Popular free-to-play game “League of Legends” has recently suffered a security breach compromising user information. As a result Riot Games are implementing a security update and password reset. Players will be prompted to change their passwords the next time they log into the game.
August 20th Riot posted information about the security issue on the LoL website and the following day email notifications were sent out to affected members. A portion of the North American account was affected and only North American members will be asked to reset their passwords. And only North American accounts are at risk for being compromised.
Sensitive information that users need to worry about are their actual names, usernames, email addresses, passwords and potentially credit card information. The announcement explains,” What we know: usernames, email addresses, salted password hashes, and some first and last names were accessed. This means that the password files are unreadable, but players with easily guessable passwords are vulnerable to account theft.
Additionally, we are investigating that approximately 120,000 transaction records from 2011 that contained hashed and salted credit card numbers have been accessed. The payment system involved with these records hasn't been used since July of 2011, and this type of payment card information hasn't been collected in any Riot systems since then. We are taking appropriate action to notify and safeguard affected players. We will be contacting these players via the email addresses currently associated with their accounts to alert them. Our investigation is ongoing and we will take all necessary steps to protect players.”
In an effort to keep their game safe Riot is having all North American accounts change their password to something more secure. They are also implementing new security features. These new features include email verification for newly registered accounts and two-factor authentication through email or mobile SMS.
The Riot Games crew thoroughly apologizes for the situation and any inconvenience it has caused. They also encourage players to visit the player support knowledge base or player support directly with their questions and concerns.