Page 1 of 1

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 26 Jul 2024, 23:27
by Ferefire
As you may already be aware, on the 24th July, our websites got hacked. As a precaution, we took down the sites and have been working on identifying and patching the security breach. We now know what data has been compromised. Please read the below -

We are writing to inform you of a security incident that may have affected some of your registered information with AnimeLeague.

What Happened
On the 24th of July 2024, we discovered that our website was compromised by a malicious actor. Upon investigation, it was determined that the unauthorized access resulted in the access of some of the database tables.

What Information Was Involved
The compromised data includes the following information:

Usernames and/or Full names
Email addresses
(Only if Registered for the AL Forums) - Hashed Forum passwords (encrypted)

Only the encrypted passwords used for the forums were breached. We do not store any other passwords. The main point of breach was the forums and this should not affect event registrations or ticket purchases.

We can confirm that NO card or payment details were taken as we do not store this information on our server. No other personal information such as addresses, paypal logins, phone numbers or anything of that nature were taken either. We do not store such information as per regulatory requirements.

What We Are Doing
We have taken immediate and decisive actions to address the situation and protect your information:

Secured the Vulnerability: We identified and removed a backdoor placed on our server by the malicious actor.
Enhanced Security Measures: We have implemented additional security measures to prevent future breaches.
Notified Authorities: We have informed the relevant authorities and are cooperating fully with their investigations.
System Review: We are conducting a thorough review of our systems to ensure their integrity and security.

What You Can Do
To protect your information, we recommend the following steps:

(Only for AL Forum Users) Change Your Passwords: If you have not already done so and use the forums, please change your passwords for AnimeLeague and any other accounts that use the same email/password combination.
(Only for AL Forum Users) Monitor Your Accounts: Keep an eye on your accounts for any suspicious activity and report any unauthorized actions immediately.
Be Cautious of Phishing: Be wary of any unsolicited communications asking for your personal information.

Contact Us
We understand that you may have questions or concerns about this incident. Our support team is available to assist you. Please contact us at registrations@animeleague.com for further information.

We deeply regret and apologise for any inconvenience this incident may cause and are committed to ensuring the security and privacy of your information. Thank you always for your understanding and continual support.

Important Security Notice - Forum Data Breach Notification

Posted: 27 Jul 2024, 00:49
by Ferefire
^ If you are unable to log in to your account and the recovery link does not work, then please email me on info@animeleague.com and I will sort this for you, thanks.

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 31 Jul 2024, 21:16
by Ferefire
Also, to be clear, we are aware that some people are experiencing forum errors when posting. This is due to a security update which we are still configuring. When you get the error, your post still goes through - simply hit back and refresh.

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 01 Aug 2024, 16:50
by Rich-Allen1976
In good news (I'm sure you could do with some :D ) I managed to pay off my support worker ticket for the Sheffield AL con next month yesterday so I'm definitely coming, I just hope they don't send me out with some workshy 20 year old with the attention span of a Jam sponge.

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 02 Aug 2024, 23:44
by Leehaydez
I can't wait to take my fiance to his first ever anime on 😍😍

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 03 Aug 2024, 09:59
by Sheff City Centaur
Tha what? E by ek lad, where's tha been. Nathen lad, take it from me, Sheffieldish as it is spoke is a reght bother.

Hope you enjoy our city, I've lived here since 1968, and lucky enough to hear the locals speak the dialect proper like. :)

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 03 Aug 2024, 15:53
by Ferefire
Leehaydez wrote:
02 Aug 2024, 23:44
I can't wait to take my fiance to his first ever anime on 😍😍
Hope you both enjoy it. :)

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 05 Aug 2024, 09:33
by Rich-Allen1976
One thing I'm a bit worried about is that it appears some of my photos from the cosplay section have been half inched.

I know they're not THAT personal but that's beside the point innit? It's still photos of me.

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 07 Aug 2024, 18:24
by dvstlnxa
I joined just to warn you guys that private messages and purchases were also leaked in the data breach

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 07 Aug 2024, 19:36
by Ojisama
dvstlnxa wrote:
07 Aug 2024, 18:24
I joined just to warn you guys that private messages and purchases were also leaked in the data breach

Thank you for your insight. I will ask the IT team to look into your information.

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 07 Aug 2024, 19:41
by Rich-Allen1976
dvstlnxa wrote:
07 Aug 2024, 18:24
I joined just to warn you guys that private messages and purchases were also leaked in the data breach

What the hell? I just paid off my support worker ticket for the Sheffield event next month!

Notification of Potential Data Breach on Registered Information [Important Information]

Posted: 07 Aug 2024, 21:20
by Ferefire
That is factually inaccurate. As stated, we do not record personal payment information such as card details, paypal details etc. Nothing useful that could cause harm there is recorded - we are not even legally allowed to do so. If you are referring to what a website has reported then they are mistaken and we have already reached out to them to try and fix this inaccuracy.

This topic has now been up two weeks. Time has come to lock this and move on. If anyone has any further questions or concerns, or if you wish to delete your data, then please email us on registrations@animeleague.com Thank you.