HomeSecurityRoll20 - Data Breach: Player Details Exposed

Roll20 – Data Breach: Player Details Exposed

Roll20 , a popular online tabletop platform for role-playing games (RPGs), has disclosed a data breach affecting users.

Roll20 Data Breach

According to the platform, the attacker gained unauthorized access to the company's management websiteon June 29. Through this access, he was able to view and break into users' accounts, compromising their personal information.

Roll20 says that the data exposed during this data breach is: first and last names users', email addresses, the last known IP address, and the last four digits of the credit card of users who had a payment method saved to their Roll20 account.

See also: HealthEquity: Customer health data breach

However, have been exposed passwords, protected by salt and bcrypt hashes, nor full payment information.

"We do not store this information on our servers, it is stored on our payment processors," the company explained.

The gaming platform has found no evidence of misuse of the compromised data, but says it is notifying users of the breach so they can stay informed and watch out for potentially suspicious communication.

Roll20 says on its website that it has a total of 12 million users, but has not reported the number of people affected by the data breach.

Roll20 says it noticed the breach at around 6:30 p.m. Pacific Time on June 29. The attacker had modified a account . However, the company had by 7:30 p.m. reversed those modifications and blocked any unauthorized access.

Roll20 did not provide details about how its system was breached or the attackers.

See also: Formula 1 governing body reveals data breach

However, the company confirmed that it has begun implementing an action plan, which includes:

  • Further restricting access to administrator accounts to prevent unauthorized account access
  • Further restricting the data an administrative user can access
  • Adding enhanced security
Roll20 - Data Breach: Player Details Exposed

The potential consequences of the Roll20 data breach could be serious. One of the most immediate consequences is identity theft. Malicious users who have gained access to users' personal data can use this information to create fake identities or gain access to other user accounts.

Another important consequence is the possibility of financial fraud. Malicious users can use personal data to make purchases or gain access to bank accounts, causing financial losses to users.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A data breach can also lead to a loss of trust in the Roll20 platform. Users may feel that the security of their personal data is not sufficient and may decide to stop using the platform, negatively affecting the community and the company's financial situation.

See also: Affirm says cardholders were affected by Evolve Bank data breach

Finally, users can become targets of phishing attacks. Malicious users can use the information they have obtained to send fake messages or emails, attempting to extract further sensitive information or install malicious software on users' computers.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS