1. Check out this week's build competition!
    http://craftblock.me/this-weeks-theme
    Dismiss Notice

CraftBlock Security Alert | Change Your Passwords!

Discussion in 'Announcements' started by misskoa, May 4, 2017.

Thread Status:
Not open for further replies.
  1. misskoa

    misskoa addiction.
    Owner

    Joined:
    Dec 15, 2013
    Messages:
    3,020
    Projects:
    8
    Albums:
    1
    Likes Received:
    718
    TL;DR. We got hacked! If you had a forum account, we advise you to sign-in to your forum account and change it, as well as your Minecraft account password IF both passwords were the same!

    Hello Craftvians,

    A few days ago, one of our administrator accounts were breached, including their Minecraft account. After we've fixed the situation relating to MC account, the users who breached the MC account also got a hold of the forum account of the admin.

    They've caused no damage but trolled the forums with silly "Hacked By" posts, as well as attempt to delete threads. Thankfully, our permissions are pretty strict and you can only soft delete threads as a staff member, so we was able to restore any deleted threads.

    We do not know what kind of data these users had access too. They've admitted to have access to our users and their passwords, and it could be true. After a day of the breach, they got through one of the moderator accounts and attempted to delete threads again and posted a few threads as well.

    To hopefully remedy this situation, we've did the following:

    • Updated the forums to the latest version.
    • Force password change to all forum accounts.
    • Demoted all moderators and admins on the forums. We're now requiring all current and future staff members to enable two-step verification on the forums before their promoted.
    • Other internal security measures have been put in placed.
    • We're also looking into more security in-game for our staff and any other group with world-edit. For the next week or so we'll be attempting to find a possible solution, such as a login requirement when you join the server. We tried this a few days ago, but the solution impacted all players and it was more of a headache.

    Change Your Passwords
    If the password to your forum account was the same as your Minecraft account, change your account password! Also enable two-step verification in your mojang account and on the forums!

    Two-Step Verification
    A way to stop someone getting access to your account if they've managed to get your password. If your IP is different, the system will either email you a code or text your phone number it. Head to your forum settings now to enable this. http://craftblock.me/account/two-step

    Also head over to your Minecraft account settings @ mojang.com (or Minecraft.net?) and enable this there too. It's always good to be safe!

    One last thing
    Hacking is crime, and while one IP address was using a VPN/Proxy, another wasn't. We've reported the IP address to the proper authorities and we're waiting on a response back on the incident.

    Messing with other communities who did nothing to you shows you are a scum on this earth, and you have no respect for anyone nor yourself. Get a life.

    Concerned?
    We're keeping this thread closed, if you have any questions, please send me a PM. Thanks!
     
    #1 misskoa, May 4, 2017
    Last edited: May 4, 2017
    DeltaBeetle likes this.

Users Who Have Read This Thread (Total: 0)

Thread Status:
Not open for further replies.