So in light of Bethesa accidentally leaking support tickets to a bunch of users, this is just a note I wanted to leave as a developer who actually deals with credit card data. Before everyone riots and cancels their credit cards, it is very very unlikely Bethesda leaked any credit card data that actually allows someone to use your credit card or even come close to it. You can still cancel your card if you want to super cautious, but it is not really necessary.

In the US there is something called PCI DSS which is a set of guidelines/organization that has rules that you have to follow if you handle credit card data in anyway, shape or form.

Now, I can only assume that Bethedsa is PCI compliant and they are doing what they are suppose to be for handling credit card data since you know, they would be in way bigger trouble if they were not. Credit card numbers (and bank account numbers, etc.) are what is called "primary account numbers" or PAN. This data is 100% absolutely not allowed to be stored in plain text anywhere. If it is, it is a PCI violation and it has to be reported. You will get fined for it. The place I work at, we have log processors that scan every log on every server and all of our network traffic to make sure we are not accidentally leaking PAN anywhere.

Additionally, PAN data is usually not even kept in an encrypted form. It is usually only kept in memory as it is transitioning throw a secure encrypted network. A vendor, in this case Bethesda, has a payment processor that they work with that actually charges these accounts for money. Generally the way the flow works is that the vendor will get the PAN number from the user and give it to the payment processor right away. The payment processor will then give the vendor a "payment token" which is unique representation of that PAN and unique to that vendor (if someone got their hands on it, it is useless unless they use THAT vendors application to use it). As a result, the only data Bethesda should have stored is the expiration date of a credit card, the last 4 digits and the payment token. Nothing else.

Of course I do not work at Bethesda and I cannot know this 100% for sure, but I can promise if this is not the case, Bethesda will likely be going bankrupt soon. Leaking that much credit card that is an extremely serious fine. I cannot remember exactly, but it is like $100,000 per violation or something very large.

