- [DramaScape] Used Car Lot
- Age of Anarchy RPG Kickstarter
- [Ennead Games] Spell Options 3: Lightning Bolt
- [Mongoose Publishing] Traveller Referee’s Briefing 5: Incidents and Encounters
- New Year, New ‘cast, New You!
- [D101 Games] Monkey, the RPG of the Journey to the West Kickstarter
- [DramaScape] Hanger 1A
- [Dungeon Masters Guild] Perilous Places: The King’s Mercy
- [Ennead Games] Quick Generator: Crimes & Punishments
- [Ennead Games] Adventure Outline Maker: SciFi Edition
Companies and websites getting hacked is a pretty regular occurrence these days. The latest victim is DriveThruRPG (also known as RPGNow), which has sent out emails to those who have made a card payment on the site since July 6th, as well as those who have their payment details stored on the site. The company has sent an email to both groups of customers. If you’ve used DTRPG or RPGNow in the last month or so, or if your details are stored there, be sure to check that there are no unusual transactions on your account.
The email reads:
I regret to inform you that one of our servers suffered a security breach which may have compromised your credit card information.
You are receiving this email because you elected to store your credit card number on our server for future purchases. We store these numbers encrypted on our site, and we have no evidence the stored numbers were compromised during the breach. It is possible, however, that the encrypted numbers could have been copied and un-encrypted. We do not store your CVV code (the digits on the back of your credit card), making it difficult for the hacker to use your card number for online fraud. So while we think the data was not compromised, we wanted to inform you of the possibility. It would be safest if you contact your credit card issuer and ask for a replacement card. At the very least, you should check your card for any suspicious charges occurring on or after July 6th.
Our technical team has identified the issue and has secured our servers. Our websites are once again safe to use.
Information such as your name and email address were potentially compromised as well.
Login passwords are stored encrypted with a one-way hash and cannot be decrypted. You do not need to change your account password, but you are more than welcome to do so on your Account page at any time if you wish.
We are truly sorry this incident occurred and sincerely regret the inconvenience it causes you. Navigating credit card company call center menus is no one’s idea of a good time.
Security has always been our top concern and up until this incident we were proud of our security record at . We will continue to do everything we can to keep our marketplace secure going forward.
You can find more information on the website’s support page.
With thanks to EN World for the news item.