Evidence was recently discovered Thekeyplay.com was the target of a hacker or hackers. After an internal investigation, it's unknown what, if any data, was compromised. However, as a TKP member, it's important to be transparent and communicate with you about the situation. The exploit was seemingly related to a software vulnerability. The suspected vulnerability has since been patched.
The Key Play does not store clear-text passwords in its database. It stores one-way hashes, a system designed with security in mind. It is considered good practice for users to pick a new strong password following a suspected attack. You can do that via your profile page. For a myriad of reasons (external communication, authentication, ...), email addresses along with information listed in your user profile is stored in the database.
In addition, for members of The Key Players Club, your credit card number is passed directly to the payment processor at the time you join TKPC. The Key Play does not store credit card numbers in its database. Again, that is a security best practice. Name and address/addresses are stored, primarily to fulfill delivery of keychain bottle openers.
The Key Play values transparency and proactiveness with its members, and this communication is the result of those beliefs.

Comments
Thanks for the heads up, ..gonna change my password right meow.
is there any way to contact staff at TKP? email?
Shine this into the air.
But seriously yes: mailto: sauces@thekeyplay.com
Now I know who the
are!
Thank you!
I sent an email last Wednesday but have not heard back. Should I try a different email?
And more power to ya for it.
Sorry, I hired Russians to take down Guitarman and let me gain the top spot on the big board.
Я знал, что что-то чувствует
Well played sir.
Slav squats intensify
edit: I swear to God every depiction of Eastern Europe looks exactly the same.
Haha. This looks amazing. I'm dying here!
Oh man. This is going to be like an Ashely Madison style outing for all those wahoo fans who are secret subscribers.
I'm ok. The only other place I use this password is on my luggage.
guess I need to change my password from "password" to "123456". That will stop them
If all of a sudden my account starts posting things that are intelligent, insightful, or in anyway useful, you will know I've been hacked.
PS- top gun is a great movie.
New Password: LOLUVAlostTOa#16seed
Dammit, Deuce, now I have to change mine!
Are the user passwords in the database salted and hashed?
Yes. Read the nerd details here: https://stackoverflow.com/questions/5031662/what-is-drupals-default-pass....
Yumm...nerd details... Thanks for responsibly safeguarding sensitive information and being open when an incident happens.
Seconded. Thank you for taking this seriously.
salted and hashed?
That sounds fuckin' delicious
I had some awesome corned beef hash last weekend for breakfast and this got me thinking about it immediately.
Those god damn Le Sabres are trying to steal our TURKEY LEGS!
Zero doubt in my mind it was Le Sabre. Started plotting the second the clock hit 0:00 against UMBC. You might remember UMBC, they became the first 16 seed to ever beat a 1 seed in the NCAA tournament when they beat the shit out of lolUVA.
Don't know if I trust the CS grads from UVA to be so sophisticated. Heard a rumor towards the end of my undergrad that some UVA kids tried to sneak into the CS career fair since their school wasn't being as heavily recruited as ours. Maybe it's changed given their upset victory over UMBC in that cybersecurity challenge.
It was LOLUVA.
https://news.virginia.edu/content/first-attempt-uva-student-team-wins-na...
Also you will notice this detail:
So waiting for the LOLUVA excuse that they beat UMBC in what really matters.
Shoot. The only number I remember (my driver's license # growing up and student # at VT) may have been compromised as my password! Two questions:
1. Do I need to change my password to something other than my SSN for everything, or just TKP?
2. What should I use as my new password?
A1B2C3PO
You probably only need to change it on TKP, but you should also probably let us know what you SSN is so we can verify for you... you know... for safety purposes.
Your new password should probably be your PIN. You should post that as well so we can verify that as well
1. Probably everything
2. Bank account + routing number
From the email I received:
Question: I just had to update my credit card number here for the upcoming payment. Was that update
when I changed it?
Indeed it was.
Great, Thanks for speedy reply, Joe.
Shit, I need to update my cc info now that I think about it.
But seriously, thanks for info Joe.
Well now at least we have a better scapegoat than "my drunk brother."
New scapegoat: my Russian cousin
Everybody Panic!
Just so you can enjoy my pain, see excerpt from email I just the boss:
I am an idiot. I just changed my password, and then deleted the new one when trying to delete the old one. Now I am afraid to sign out, but can't access the change password section to rechange to something I can save. I feel old - help.
Shoulda just used the A1B2C3PO instead of safari recommended chain - at least I would have remember it.
The real question, when is the head of TKP going to testify in front of Congress for this breach? /s
The gentleman from Virginia not wearing pants.
I hope you got some sort of tan on those legs, Joe. If you're as white as Zuck, Congress and everyone watching will be blind.
What's wrong with Zuck? He looks fine to me... /s

If you want to Winnie the Pooh it in front of Congress, by God I'm not going to stop you.
Important Question:
How much money did you make for selling our information to Cambridge Analytica in this alleged hack? And, was it enough to keep TKP afloat for several more years? And, will you need a booster seat when you sit in front of Congress?
(I don't really think this, I just wanted to use the gif.)
(Hmmm...I wonder how often that happens?)
This is obviously why I get scripted ads for mail order brides and russian escort services. I knew it wasn't due to my search history. I'll just go use this
excuseexplanation with my wife now....Just got an email from Twitter about hashed passwords. Maybe you should @Jack and exchange notes (but don't @ Quin Blanding).