Hacker knacken Kickstarter – Ändert eure Passwörter

kickstarter-badge-funded

Die beliebte Crowdfounding Plattform Kickstarter gab heute bekannt, dass es Hackern gelungen ist Kundendaten zu entwenden.

Kickstarter wurde letzten Mittwoch von den US Behörden über den Einbruch informiert und hat die Sicherheitslücke darauf hin sofort geschlossen. Kreditkartendaten wurden offenbar keine gestohlen. Die Benutzernamen, die dazugehörigen (verschlüsselten) Passwörter sowie eventuell gespeicherte Telefonnummer gelangten aber in die Hände der Hacker.

Obwohl die Passwörter verschlüsselt sind empfiehlt Kickstarter allen Benutzer ihr Passwort sofort zu ändern. Das könnt ihr auf der Account Seite von Kickstartet tun.

Wie immer in solchen Fällen einmal mehr mein Aufruf eure Passwörter nur einmal pro Dienst zu benutzen. Keinesfalls sollten Passwörter bei mehreren Diensten im Netz identisch sein, da sonst die bösen Buben leichtes Spiel haben.

Anbei noch das E-Mail welches Kickstarter heute an seine Benutzer verschickt hat:

On Wednesday night, law enforcement officials contacted Kickstarter and alerted us that hackers had sought and gained unauthorized access to some of our customers‘ data. Upon learning this, we immediately closed the security breach and began strengthening security measures throughout the Kickstarter system.

No credit card data of any kind was accessed by hackers. There is no evidence of unauthorized activity of any kind on your account.

While no credit card data was accessed, some information about our customers was. Accessed information included usernames, email addresses, mailing addresses, phone numbers, and encrypted passwords. Actual passwords were not revealed, however it is possible for a malicious person with enough computing power to guess and crack an encrypted password, particularly a weak or obvious one.

As a precaution, we strongly recommend that you change the password of your Kickstarter account, and other accounts where you use this password.

To change your password, log in to your account at Kickstarter.com and look for the banner at the top of the page to create a new, secure password. We recommend you do the same on other sites where you use this password. For additional help with password security, we recommend tools like 1Password and LastPass.

We’re incredibly sorry that this happened. We set a very high bar for how we serve our community, and this incident is frustrating and upsetting. We have since improved our security procedures and systems in numerous ways, and we will continue to do so in the weeks and months to come. We are working closely with law enforcement, and we are doing everything in our power to prevent this from happening again.

Kickstarter is a vibrant community like no other, and we can’t thank you enough for being a part of it. Please let us know if you have any questions, comments, or concerns. You can reach us at accountsecurity@kickstarter.com.

Thank you,

Yancey Strickler
Kickstarter CEO

1 Kommentar » Schreibe einen Kommentar

Kommentar verfassen

Diese Website verwendet Akismet, um Spam zu reduzieren. Erfahre mehr darüber, wie deine Kommentardaten verarbeitet werden.

Mastodon