Hello,
Last week, we discovered someone using a bug in our code to access limited non-personal information about Humble Bundle accounts.
The bug did not expose email addresses, but the person exploited it by testing a list of email addresses to see if they matched a Humble Bundle account. Your email address was one of the matches.
Sensitive information such as your name, billing address, password, and payment information was NOT exposed. The only information they could have accesses is you Humble Monthly subscription status. More specifically, they might know if your subscription is active, inactive, or paused; when your plan expires; and if you've received any referral bonuses.
Even though the information revealed is very limited, we take customer trust very seriously and wanted to promptly disclose this to you. We want to make sure you are able to protect yourself should someone use the information gathered to pose as Humble Bundle.
As a reminder, here are some tips to keep your account private and safe:
- Don't share your password, personal details, or payment information with anyone. We will NEVER ask for information like that.
- Be careful of emails with links to unfamiliar sites. If you receive a suspicious email related to Humble Bundle, please contact us via our support website so that we can investigate further and warn others.
- Enable 2-Step Verification (2SV) so that even if someone gets your password, they won't be able to access your account. You can enable 2SV by following these instructions [Link to settings].
We sincerely apologize for this mistake. We will work even harder to ensure your privacy and safety in the futures.
Jeffrey Rosen, CEO, Humble Bundle