Magic: The Gathering Maker Exposes Player Data in Unprotected Cloud Bucket
Wizards of the Coast leaves a database of over 450,000 Magic: The Gathering players in a public cloud storage bucket without a password. The company is now forcing password resets and investigating the security lapse.
Wizards of the Coast, the developer of Magic: The Gathering, confirms that a security mistake exposes the data of hundreds of thousands of players. The company leaves a database backup file in a public Amazon Web Services storage bucket without password protection, allowing anyone to access the files inside.
The exposed database contains information for 452,634 players, including names, usernames, email addresses, and account creation dates. While the user passwords in the database are hashed and salted, the rest of the data remains entirely unencrypted. Security firm Fidus Information Security discovers the exposed bucket and attempts to contact the game maker, but receives no response until TechCrunch reaches out.
After TechCrunch contacts the company, Wizards of the Coast pulls the storage bucket offline and commences an investigation. A company spokesperson claims the incident is isolated and states there is no evidence of malicious use, but still requires affected players to reset their passwords as a precaution. Security researchers express surprise that such a large company fails to maintain basic security hygiene for a user base of this size.