Friday, June 10, 2011

Codemasters Hacked

Less than a week after European Lotro transferred back to Turbine Codemaster's servers were hacked. Although I had already moved all of my details are still on Codemaster's servers. Here is the email I received from them about this.

Dear valued Codemasters customer,

On Friday 3rd June, unauthorised entry was gained to our

website. As soon as the intrusion was detected, we immediately took and associated web services offline in order to prevent
any further intrusion.

During the days since the attack we have conducted a thorough

investigation in order to ascertain the extent and scope of the breach
and have regrettably discovered that the intruder was able to gain
access to the following: website

Access to the Codemasters corporate website and sub-domains.

DiRT 3 VIP code redemption page

Access to the DiRT 3 VIP code redemption page.

The Codemasters EStore

We believe the following have been compromised: Customer names and

addresses, email addresses, telephone numbers, encrypted passwords and
order history. Please note that no personal payment information was
stored with Codemasters as we use external payment providers, meaning
your payment details were not at risk from this intrusion.

Codemasters CodeM database

Members' names, usernames, screen names, email addresses, date of birth,

encrypted passwords, newsletter preferences, any biographies entered by
users, details of last site activity, IP addresses and Xbox Live
Gamertags are all believed to have been compromised.

Whilst we do not have confirmation that any of this data was actually

downloaded onto an external device, we have to assume that, as access
was gained, all of these details were compromised and/or stolen.

The website will remain offline for the foreseeable

future with all traffic re-directed to the Codemasters
Facebook page instead. A new website will launch later in the year.


For your security, in the first instance we advise you to change any

passwords you have associated with other Codemasters accounts. If you
use the same login information for other sites, you should change that
information too. Furthermore, be extra cautious of potential scams, via
email, phone, or post that ask you for personal or sensitive
information. Please note that Codemasters will never ask you for any
payment data such as credit card numbers or bank account details, nor
will Codemasters ask you for passwords or other personal identifying
data. Be aware too of fraudulent emails that may outwardly appear to be
from Codemasters with links inviting you to visit websites. The safest
way to visit your favourite websites is always by typing in the address
manually into the address bar of your browser.

Unfortunately, Codemasters is the latest victim in on-going targeted

attacks against numerous game companies. We assure you that we are doing
everything within our legal means to track down the perpetrators and
take action to the full extent of the law.

We apologise for this incident and regret any inconvenience caused.

We are contacting all customers who may have been affected directly.

Should you have any concerns or wish to speak to a member of our

Customer Services team, please email them at

You have been sent this email as part of your Codemasters Code M

membership. If you have any questions or queries about this email or
your CodeM account, please email The Codemasters
Software Company Limited, registered in England (Company No. 2044132)
whose registered office is at Codemasters Campus, Southam, Warwickshire,
CV47 2DL, England. For more Privacy information, please read the
Codemasters Privacy Policy :

I don't really know whether to be worried about this or not. In recent years I have gotten pretty diligent about using different log in details for different systems but there was a time when I was not so vigilant and of course I still live in the same house with the same telephone number.


Tesh said...

Still not sure why CodeMasters needed my phone number in the first place. I think I gave them a dummy.

...actually, I'm not sure how much I gave them. I tend to fill in fields with dummy info if I feel it's impertinent of them to ask for it.

mbp said...

Well you can still log in and see what information is is your profile. I did and changed my password not that I will be using my codemasters account for much anyway.

Anonymous said...

Got the same email but can't remember ever signing up with Codemasters.

It's beginning to feel like unless your hacked your not a real company. The phrase 'all press is good press' springs to mind.

mbp said...

Codemasters seem to have multiple logins for different games and services DM. I don't know whether this makes them more secure or less secure.

You probably signed up for a forgotten game or newsletter some time ago.