"He got an old cell phone [number] of mine, and yeah, he called it occasionally," Xbox Live director of policy and enforcement Stephen "Stepto" Toulouse told us of the contact he'd had with the apparent hacker known as "Predator," who took control of Toulouse's Xbox Live account this past weekend. "I can play you a voice message if you want, to show you the nature of his contact with us." What followed was ... not suitable for printing. Expletives and derogatory terms were all that we could make out in the mess of a message.
Multiple voices could be heard, too. "I have a six minute one where he and his friend discuss all the different ways they're gonna have sex with my wife." Not exactly what Predator characterized as "reaching out" to Microsoft to offer his help resolving the security issues he's claimed to have exploited.
"I would say 'reaching out for contact' is an extremely generous phrase," Toulouse said. "Most of the stuff that he leaves on there is flat out harassment. It's not contact. He's not trying to help or do anything. He's mostly just insulting me. And I get that from time to time. It's just the nature of my role. The kids sometimes try to go after me -- it's not that big a deal."
In terms of what actually happened, Toulouse was quick to point out that his Xbox Live account wasn't "hacked" per se, but rather his personal site's web host failed to protect his information. The actual issue, he said, is social engineering (Predator's ability to manipulate the web host in order to reset Toulouse's password) -- an issue that "no one has solved."
"What happened here had absolutely nothing to do with Xbox Live," Toulouse insisted. "What these kids try and do is, all day long, they try and get my account or someone's account who's popular or prominent. We're talking like hours and hours and hours of phone calls and trading tips and tricks on forums. It's quite humorous sometimes to watch."
Of course, this particular incident is no laughing matter. "What he did, from a lot of people's point of view, I think, is a crime, and we're going to be investigating that," Toulouse added.
Customer account security remains job number one for the Xbox Live guardian, regardless of what method is being used to breach security. "We certainly take threats against accounts seriously," he assured. "We wanna make sure that our customers are protected as well."
Toulouse's best advice for protecting oneself from a similar breach? It's surprisingly simple: "have strong passwords and don't give them out."
Reader Comments (125)
Posted: Apr 4th 2011 6:04PM copa said
I hope Microsoft pays Stepto an assload of a salary.
Posted: Apr 4th 2011 6:05PM FriedConsole said
They should just call his mom and have him grounded.
Posted: Apr 4th 2011 6:18PM That Burning Sensation said
@FriedConsole
Ha! How much do you want bet his parents are pricks too? Many times when kids act out like this is because they are emulating their parents or the parent just sucks at doing their job.
Reply
Ha! How much do you want bet his parents are pricks too? Many times when kids act out like this is because they are emulating their parents or the parent just sucks at doing their job.
Posted: Apr 4th 2011 6:26PM Dance Mofo said
@FriedConsole Please! Mom will be at the forefronts of the battlefield defending her son. Dad would probably be non-existent.
Reply
Posted: Apr 4th 2011 7:35PM BananaBoat said
@That Burning Sensation - No one wants to believe that their precious little muffin could be capable of doing such a thing. I wasn't bullied in school, but one day in fourth grade, a kid decided to grab my baseball cap, throw it in a toilet, and then run away before I could beat him senseless. He did this in front of other kids, but his mother was adamant that I must have done something to him to provoke it, and that her little angel wouldn't have done it unprovoked. She could have seen a video of him doing it, and she still would have denied it (like that bullies mom from the Zangief Kid video).
Reply
Posted: Apr 4th 2011 11:45PM GMUHistorian said
@FriedConsole
Believe it or not but Stepto's actually done this with kids who get banned and whine about it via their parents. He's said on Major Nelson's show that one time he got a phone call from a Mother who was adamant based on what her did told her that the ban wasn't justified. Stepto repeated to the parent exactly what the kid said on XBL while Stepto was in the multiplayer match. Thankfully, the parent's tone changed quite quickly and she said she'd have a "talk" with her kid.
That said, I agree with BannanaBoat, too many parents are so ready to believe their kid could do absolutely no wrong that they won't even consider it regardless of the evidence presented.
Reply
Believe it or not but Stepto's actually done this with kids who get banned and whine about it via their parents. He's said on Major Nelson's show that one time he got a phone call from a Mother who was adamant based on what her did told her that the ban wasn't justified. Stepto repeated to the parent exactly what the kid said on XBL while Stepto was in the multiplayer match. Thankfully, the parent's tone changed quite quickly and she said she'd have a "talk" with her kid.
That said, I agree with BannanaBoat, too many parents are so ready to believe their kid could do absolutely no wrong that they won't even consider it regardless of the evidence presented.
Posted: Apr 5th 2011 12:00PM HaVoK308 said
@That Burning Sensation
Exactly. I'm a father of four children and I also coach football and baseball. I also help out in other various community activities and it is from my experience that kids are a direct reflection of their parents. Generation X has given birth to Generation Entitled.
Reply
Exactly. I'm a father of four children and I also coach football and baseball. I also help out in other various community activities and it is from my experience that kids are a direct reflection of their parents. Generation X has given birth to Generation Entitled.
Posted: Apr 9th 2011 1:42PM RedgeHammer said
@GMUHistorian
Fortunately there are some kids that have the benefit (mine) of parents that truly care and are involved. My kids are not allowed to use a mic, unless they are in a party with me. It is IMO, completely insane to let your children loose anywhere that bitter 20 somethings seem to exist for the sole purpose of berating, belittling and offering to defile a young kids mother. Douche bags!! Children cant adequately defend themselves, unless they are taught.
Reply
Fortunately there are some kids that have the benefit (mine) of parents that truly care and are involved. My kids are not allowed to use a mic, unless they are in a party with me. It is IMO, completely insane to let your children loose anywhere that bitter 20 somethings seem to exist for the sole purpose of berating, belittling and offering to defile a young kids mother. Douche bags!! Children cant adequately defend themselves, unless they are taught.
Posted: Apr 4th 2011 6:06PM King Johngie the Fourth said
Wow this guy is a hilarious douche
Posted: Apr 4th 2011 6:15PM King Johngie the Fourth said
@King Johngie the Fourth
Stepto, not Predator
Reply
Stepto, not Predator
Posted: Apr 4th 2011 6:17PM King Johngie the Fourth said
@King Johngie the Fourth
Shoot me now
Meant meant Predator, not Stepto
Reply
Shoot me now
Meant meant Predator, not Stepto
Posted: Apr 4th 2011 6:20PM That Burning Sensation said
@King Johngie the Fourth
"Meant Hitler, not Predator. . . eventually one of my lies are going to get me upvoted."
Reply
"Meant Hitler, not Predator. . . eventually one of my lies are going to get me upvoted."
Posted: Apr 4th 2011 7:32PM original fred said
@That Burning Sensation
Not that far fetched that it was an honest mistake. I've done worse.
Reply
Not that far fetched that it was an honest mistake. I've done worse.
Posted: Apr 4th 2011 6:07PM Apakal said
Oh look, another douchebag hacker. What a surprise.
Posted: Apr 4th 2011 9:13PM Special Agent Bob said
@Apakal
I have never hated the community so much at this moment just look at the vid comments.
Reply
I have never hated the community so much at this moment just look at the vid comments.
Posted: Apr 4th 2011 6:08PM onan said
Did Predator mean to say "Hijacked by Predator" on Stepto's profile? After all that effort, I hope he's aware "jacked" means something else...
Posted: Apr 4th 2011 10:01PM GordoJones88 said
@onan
My little avatar is always giving away my Microsoft points to get jacked by these guys.
Reply
My little avatar is always giving away my Microsoft points to get jacked by these guys.
Posted: Apr 4th 2011 6:09PM louiedog said
The "hacker's" supposed info was posted online. He seems to be a kid living with his parents. I'd pay $10 for a recording of a call between Stepto and the kid's parents, and his subsequent talking to.
Posted: Apr 4th 2011 6:10PM Mr Lingo said
I respect his reaction to the matter. He's not talking like "oh, XBL can never be hacked." He's aware of what's out there and doesn't try to act like his platform is unstoppable.
Posted: Apr 4th 2011 8:23PM Kazzahdrane said
@Mr Lingo
But he explicitly pointed out that LIVE wasn't hacked. His webhost, where his Live passport e-mail address presumably is, gave Predator his sign-in password through social engineering ("I'm really sorry but I don't remember my security code, I can prove it's me by giving you all my personal details though"). Then all he needed to do was tell LIVE that he'd forgotten his password, and watch as a reset link came into the e-mail inbox.
The only thing that could be levied at LIVE is that it;s too easy to have your password reset, but in the end all these security questions can be "hacked" unless you deliberately lie in the answers you supply when you register.
Reply
But he explicitly pointed out that LIVE wasn't hacked. His webhost, where his Live passport e-mail address presumably is, gave Predator his sign-in password through social engineering ("I'm really sorry but I don't remember my security code, I can prove it's me by giving you all my personal details though"). Then all he needed to do was tell LIVE that he'd forgotten his password, and watch as a reset link came into the e-mail inbox.
The only thing that could be levied at LIVE is that it;s too easy to have your password reset, but in the end all these security questions can be "hacked" unless you deliberately lie in the answers you supply when you register.
Posted: Apr 4th 2011 10:04PM GordoJones88 said
@Kazzahdrane
No, that is not what happened. He did not call Xbox Live. He hacked the webhost server that had Stepto's email account and managed to reset the password. Then he logged into Stepto's Gamertag.
Reply
No, that is not what happened. He did not call Xbox Live. He hacked the webhost server that had Stepto's email account and managed to reset the password. Then he logged into Stepto's Gamertag.
Posted: Apr 5th 2011 7:04AM Kazzahdrane said
@GordoJones88
That's what I said, sorry if I didn't make it clear.
Reply
That's what I said, sorry if I didn't make it clear.
Posted: Apr 5th 2011 9:01AM xreadmore said
@GordoJones88
@ Kazzahdrane
You're both almost there. He clearly said that this kid contacted his personal website host, not LIVE, not Passport, personal website host. From there he was able to reset a password, giving him access to an email address from which he must have been able to send a password change for his LIVE account.
The problem here was that with today's social media: Facebook, LIVE, etc, people have access to a lot of your personal info. and then can use that info to get around some shitty overseas call center agent (assuming overseas for dramatic effect) by answering some personal questions.
This really had nothing to do with LIVE other than it's what he posted. He very well could have changed his cell phone plan with the same email info. This is why having a bunch of email addresses with different passwords, is really important.
Reply
@ Kazzahdrane
You're both almost there. He clearly said that this kid contacted his personal website host, not LIVE, not Passport, personal website host. From there he was able to reset a password, giving him access to an email address from which he must have been able to send a password change for his LIVE account.
The problem here was that with today's social media: Facebook, LIVE, etc, people have access to a lot of your personal info. and then can use that info to get around some shitty overseas call center agent (assuming overseas for dramatic effect) by answering some personal questions.
This really had nothing to do with LIVE other than it's what he posted. He very well could have changed his cell phone plan with the same email info. This is why having a bunch of email addresses with different passwords, is really important.
Posted: Apr 4th 2011 6:11PM Wiizer said
Security question:
"What is your favorite game console?"
"What is your favorite game console?"
Posted: Apr 4th 2011 6:21PM That Burning Sensation said
@Wiizer
That would be hilarious if his answer would be Playstation 3.
Reply
That would be hilarious if his answer would be Playstation 3.
Posted: Apr 4th 2011 6:12PM Martyrdom said
Predator? What a dumb ass name. Why do hackers always use names like that?
Posted: Apr 4th 2011 6:14PM GooberMagoo said
@Martyrdom
All the good pot-related names were taken?
Reply
All the good pot-related names were taken?
Posted: Apr 4th 2011 7:40PM The Cole Train said
@Martyrdom Cause he's a super cool badass hacker that hunts for Xbox accounts......not.
Reply
Posted: Apr 5th 2011 10:53PM Broken Eagle X said
@DV8ing1
Thats so true. For example when I read a name like Digital Assasin I immediately think... pole smoker.
Reply
Thats so true. For example when I read a name like Digital Assasin I immediately think... pole smoker.
Posted: Apr 4th 2011 6:12PM Morph156 said
I personally wish we could stop referring to this kid as a "hacker" or what he did as "hacking".
Posted: Apr 4th 2011 6:14PM Ezio Auditore da Firenze said
Oh, so he's just your typical basement dwelling neckbeard loser.
Gotcha.
Gotcha.
Posted: Apr 4th 2011 8:48PM Adinnieken said
@Ezio Auditore da Firenze
Based on the info released about him, he's not a neckbeard loser. My guess, based on his voice, he barely has peach fuzz on his face let alone his balls.
He's a punk-ass kid.
Reply
Based on the info released about him, he's not a neckbeard loser. My guess, based on his voice, he barely has peach fuzz on his face let alone his balls.
He's a punk-ass kid.
Posted: Apr 4th 2011 6:14PM (Unverified) said
Looks like I've been doing this internet thing all wrong. Time to correct my mistakes and change all my passwords to 'strong'.
Posted: Apr 4th 2011 6:49PM Rocket Raccoon said
@(Unverified)
Strong1 if you want to be REALLY safe!
Reply
Strong1 if you want to be REALLY safe!
Posted: Apr 4th 2011 10:22PM Special Agent Bob said
@Rocket Raccoon
Ha! Strong1 too easy mix it up a bit like Strong11 see no one would ever guess that.
Reply
Ha! Strong1 too easy mix it up a bit like Strong11 see no one would ever guess that.
Featured Stories
Super Joystiq Podcast 004: 38 Studios meltdown, Gravity Rush, Civilization 5: Gods & Kings, Dragon's Dogma
Posted on May 25th 2012 3:30PM






