Avatar
    Join Date
    Jun 2009
    Location
    Bracknell
    Posts
    2,708
    Thanks
    992
    Thanked
    833 times in 546 posts
    • AGTDenton's system
      • Motherboard:
      • MSI MEG X570S ACE MAX
      • CPU:
      • AMD 5950x
      • Memory:
      • 32GB Corsair something or the other
      • Storage:
      • 1x 512GB nvme, 1x 2TB nvme, 2x 8TB HDD
      • Graphics card(s):
      • ASUS 3080 Ti TuF
      • PSU:
      • Corsair RM850x
      • Case:
      • Fractal Design Torrent White
      • Operating System:
      • 11 Pro x64
      • Internet:
      • Fibre

    Re: Creative Labs forum data breach

    Quote Originally Posted by badass View Post
    Personally I would inform the ICO first. https://ico.org.uk/ Now with GDPR there is a mandatory 72 hour breach notification and if it turns out they have been sloppy then they might be looking at a decent size fine. It will take a good number of prosecutions before the last incompetent dregs of the corporate world take security seriously.
    Annoyingly I can't see any news about it yet. According to HIBP, the breach happened 1st May prior to GDPR, but cannot find out when they actually knew about it.

    It appears to have gone completely unnoticed, possibly because its just another unpatched vBulletin forum

  5. #5
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Creative Labs forum data breach

    Data breaches are still notifiable under previous DPA - although I'm unclear about how that relates to American businesses. Creative has a UK presence, but I can't imagine their forums are part of that subsidiary.

    I very reluctantly sign up to forums, I tend to find if I'm trying to solve a problem, somebody has already asked it and just follow other threads. And if I have a view on it, I work out if it's really worth signing up to spew my thoughts to random people on the Internet who probably won't read it.

    But when I do sign up, I use a unique email address. That way when stuff like this happens, and it does frequently happen, I can simply delete that alias and have all mail bounced - or if I'm feeling vindictive, redirect all mail to the CEO of the company who had the breach.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •