League of Legends US accounts hacked, credit card details could be at risk

League of Legends

League of Legends' database has been hacked, again , although this time it's US players who have had their details compromised, as announced on the LoL blog . "What we know: usernames, email addresses, salted password hashes, and some first and last names were accessed." Along with 120,000 transaction records from 2011 - so if you have a US account and you used your card on the LoL store a couple of years ago, you're going to want to keep a close eye on your bank account. Riot are "taking appropriate action to notify and safeguard affected players", and within the next day they'll be enacting a mandatory password change, which will require NA accounts to pick something safer. Something like, I dunno, Password 2 ?

Here's the full story, from the League of Legends blog:

"The security of your information is critically important to us, so we're really sorry to share that a portion of our North American account information was recently compromised.

"What we know: usernames, email addresses, salted password hashes, and some first and last names were accessed. This means that the password files are unreadable, but players with easily guessable passwords are vulnerable to account theft.

"Additionally, we are investigating that approximately 120,000 transaction records from 2011 that contained hashed and salted credit card numbers have been accessed. The payment system involved with these records hasn't been used since July of 2011, and this type of payment card information hasn't been collected in any Riot systems since then. We are taking appropriate action to notify and safeguard affected players. We will be contacting these players via the email addresses currently associated with their accounts to alert them. Our investigation is ongoing and we will take all necessary steps to protect players."

Thankfully, Riot Games will be introducing new security features in the wake of this latest breach, including "email verification: all new registrations and account changes will need to be associated with a valid email address (we'll also require all existing players to provide a valid email address)" and "two-factor authentication: changes to account email or password will require verification via email or mobile SMS."

Riot's Marc Merrill and Brandon Beck concluded the post by saying that "we're sincerely sorry about this situation. We apologize for the inconvenience and will continue to focus on account security going forward."

Ta, PCGamesN .

Tom Sykes

Tom loves exploring in games, whether it’s going the wrong way in a platformer or burgling an apartment in Deus Ex. His favourite game worlds—Stalker, Dark Souls, Thief—have an atmosphere you could wallop with a blackjack. He enjoys horror, adventure, puzzle games and RPGs, and played the Japanese version of Final Fantasy VIII with a translated script he printed off from the internet. Tom has been writing about free games for PC Gamer since 2012. If he were packing for a desert island, he’d take his giant Columbo boxset and a laptop stuffed with PuzzleScript games.

Latest in MOBA
League of Legends promo image - huge dude in a huge suit of armor holding a huge axe
Riot walks back unpopular League of Legends changes: Hextech Chests are coming back, and the Blue Essence cost for new champions will be cut in half
A triptych of views from Deadlock's improved map, showing a suspension bridge backlit by a setting sun, a triumphal arch with buildings in the background, and a leafy park overlooked by distant skyscrapers.
Deadlock gets a massive map overhaul that shrinks its map from four lanes to three: 'This has a large range of accompanying map-wide changes'
Three monsters holding clubs in Dota 2.
As a lapsed 4,500 hour veteran of Dota 2, the big new Wandering Waters update has lured me back—but despite the changes, the game still feels stuck in its ways
Sahn-Uzal Mordekaiser revealed in silhouette against a white moon and a blood-red sky.
League of Legends is getting a hotly anticipated skin for its lich necromancer Mordekaiser, but fans' joy has been 'obliterated' because it's 'stuck in a $200 fomo gacha store'
Smite 2 art
Hi-Rez will only be giving 'minor updates' to Smite and Paladins now it's laying off around 70 employees, but don't worry, Smite 2 is the 'primary focus of the newly streamlined operations'
LoL summoner art
It's high time League of Legends got full voice chat
Latest in News
spectre divide
Spectre Divide and its studio are shutting down after just six months: 'The industry is in a tough spot right now'
Naoe looking at the wrist blade in Assassin's Creed Shadows
Ubisoft backflips, says Assassin's Creed Shadows will support Steam Deck at launch, but I doubt I'll actually want to play it there
Henry from KCD2 wearing nice outfits
'Diversify your fashion endgame' with this Kingdom Come: Deliverance 2 mod that gives Henry fly new gambesons, pourpoints, and caftans
Masked Counter-Terrorist in helmet in forefront with sunglasses and beret-wearing CT in background touching headset
There's hope yet for Classic Offensive after its Steam rejection: The team behind the Counter-Strike 1.6 revival mod is in touch with Valve about its 'concerns'
Recently appointed Intel CEO Lip-Bu Tan.
Here comes Intel's new CEO: a semiconductor veteran that won the same prestigious award as Jensen Huang and Lisa Su
BURBANK, CALIFORNIA - AUGUST 15: Protestors attend the SAG-AFTRA Video Game Strike Picket on August 15, 2024 in Burbank, California. (Photo by Lila Seeley/Getty Images)
8 months into their strike, videogame voice actors say the industry's latest proposal is 'filled with alarming loopholes that will leave our members vulnerable to AI abuse'