NFO Servers Compromised

CR8Z

Bald fat guy.
-bZ- Member
On July 29, 2015, NFOservers suffered a compromise of some of its systems, including the main webserver and email server. This compromise likely led to an attacker obtaining information about your account, including your email address, any passwords visible in the control panel, any passwords for email accounts hosted with us, and a hashed and salted version of your control panel password.

We have a full write-up of this incident here: http://forums.nfoservers.com/viewtopic.php?f=1&t=12912. In that post, we give a detailed description of what we know was accessed, and we issue guidance for how you should respond (most importantly, by changing all your passwords). We also discuss how we've responded to the breach, and some of what we know about how it was done.

We take security seriously here and your credentials and private information are very important to us. We are doing all that we can to thoroughly and properly handle this incident and prevent something like this from happening again.

Thank you for your continued use of our services. We are very grateful for our loyal customers.

-John

President
 
No. All that we know is that your username and password were compromised.

So, if you use this username and password someplace else, you might consider changing your shit.

I would love to say that this is unusual, but it's not. This happens all the time. 
 
Reposting this here:

The key takeaway here is to ensure everyone changes their passwords across the board in case someone is stupid enough to use the same mutual password everywhere.

Even with a password system it is best to change the master and sub-site related passwords in a security breach such as this.

Ensure that if you store your passwords on your browser you are using a master key system to encrypt your passwords and change your master once a month.

Password managers are actually far safer to use overall, most folks are just too lazy to use them.
 
What UN / PW would I have w/ NFO?  I thought they were just our BF4 servers.
NFO servers (just like most gaming servers) receives the keys from Battlelog (typically these are encrypted). So I would have to guess your Battlelog username/password? Doesn't make much since since that is a separate unique key associated with our BF4 accounts.

Perhaps BF4stats.com as well? Not exactly sure.
 
Last edited by a moderator:
Back
Top