{"id":13989,"date":"2018-12-04T10:10:03","date_gmt":"2018-12-04T18:10:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/12\/04\/news-7756\/"},"modified":"2018-12-04T10:10:03","modified_gmt":"2018-12-04T18:10:03","slug":"news-7756","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/12\/04\/news-7756\/","title":{"rendered":"Humble Bundle alerts customers to subscription reveal bug"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 04 Dec 2018 17:20:27 +0000<\/strong><\/p>\n<p>You\u2019ll want to check your mailbox if you have a Humble Bundle account, as they\u2019re notifying some customers of a bug used to gather subscriber information.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26482\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/humble-bundle-subscription-bug-alert\/attachment\/bug-notice\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice.jpg\" data-orig-size=\"1111,832\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"bug notice\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice-300x225.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice-600x449.jpg\" class=\"aligncenter size-medium wp-image-26482\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice-300x225.jpg\" alt=\"bug notice\" width=\"300\" height=\"225\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice-300x225.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice-600x449.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/bug-notice.jpg 1111w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<p>The mail reads as follows:<\/p>\n<blockquote>\n<p><em>Hello,<\/em><\/p>\n<p><em>Last week, we discovered someone using a bug in our code to access limited non-personal information about Humble Bundle accounts. The bug did not expose email addresses, but the person exploited it by testing a list of email addresses to see if they matched a Humble Bundle account. Your email address was one of the matches.<\/em><\/p>\n<\/blockquote>\n<p>Now, this is the part of a breach\/bug mail where you tend to say \u201cOh no, not again\u201d and take a deep breath. Then you see how much of your personal information winged its way to the attacker.<\/p>\n<h3>Oh no, not again<\/h3>\n<p>For once, your name, address, and even your login details are apparently in safe hands. Either this bug didn\u2019t expose as much as the attacker was hoping for, or they were just in it for the niche content collection.<\/p>\n<p>The email continues:<\/p>\n<blockquote>\n<p><em>Sensitive information such as your name, billing address, password, and payment information was NOT exposed. The only information they could have accessed is your Humble Monthly subscription status. More specifically, they might know if your subscription is active, inactive, or paused; when your plan expires; and if you&#8217;ve received any referral bonuses.<\/em><\/p>\n<\/blockquote>\n<p>I should explain at this point. You can buy standalone PC games on the Humble store, or whatever book, game, or other collection happen to be on offer this week. Alternatively, you can sign up to the monthly subscription. With this, you pay and then every month you\u2019re given a random selection of video game titles. They may be good, bad, or indifferent. You might already own a few, in which case you may be able to gift them to others. If you have<span class=\"Apple-converted-space\">\u00a0 <\/span>no interest in the upfront preview titles, you can temporarily pause your subscription for a month.<\/p>\n<p>This is the data that the bug exploiter has obtained, which is definitely an odd and specific thing to try and grab.<\/p>\n<h3>Security advice from Humble Bundle<\/h3>\n<p>Let\u2019s go back to the email at this point:<\/p>\n<blockquote>\n<p><em>Even though the information revealed is very limited, we take customer trust very seriously and wanted to promptly disclose this to you. We want to make sure you are able to protect yourself should someone use the information gathered to pose as Humble Bundle.<\/em><\/p>\n<p><em>As a reminder, here are some tips to keep your account private and safe:<\/em><\/p>\n<ul>\n<li><em>Don&#8217;t share your password, personal details, or payment information with anyone. We will NEVER ask for information like that.<\/em><\/li>\n<li><em>Be careful of emails with links to unfamiliar sites. If you receive a suspicious email related to Humble Bundle, please contact us via\u00a0<a href=\"https:\/\/support.humblebundle.com\/\" target=\"_blank\" rel=\"noopener\">our support website<\/a>\u00a0so that we can investigate further and warn others.<\/em><\/li>\n<li><em>Enable Two-factor authentication (2FA) so that even if someone gets your password, they won&#8217;t be able to access your account. You can enable2FA by following\u00a0<a href=\"https:\/\/support.humblebundle.com\/hc\/en-us\/articles\/202421374-Humble-Bundle-Two-Step-Verification\" target=\"_blank\" rel=\"noopener\">these instructions<\/a>.<\/em><\/li>\n<\/ul>\n<p><em>We sincerely apologize for this mistake. We will work even harder to ensure your privacy and safety in the future.<\/em><\/p>\n<\/blockquote>\n<h3>Good advice, but what&#8217;s the threat?<\/h3>\n<p>One could guess that the big risk here, then, is the potential for spear phishing. They could exploit this by sending mails to subscribers that their subscription is about to time out, or claim problems with stored card details. Throw in a splash of colour text regarding your subscription \u201ccurrently being paused,\u201d and it\u2019s all going to look convincing.<\/p>\n<p>Phishing is a <a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/06\/somethings-phishy-how-to-detect-phishing-attempts\/\" target=\"_blank\" rel=\"noopener\">major danger online<\/a>, and we should do everything we can to thwart it. While the information exposed here isn&#8217;t as bad as it tends to be, it can still cause major headaches. Be on the lookout for dubious Humble mails, especially if they mention subscriptions. It&#8217;ll help to keep your bundle of joy from becoming a bundle of misery.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/humble-bundle-subscription-bug-alert\/\">Humble Bundle alerts customers to subscription reveal bug<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/humble-bundle-subscription-bug-alert\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 04 Dec 2018 17:20:27 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/humble-bundle-subscription-bug-alert\/' title='Humble Bundle alerts customers to subscription reveal bug'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/shutterstock_672048862.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Humble Bundle is sending emails to subscribers due to information being revealed by a bug. How bad it is? We take a look.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/2-step-verification\/\" rel=\"tag\">2-Step Verification<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/2fa\/\" rel=\"tag\">2fa<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/breach\/\" rel=\"tag\">breach<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/bug\/\" rel=\"tag\">bug<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/games\/\" rel=\"tag\">games<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gaming\/\" rel=\"tag\">gaming<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/humble-bundle\/\" rel=\"tag\">humble bundle<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phish\/\" rel=\"tag\">phish<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spear-phishing\/\" rel=\"tag\">spear phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/two-factor-authentication\/\" rel=\"tag\">two-factor authentication<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/video-games\/\" rel=\"tag\">video games<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/humble-bundle-subscription-bug-alert\/' title='Humble Bundle alerts customers to subscription reveal bug'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/humble-bundle-subscription-bug-alert\/\">Humble Bundle alerts customers to subscription reveal bug<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[20349,10598,11510,11210,4503,11059,1445,20350,10511,3924,10510,11727,10606,4433],"class_list":["post-13989","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-2-step-verification","tag-2fa","tag-breach","tag-bug","tag-cybercrime","tag-games","tag-gaming","tag-humble-bundle","tag-phish","tag-phishing","tag-social-engineering","tag-spear-phishing","tag-two-factor-authentication","tag-video-games"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13989"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13989\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13989"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}