• The VOIDRUNNER'S CODEX is LIVE! Explore new worlds, fight oppressive empires, fend off fearsome aliens, and wield deadly psionics with this comprehensive boxed set expansion for 5E and A5E!

Rpgnow creditcard information stolen

Particle_Man

Explorer
I think I am safe. I remember being annoyed at having to learn to use paypal because I am Canadian and various places would not accept my "foreign" credit card. If rpg.now is like that, I am retroactively glad for the inconvenience.

I just hope no one successfully hacks into paypal...
 

log in or register to remove this ad

Prest0

First Post
Someone hacking into Paypal would be like hacking into Wells Fargo, Epay, or one of the other major processors. If Paypal were hacked, the fallout in the RPG PDF world would pale compared to the fallout in Ebay.
 

Ry

Explorer
I was affected by this, although it appears to have my old (expired) card's info only. Still, cancelling the card I use there just to be safe. My hat know no limit.
 

Ry

Explorer
Lockridge said:
This explains why my credit card has had several fraud transactions from all over the world over the past couple of months.
I've since cancelled it. I'll be paying by Paypal from now on.
Didn't get a warning email though. Perhaps it was filtered by my spam protection although everything else from rpgnow gets through.
The e-mail I got said it was being sent to all affected customers - you might not have stored the info. DId you enter it each time you purchased?
 

catsclaw227 said:
This sucks, for sure. I just logged into rpgnow and they don't seem to have a place to edit/modify your credit card data via the My Account console. Is this normally only available during checkout?

I can't remember if they have my credit card data, and I don't know which card I used. I hope we find out soon.

And I also wonder if, in the merger, the credit card data was combined between RPGNow, DTRPG and Enworld Gamestore. That would really suck if all three were now affected.


This only effects enworld.rpgshop.com (rpgshop.com) and the new enworld gamestore (RPGNow) customers. Not DTRPG customers or the old ENWorld Gamestore customers.

You should have gotten an email from us if your card has the posability of being compromised. Not all were and only those who saved their cards are at risk. During checkout you have to MANUALLY select SAVE THIS DATA to have it happen.

If you're still in doubt or need the last 4 digets of the card in question, please email me at "webmaster@rpgnow.com"
James
 

Thank you for that clarification, James.

Will we see an official statement from RPGNow on this?

I never bought from the ENW-related stores, but from RPGNow's main site, and I left my data there *saved*. DO I have to fear that my account info was stolen? How shall I google for it to find out? I just googled my name, but found nothing unusual.

For, in all honesty, should my account info have been stolen and should I not have been warned, I guess my as well as most other's reaction would be to blame RPGNow.

Yours,

Rafael
 

Dark Seraph

First Post
Irrespective of whether it is old data or new data, this sort of leak and the means to gain unauthorised access to data that can either actually or potentially compromise a person's financial and credit facilities is unacceptable to say the least.

It is difficult enough to feel secure about providing ones credit card details to online vendors of products and services.

I think it is way overdue for online vendors to re-look at how they manage sensitive data provided to them via electronic transaction, otherwise we may be looking at the first of many waves of litigation concerning this area. When I enter a website and provide my credit card data to compete a commercial trasaction, there is an implicit trust and presumption that the vendor will do everything within its means and then some to ensure that this trust is not violated or compromised.

As a lawyer I for one will be watching this space very closely and for good measure hold off any future transactions on RPGNOW until such time I personally feel assured that they have implemented a far more robust means of managing sensitive data that they are provided by their consumers so as to avoid a fiasco like this from repeating itself - 'nuff said, for now.

DS.
 

GMSkarka

Explorer
OneBookShelf-Banners said:
You should have gotten an email from us if your card has the posability of being compromised. Not all were and only those who saved their cards are at risk. During checkout you have to MANUALLY select SAVE THIS DATA to have it happen.

You might want to double-check your email list, James. My name and info appeared on the credit card list, but I still have received no email from OBS.

I'm also not in the habit of selecting SAVE THIS DATA, ever.....and usually pay with Paypal, besides. Given the age of the card and the info in question, I'm concerned that it was the card that I gave when I created an account in the first place.
 
Last edited:

Dark Seraph said:
As a lawyer I for one will be watching this space very closely and for good measure hold off any future transactions on RPGNOW until such time I personally feel assured that they have implemented a far more robust means of managing sensitive data that they are provided by their consumers so as to avoid a fiasco like this from repeating itself - 'nuff said, for now.

All credit card data and even the option to store it has been removed from RPGNow and RPGShop... so it can't possibly happen again- we just don't have the data for someone to find.

James
 

Swack-Iron

First Post
Red Moon Games said:
Google will almost certainly log all entries, so it's probably not a good idea...

If you're concerned about that, I refer you to Google's privacy policy here:

http://www.google.com/intl/en/privacy.html

If you still have concerns, Piratecat is correct -- running a search for part of your credit card should do the trick. Other people have also noted that searching on their name with [ RPGnow ] has yielded results.

I've seen a couple of tickets in our system from the ENWorld community, and I want to let you know I'm getting to work on them right now.
 

Voidrunner's Codex

Remove ads

Top