You might not want to sell or give away your Xbox 360 any time soon. Not without taking a hammer to the hard drive.
Even restoring your console to factory settings won't remove some of the data it stores, according to an ongoing study from researchers at Drexel University. And with a handful of common tools, hackers and modders can dig into a system's hard drive and excavate your credit card number or other personal information.
Speaking to Kotaku in a phone interview today, researcher Ashley Podhradsky said Xbox publisher Microsoft is doing a "disservice" to its customers by not doing a better job of keeping personal data protected.
"Microsoft does a great job of protecting their proprietary information," she said. "But they don't do a great job of protecting the user's data."
Podhradsky, along with colleagues Rob D'Ovidio and Cindy Casey at Drexel and Pat Engebretson at Dakota State University, bought a refurbished Xbox 360 from a Microsoft-authorized retailer last year. They downloaded a basic modding tool and used it to crack open the gaming console, giving them access to its files and folders. After some work, they were able to identify and extract the original owner's credit card information.
We reached out to Microsoft for comment on this issue, but as of press time, they have not yet responded.
Update: Microsoft has said it is investigating this issue.