Digit River hacked; is Wizards affected?

Post/Author/DateTimePost
#1

ygjb

Jun 04, 2010 16:10:20

Digital River was hacked and 200,000 accounts were stolen.  Does Wizards know if any D&D Insider accounts were compromised?

www.bizjournals.com/twincities/stories/2...

Regards,
ygjb.
#2

KM.549

Jun 04, 2010 18:18:15
As expected, no offical response from WOTC.  Nice that the people that pay for DDI have to hear this from a third party source and not from the company that is taking peoples hard earned money. But thats normal for WOTC.
#3

ygjb

Jun 04, 2010 18:25:03
Taken directly from my response to a similar comment on rpg.net...


"Actually, not so much.  Wizards of the Coast did a brilliant thing in outsourcing their e-commerce component; they left it to specialists.  If you read the articles, it seems that there was insider collusion within Digital River or its service providers.  Speaking as a senior IT Security professional at one of the largest financial institutions in the world, I can say that Wizards is not at fault here, I just want to know if my credit card number is compromised :P"

#4

mudbunny

Jun 04, 2010 18:28:26
I have poked WotC about this and directed them to this thread. As soon as I hear something, I will post it here.
#5

Shroomy

Jun 04, 2010 19:16:40

I just called the Customer Service number and spoke to what I think was actually a Digital River call center.  I was told that the information stolen was not DDI information, it was actually related to software sold by a Digital River affiliate called Direct Track (that particular information seems to be confirmed in the expanded St Paul Pioneer Press story available online).

#6

loonmaxx

Jun 04, 2010 19:20:59
As expected, no offical response from WOTC.  Nice that the people that pay for DDI have to hear this from a third party source and not from the company that is taking peoples hard earned money. But thats normal for WOTC.

Really? You have no idea what happened and you just start blurting out crap like that? I swear, some people just look for any reason to start running off at the mouth. This kind of thing is getting old. Why not wait and see what happened and if any DDI accounts were even involved (which it seems they weren't) before you start spewing vitriol onto the boards?
#7

mudbunny

Jun 04, 2010 20:18:42
I did some googling, and here is what I found:

(via www.theregister.co.uk/2010/06/04/digital...)

E-commerce company Digital River exposed data belonging to almost 200,000 individuals after hackers executed a “highly unusual search command” against its secured servers, according to a news report.

...

The data contained names, email addresses, websites, and unique user-identification numbers for 198,398 individuals. It was originally gathered by affiliated marketing companies using software offered by Digital Rivers subsidiary Direct Response Technologies and stored on password-protected servers.




(via dailyme.com/story/2010060400003021/digit... )

Porat, who lives at home with his parents, claimed in e-mails and instant messages with Media Breakaway that he had consumer-tracking information from a dozen different companies, including names, e-mail addresses, websites, company names and unique user-identification numbers, for 198,398 individuals. This kind of information is extremely valuable to companies seeking targeted marketing lists of potential customers.



So far, nothing I have found indicates that any CC numbers were acquired.

As I mentioned above, WotC has been notified and I have asked them to post here as soon as they have any info.

I suspect that WotC is waiting until they have actual information available to share with us before they say anything.

Edit to add - The above is based on my 5 minutes of googling, and not based on any info from WotC.
#8

The_Jester

Jun 04, 2010 23:54:48
As expected, no offical response from WOTC.  Nice that the people that pay for DDI have to hear this from a third party source and not from the company that is taking peoples hard earned money. But thats normal for WOTC.

Really? You have no idea what happened and you just start blurting out crap like that? I swear, some people just look for any reason to start running off at the mouth. This kind of thing is getting old. Why not wait and see what happened and if any DDI accounts were even involved (which it seems they weren't) before you start spewing vitriol onto the boards?



Well, considering this happened this morning and we have been told nothing and will likely continue to hear nothing until the resumption of business on Monday morning the above comments were fair. 
IF DDI security had been comprimised this would have been 72-hours the impacted individuals could have spent securing their identity, cancelling credit cards, or contacting their financial institution (or, at least started this process pre-weekend).

Instead, we hear about this on the forums. The reassurances are entirely from someone who called DR and a dedicated and overworked volunteer.  Couldn't someone at WotC called DR? Wouldn't they have better numbers and direct lines?


Unfortunately, there's not a good place for news on the WotC site. It's very poorly designed for such. They tend to kludge them into articles column, squeezing-out the actual for-pay content. Like how the articles are being pushed-out for a Dark Sun plug and how they were pushed-out by the creature competition and kiddie adventure for a while necessitating annoying searches in the archives. 
Really, if you want new on WotC you go to ENWorld. There's been nothing on the core site about new products or announcements in ages. You go to the WotC site for your daily dose of DDI as a subscriber.  
#9

Shroomy

Jun 05, 2010 12:12:30
I heard about this from the OP over at RPG.net and I kind of think he overreacted based on the exceprted article from the St Paul Pioneer Press website.  I'm not sure that the situation warranted a response from WotC (unfortunately, it does now based on these two threads).  If I had read the entire article (which I did after calling Customer Service), I would have never even made the call because the article makes it pretty clear IMO that what happened wasn't related to DDI
#10

loonmaxx

Jun 05, 2010 12:26:37
As expected, no offical response from WOTC.  Nice that the people that pay for DDI have to hear this from a third party source and not from the company that is taking peoples hard earned money. But thats normal for WOTC.

Really? You have no idea what happened and you just start blurting out crap like that? I swear, some people just look for any reason to start running off at the mouth. This kind of thing is getting old. Why not wait and see what happened and if any DDI accounts were even involved (which it seems they weren't) before you start spewing vitriol onto the boards?



Well, considering this happened this morning and we have been told nothing and will likely continue to hear nothing until the resumption of business on Monday morning the above comments were fair.

IF DDI security had been comprimised this would have been 72-hours the impacted individuals could have spent securing their identity, cancelling credit cards, or contacting their financial institution (or, at least started this process pre-weekend).

Instead, we hear about this on the forums. The reassurances are entirely from someone who called DR and a dedicated and overworked volunteer.  Couldn't someone at WotC called DR? Wouldn't they have better numbers and direct lines?



No, the comments weren't fair. Read the article. Seriously, read it. This happened a month ago. And the information stolen was marketing data. It's all there in the article. This has nothing to do with WotC or DDI. WotC doesn't owe us an explanation because they aren't involved and it doesn't affect their customers. Speaking of which, the guy I quoted who was bashing WotC isn't even a DDI subscriber.
#11

KM.549

Jun 05, 2010 15:04:20
Speaking of which, the guy I quoted who was bashing WotC isn't even a DDI subscriber.




Well I don't like to throw my money away. I don't like 4th ed at all. So why would I subscribe to DDI if it was not useful to me?

Why am I here? I am seeing if WOTC will accually stick to what they said and come out with the orginal tools they promised for DDI. Besides, its fun to watch a train wreck.
#12

WotC_Trevor

Jun 07, 2010 10:58:18
Hey guys, sorry for the late reply on this but I just wanted to make sure I had all the information. DDI accounts were not affected with this whole deal. If I come across any more information I can share, I'll pop back in.
#13

ORC_Uzumaki

Jun 07, 2010 13:05:06

Remember to keep posts here on-topic and friendly. Please consider the code of conduct when posting to these forums.


wizards.custhelp.com/cgi-bin/wizards.cfg...

#14

Jharii

Jun 07, 2010 14:56:47
I just like how the only people (accounts) complaining about this do not appear to even have DDI accounts.  Trolls are everywhere.  Please include this variety in MM4.
#15

mudbunny

Jun 07, 2010 15:05:36
Well, considering this happened this morning and we have been told nothing and will likely continue to hear nothing until the resumption of business on Monday morning the above comments were fair. 
IF DDI security had been comprimised this would have been 72-hours the impacted individuals could have spent securing their identity, cancelling credit cards, or contacting their financial institution (or, at least started this process pre-weekend).



For what it's worth, the theft of the information happened several months ago, from what I can dig up from the various news articles, and it was only marketing data that was stolen. No CC numbers or anything. For that, I do not believe (IANAL) that DR is obligated to contact its digital partnmers for whom they operate a digital store.

If it had been CC numbers that had been stolen, the response would have been much different and much more urgent, both on the side of DR *and* on the side of WotC.

However, that does bring up a good point about there being a central place on the Wizards website that people can go to for information such as this when they (people) have a subscription with or make purchases from WotC via the net. (DDI, MTGO, etc) I will mention this in my weekly report to WotC as something that they need to consider.
#16

KM.549

Jun 07, 2010 16:04:01

Something I would have liked to have seen from WOTC on the matter was  a statment like this: 

" It has come to our attention that the company that handles the credit card info for DDI was hacked. After checking with them we found out that no DDI account info was effected. We apoligize for the stress this may have caused DDI subscribers." 

Putting this type of info out will go far with the customers IMO. I do agree with Mudbunny that WOTC needs a place customers can go for info.

#17

The_Jester

Jun 07, 2010 17:22:17
Well, considering this happened this morning and we have been told nothing and will likely continue to hear nothing until the resumption of business on Monday morning the above comments were fair. 
IF DDI security had been comprimised this would have been 72-hours the impacted individuals could have spent securing their identity, cancelling credit cards, or contacting their financial institution (or, at least started this process pre-weekend).



For what it's worth, the theft of the information happened several months ago, from what I can dig up from the various news articles, and it was only marketing data that was stolen. No CC numbers or anything. For that, I do not believe (IANAL) that DR is obligated to contact its digital partnmers for whom they operate a digital store.

If it had been CC numbers that had been stolen, the response would have been much different and much more urgent, both on the side of DR *and* on the side of WotC.

However, that does bring up a good point about there being a central place on the Wizards website that people can go to for information such as this when they (people) have a subscription with or make purchases from WotC via the net. (DDI, MTGO, etc) I will mention this in my weekly report to WotC as something that they need to consider.



Thanks.
The official site has become very lax with news in general. It tends to be entirely DDI focused. Even newly announced products tends to be "announced" through Ampersand (subscriber only, and harder to find specific entries) or community messages. There has been no real "news" items mentioning, say, the Beholder pack, or Orcus, or the lack of the Monster Builder updates in June. I'm not even sure the new Gale Force Nine licence (maps and mini-sets and DM box) have been announced on the main site.
But that's just me. I'd rather go to the official site for new on my hobby. 

And this is a big issue, mostly because the news was so scattered and held back. But it made it into the blogosphere:
critical-hits.com/2010/06/05/ddi-custome...

#18

mudbunny

Jun 08, 2010 8:26:52
Here is the note that I am putting in my weekly report to WotC about this:

1) A single place to put notifications or announcements


Summary: It would be nice if there were a single page on the WotC website that people could go to that would allow them to see information about WotC services.


URL: community.wizards.com/go/thread/view/758...


Suggestion: Have a page (perhaps a blog or something like that) where people could go to and quickly see information about WotC services, such as DDI subscriptions, Magic:Online stuff, etc, that involves peoples credit cards or other financial information. For example, recently (Friday the 7th of May), news was released that Digital River had been hacked and 200k user accounts were stolen. Luckily, it was only marketing data, and no credit card info was compromised, but there was no one central location where people could go and look for info. A single page would allow people to quickly go and look at information if required, as well as enable WotC to have a single place to put stuff.