Quantcast
Channel: Expert Reviews
Viewing all articles
Browse latest Browse all 4891

Is Microsoft's Minecraft under attack?

$
0
0
Minecraft

1,800 Minecraft account details leaked online

The account details of around 1,800 Minecraft players have been posted online, raising fears over a bigger breach in security. The leaked credentials were posted on Pastebin, a site that's routinely used to publish details of compromised accounts. 

It's not clear where the account details have come from or who is behind the breach, although most of the published account details are believed to be those of German gamers. It's entirely possible that the compromised account details were stolen during an attack on another site/service, and that users have used the same username/password combination for Minecraft. A large part of the Minecraft audience is children, who are more susceptible to phishing attacks and other techniques used to steal account details. 

Find out why we gave Minecraft a five-star review here

The stolen credentials could be used to gain unauthorised access to Minecraft players' online worlds or download a full version of the game. The game has more than 100 million registered players, so the leaking of 1,800 credentials is a drop in the blocky blue ocean, although it's possible that the attackers may only have published a small selection of the compromised accounts to prove their validity. Hackers often attempt to extort money from companies by threatening to release compromised account/password details.

Microsoft bought Minecraft last year in a shock deal worth $2.5 billion. That would naturally make the game a richer target for attackers, although there's no evidence that any Microsoft or Minecraft systems have been compromised. Microsoft hadn't responded to a request for comment at the time of publication, and there is no mention of the leak on the Minecraft website.

"My recommendation would be that if users have any concern that their accounts might be exposed to hackers that they should change their passwords immediately," independent security expert, Graham Cluley, writes on the Hot For Security blog. "It goes without saying that they should be particularly concerned if they are using the same password anywhere else on the web."

20 Jan 2015
News

Viewing all articles
Browse latest Browse all 4891

Trending Articles