The War Z offline after security breach, change your password now

The War Z

By on April 3, 2013 at 11:59 am

If you’re one of the seven people still playing The War Z then you’re advised to change your password now: OP Productions have issued an alert that all email addresses and passwords associated with the forum have been stolen.

“The data accessed included email addresses used to log-in to the forum, forum passwords which we encrypt, email addresses used to log-in to the game, encrypted game passwords as well as in-game character names and the IP addresses from which players log-in to the forum and to the game,” reads the announcement.

“If you posted other information to the forum it is likely that such data was accessed as well. We do not collect the names or addresses of our gamers so that information was not impacted unless you posted it on the forum. We are investigating whether additional information may have been obtained.”

Credit card and billing details were not compromised. While the passwords were encrypted that doesn’t mean they’re indecipherable: if you use the same password in The War Z as you do anywhere else, please go and change it now.

Source: Eurogamer

20 comments (Leave your own)

People are still playing this?


Regardless, people would use the same email address and password for other games – not to mention SPAM and other hassles…

gg WarZ, gg..


thats all well n good to say change the password, however i have literally no idea where to go to do this. clicking “account” in the launcher takes me to n that site has no login area. so im changing my password on EVERY other site i access. fuck u, war z


Their account system is retarded, only way i could find to reset my password was through the launcher “forgot account details” or something like that.


“While the passwords were encrypted that doesn’t mean they’re indecipherable”

Why? They should be! What method was used for encryption?


Wouldn’t be surprised if they sold a file of usernames, passwords and emails


LOL one of 7 people, love de humor


jme: Why? They should be! What method was used for encryption?

They don’t say, but they do say this:

We encrypt all passwords. However, there is a possibility that simple passwords can be obtained using brute force even if they are encrypted. Our research shows that many users are not using strong passwords.


And there I was thinking I couldn’t regret buying this game in alpha any more. Change all the passwords!



Nothing is undecipherable, its always just a matter of how long it takes to break the encryption. If encrypted appropriately it should take “too long” however.


Encryption was probably just another feature they mentioned and didn’t actually exist yet :D



Hahaha, brilliant!


ffs buy it in alpha to play with friend, stop playing cause its fucking shit, gets hacked now some russian mong has all the passwords to emails >.>



This. Completely unsurprising knowing the devs of this game though. Fortunately I don’t think I used that username/email + password combination anywhere important.


Wow, they just keep adding incentives to NOT play this game.



Serves your ignorant-arse right for using a password twice…



You do know how encryption works right???



Yes, I do. If a password file is encrypted using a strong method, properly strong passwords shouldn’t be cracked within our lifetime.

I’m just wondering if they used a broken method or the key/s were compromised.



thats harsh. did you need to use the language. For your information and as i discovered, i didn’t use the same password twice for my email as i did for war z, and even if i did, i have gmail’s 2 -step authentication iphone app protecting my email account.

So you NEVER have used the same password twice, in any place, ever? wow you must be incredibly brilliant remembering 100′s of 8+ digit passcodes? i think playing video games are wasted on you, trying going to work for asio. they could use a super-intelligent brain like yours.



Despite the IT security consensus, I advocate using a different password everywhere and simply writing them down on paper. Physical security risk is the much lesser of two evils IMO. And it’s made redundant by the prevalence of auto-complete.

