International Cyber Expo International Cyber Expo
  • About Us
Thursday, 23 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Hackers leak over 1.5 million ESEA player profiles – Industry Reaction

by The Gurus
January 10, 2017
in Editor's News
Share on FacebookShare on Twitter

E-Sports Entertainment Association (ESEA), one of the biggest video gaming communities, was hacked last December, with a database containing 1.5 million player profiles being compromised.
On Sunday, ESEA Tweeted: “Recently news has been made that ESEA’s user data has been leaked online. We expected something like this could happen but have not confirmed this is ESEA’s data. We notified the community on December 30th, 2016 about the possibility this could happen. The type of data and storage standards was disclosed. We have been working around the clock to further fortify security and will bring our website online shortly when that next round is complete. This possible user data leak is not connected to the current service outage.”
The Guru reached out to several cybersecurity experts to hear their view on the breach.
Giovanni Vigna, co-founder, Lastline:
“Any community can be a target. Whenever a substantial amount of personal information is stored in one location, that location becomes a possible target for a breach.
“Users tend to have similar username (and, unfortunately, passwords) across communities and applications. It is therefore possible that the records will be used as a basis for identity theft or additional breaches.
“Cybercriminals have always been creative in finding ways to monetise the data that resulted from a breach. Asking for a ransom is not new, and it might be motivated by the fact that the records could not immediately be sold for a profit in underground forums.”
Tim Erlin, Sr. Director, Product Management, Tripwire:
“If you’re not part of the video game industry, you might not realise that it’s a more than $30B industry. Profit motivated criminals target industries that deliver financially.
“Cyber criminals don’t just target credit card information and bank accounts. All kinds of personal information has value on the black market, and the video gaming industry collects plenty of personal information. Collecting all that data on users makes the industry a target.
“Modern gaming is all about collecting money from consumers, and gaming companies have plenty of credit card data to make them an attractive target.
“Ransomware isn’t a new phenomenon at all. We’ve seen this particular technique for parting businesses and individuals from their money move through industries.
“Organisations can defend from ransomware, but they often don’t do so until too late.”
Tyler Reguly, Manager of Software Development, Tripwire:
“There is a lot of money in video games and the in-game items associated with them. There are several websites that provide exchange rates for in game currency or items to real world dollars. Assuming credential reuse, gaining access to one set of credentials could allow you to gain access to various game accounts which would allow you to trade away or sell the in-game items. The concept of exchanging in-game assets for real currency is known as RMT (real money trading) and can be very lucrative. Some items can translate into thousands of dollars and, among the rarest of these items, are often the rewards for winning report tournaments. It is not unheard of for gamers to “retire” and pay for some, or even all, of their post secondary education by selling off entire accounts. Combine all of this with slow response rates from gaming company customer support and the fact that they often only punish the buyer rather than catching the seller, this is a very lucrative method of illegally making money.”
Mark James, IT security specialist at ESET:
“Gaming entities and online profiles can be worth “real life” money, not to mention in some games the ability to sell in-game items for actual money can reap large payloads for some unscrupulous individuals. Gaining access to those accounts can be achieved by many ways, using malware to harvest login credentials or phishing scams to either trick the user into entering their details to “keep their account safe” or trying to validate a scam email by including something they can relate too. The details leaked from this breach could enable someone to do just that. The leaked records included the usual personal information – registration date, city, state (or province), username, email address, date of birth etc. It’s the Steam ID, Xbox ID, and PSN ID that are more likely to be used for further scams. You should always be extra vigilante of any emails or even calls you receive that want you to validate your login or any other personal information, check your financial statements and of course change any affected passwords from this breach.”
Alex Mathews, Lead Security Evangelist of Positive Technologies:
“The gaming community is quite a target for hackers because these people hold “convenient” values: game attributes and virtual property what could go to a new owner on the other side of the planet with just a click (almost the same way as electronic money). Many gamers invest more money in virtual worlds than they spent buying a car, and it could be lost in a second as a result of cyber-attacks.
“Even though passwords are said to be safe in this case, the rest of personal data leaked is rather sensitive as well, when you get all of it an once (login, username, first and last name, email address, date of birth, zip code, phone number, Steam ID, Xbox ID, PSN ID). First, some online services allow a simplified authorization with some subscriber’s personal data from that list (phone number and date of birth, for example). So it could be used by impostors for dirty tricks.
“Second, this data can help the attackers to guess your passwords or the answer to the question in the recovery form: many people still use simple passwords based on, for example, their names.  Besides, people often use the same password for many services, or one mailbox is used for password recovery for other services. So, if one of your passwords is guessed it can be used to steal other accounts.
“Another problem is social engineering. A common phishing scheme is an e-mail letter “from support” asking you to login to some fake site; this way your password goes to fraudsters. The leaked personal data provide an easy way for these tricks: the fraudsters will know the exact services they have to fake for a targeted person. If tomorrow all these people will get an e-mail from ESEA, or Steam, or some Xbox related services, it could be phishing already.
“Finally, the leak of real names could also be harmful for those gamers who wanted to stay anonymous. “

ShareTweet
Previous Post

FireMon Announces Future Support for Check Point R80 Devices

Next Post

Shamoon disk-wiping attackers can now destroy virtual desktops, too

Recent News

threat intelligence

Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective

July 22, 2026
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

July 22, 2026
Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

July 22, 2026
privileged access management

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

July 21, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol