• Home
  • Mail
  • News
  • Finance
  • Sports
  • Entertainment
  • Search
  • Mobile
  • More
Yahoo
    • Skip to Navigation
    • Skip to Main Content
    • Skip to Related Content
    • Mail
    Lifestyle Home
    Follow Us
    • Style
    • Beauty
    • Wellness
    • Shopping
    • MAKERS
    • Holiday Guide for Guys
    • Pets
    • Video
    • Horoscopes
    • Pop Culture

    'Magic: The Gathering' game maker exposed 452,000 players' account data

    Zack Whittaker
    TechCrunchNovember 16, 2019
    Reblog
    Share
    Tweet
    Share

    The maker of Magic: The Gathering has confirmed that a security lapse exposed the data on hundreds of thousands of game players.

    The game's developer, the Washington-based Wizards of the Coast, left a database backup file in a public Amazon Web Services storage bucket. But there was no password on the storage bucket, allowing anyone to access the files inside.

    The bucket is not believed to have been exposed for long — since around early-September — but it was long enough for U.K. cybersecurity firm Fidus Information Security to find the database.

    A review of the database file showed there were 452,634 players' information, including about 470 email addresses associated with Wizards' staff. The database included player names and usernames, email addresses, and the date and time of the account's creation. The database also had user passwords, which were hashed and salted, making it difficult but not impossible to unscramble.

    None of the data was encrypted. The accounts date back to at least 2012, according to our review of the data, but some of the more recent entries date back to mid-2018.

    A formatted version of the database backup file, redacted, containing 452,000 user records. (Image: TechCrunch)

    Fidus reached out to Wizards of the Coast but did not hear back. It was only after TechCrunch reached out that the game maker pulled the storage bucket offline.

    Bruce Dugan, a spokesperson for the game developer, told TechCrunch in a statement: "We learned that a database file from a decommissioned website had inadvertently been made accessible outside the company."

    "We removed the database file from our server and commenced an investigation to determine the scope of the incident," he said. "We believe that this was an isolated incident and we have no reason to believe that any malicious use has been made of the data," but the spokesperson did not provide any evidence for this claim.

    "However, in an abundance of caution, we are notifying players whose information was contained in the database and requiring them to reset their passwords on our current system," he said.

    Harriet Lester, Fidus' director of research and development, said it was "surprising in this day and age that misconfigurations and lack of basic security hygiene still exist on this scale, especially when referring to such large companies with a userbase of over 450,000 accounts."

    "Our research team work continuously, looking for misconfigurations such as this to alert companies as soon as possible to avoid the data falling into the wrong hands. It’s our small way of helping make the internet a safer place," she told TechCrunch.

    The game maker said it informed the U.K. data protection authorities about the exposure, in line with breach notification rules under Europe's GDPR regulations. The U.K.'s Information Commissioner's Office confirmed the disclosure to TechCrunch after we published.

    Companies can be fined up to 4% of their annual turnover for GDPR violations.

    Updated with ICO remarks. 

    Stop saying, ‘We take your privacy and security seriously’


    Reblog
    Share
    Tweet
    Share

    What to Read Next

    • Caitlyn Jenner Claims Kourtney Kardashian Believed O.J. Simpson's Not Guilty Verdict Right After the Trial

      Cosmopolitan
    • Two Women Landed in the ER After Using a Vacuum to End Their Periods, According to a Nurse's Scary Viral Tweet

      Meredith Videos
    • Amazon delivery driver goes viral for unbelievable reaction to customer's gift: 'Get out of here!'

      In The Know
    • What Really Happened During Princess Anne's Encounter with Donald Trump

      Harper's Bazaar
    • Gigi Hadid Goes Topless and Wears a Wig for Dramatic Chanel Photoshoot

      Harper's Bazaar
    • 'Dancing With the Stars' not returning in spring 2020 amid backlash and controversy

      Cosmopolitan Videos
    • Fired Starbucks manager mulls lawsuit amid cup scandal: 'They were supposed to be there for me'

      In The Know
    • Gym buffs and athletes will love the Theragun massager for treating sore muscles

      In The Know
    • The Man Who Killed Trayvon Martin Is Suing His Mother For $100 Million

      Refinery29
    • Bella Hadid Takes the Thong Bikini to Extremes

      Vogue
    • Martha Stewart Got a Shaggy New Haircut That's Sending the Internet Into a Frenzy

      Allure
    • Michael Jordan’s Banned Nike Sneaker Might Have a Second Act

      Footwear News
    • Scientists say 'Grey’s Anatomy' episode increased sexual assault awareness

      Yahoo Lifestyle
    • This 20-piece 'kitchen in a box' has everything but the kitchen sink—and it's $60 off today only

      Yahoo Lifestyle
    • Princess Anne Met Her Second Husband While She Was Still Married

      Harper's Bazaar
    • Ivanka Trump Wears Chevron Stripes & Ankle-Strap Flats at the Indianapolis Motor Speedway

      Footwear News

    Bloomberg says ending 'nationwide madness' of gun violence drives his White House bid

    topssuite: That was quick. Instead of Colorado, why didn't he come to Texas to plead his case? Or did he see what happened to Beto?

    Join the Conversation
    1 / 5

    243

    • All of Kate Middleton's December Outfits Revolve Around This Color Palette

      Who What Wear
    • This influencer wants you to know what her body really looks like

      Cosmo
    • 'Vanderpump Rules' Scheana Shay Just Revealed She's No Longer Single On Instagram

      Women's Health
    • Slave plantations will no longer be glorified as 'romantic places to marry' on The Knot, Pinterest

      Yahoo Lifestyle
    • Pantone’s Color of the Year 2020 Is “Classic Blue”

      Teen Vogue
    • Chipotle Has On-Call Nurses Who Check That Employees Who Call In Sick Are Not Just Hungover

      Delish
    • Here's Kendall & Bella Lounging in Bikinis During the Middle of the Work Week

      Elle
    • 'Today' Show Star Al Roker Got Into a Twitter Fight With the Rockefeller Christmas Tree

      Good Housekeeping
    • This Republican Impeachment Argument Is a Catch-22 of Stupid

      Esquire
    • Melania Trump's ‘Ridiculous’ Coat Has People Talking

      Glamour
    • The Senate Just Confirmed a Trump Judge With No Real Trial or Litigation Experience

      Esquire
    • Kendall Jenner Wore a Very Elle Woods Slip Dress Out With Bella Hadid and Joan Smalls in Miami

      Elle
    • Hilary Duff Quit Cardio For Bodybuilding Workouts And She's 'Never Felt So Lean'

      Women's Health
    • Elsa Hosk Shuts Down the Red Carpet With a Set of Supermodel Abs

      Vogue
    • These Cockroach Killers Are the Fastest Way to Get Rid of an Infestation

      Prevention
    • These top-rated sheets are insanely soft -- and under $30

      In The Know