Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Compromised account, but how?

F1504u2nvF1504u2nv Member UncommonPosts: 3

I'm gonna throw out an idea here so put on your tin foil hats and be prepared.

 

I received an e-mail stating that my account was banned due to ToS violations and so I went to log in to the Bnet page and sure enough someone got my account. I quickly sent off an e-mail to Blizzard and its being looked at now.

 

Whats strange to me is that I haven't used or paid for my account since September, as such I would be posting this on the WoW main forums instead. I keep my computer up to date, my anti-virus scans nightly and auto updates, I use Firefox with ad-block and while this is never fool proof I don't feel like this was my fault.

 

From what I can tell the account was taken less than a week ago so if I did pick up a key logger from somewhere, if I never used the user name and password how did it get it? The person who took it didn't try to change the password cause that would of alerted me early as an e-mail is sent with notification but instead put a authenticator on the account which gave them control over the account but Blizzard I guess doesn't send an e-mail for that. 

 

 

 

I don't play anymore so I'm not as pissed off as I would be since I can wait patiently while they get my account back and restored hopefully. Technically I didn't plan on coming back unless something in Cataclysm peaked my interest but I would like to have my account sitting there waiting just as I left it when I do. I guess I'm looking for a reason other than "His account got hacked!!! OMG he must buy gold and use power leveling services!!"

 

[Mod Edit]

«13

Comments

  • EricDanieEricDanie Member UncommonPosts: 2,238

    WATCH OUT!

    It can be a phishing attempt. Mouse over the links, check if they are from really http://www.worldofwarcraft.com , http://www.blizzard.com or something REALLY OFFICIAL, NOTHING ELSE. When in doubt go to the official website and send any questions from the support navigating from there.

    These sites (and the e-mail) will either ask you for very personal information that can compromise your account like all the data needed to perform an account theft with your data, or, the websites themselves may infect your computer for that purpose (which is why I never access gold selling or phishing e-mail websites, NOT EVEN just for curiosity).

    I tell you that based on personal experience, I'm getting daily e-mails in that format, and they can be very realistic in order to trick you.

  • TheHatterTheHatter Member Posts: 2,547
    Originally posted by F1504u2nv


    I'm gonna throw out an idea here so put on your tin foil hats and be prepared.

    en.wikipedia.org/wiki/Phishing

     

    There ya go, you can throw your tinfoil hat away now.

  • VonambergVonamberg Member UncommonPosts: 16

    Same thing happened to me. Hadnt touch my wow account in over a year and someone got in my account. Wierd thing was the lvl'd my toon up from 62 to 64 and doubled my gold. Guess they were trying to max out on what they could sell it for.  All my old guildies thought i had come back and couldnt figure out why i wasnt talking to me. LOl

  • ExodiusExodius Member Posts: 5
    Originally posted by EricDanie


    WATCH OUT!
    It can be a phishing attempt. Mouse over the links, check if they are from really http://www.worldofwarcraft.com , http://www.blizzard.com or something REALLY OFFICIAL, NOTHING ELSE. When in doubt go to the official website and send any questions from the support navigating from there.
    These sites (and the e-mail) will either ask you for very personal information that can compromise your account like all the data needed to perform an account theft with your data, or, the websites themselves may infect your computer for that purpose (which is why I never access gold selling or phishing e-mail websites, NOT EVEN just for curiosity).
    I tell you that based on personal experience, I'm getting daily e-mails in that format, and they can be very realistic in order to trick you.

     

     

    yup same. My WoW account has been canceled for awhile now but I have gotten 3 e-mails in the past 2 weeks.

     

    2 were the same and were horrible written saying pretty much what the OP said, that my account was compromised blah blah blah

    The Other e-mail was made to look like my wow account info had changed and that if I didn’t make the changed then I needed to log into my account :P mouse over the link and it isn’t to a secure WoW site so fail on that.

    I contacted blizzard about each e-mail and they said what I knew already, that it’s a scam

     

  • HEYuSHOOSHHEYuSHOOSH Member UncommonPosts: 107

    My wow account got hacked as well. I had to e-mail blizzard and they are trying fix everything now. I think it had something to do with the merge to battle.net accounts.

  • pretonpreton Member UncommonPosts: 2

    same thing happened to me hadn't played since before chistmas got a call for an old guildy telling me someone was on my toons and stoled a bunch of stuff from the guild bank.

     Got my account back today and i see that whoever hacked it has paid it till feb. 14. would it be unethical of me to play on thier money lol.

  • coffee2coffee2 Member Posts: 10

    You all could of been hacked months and months ago, at a time you were playing WoW, the hackers were just waiting for the accounts to become inactive for a while... it would be useless to try and take control of an active account.

    As to how they gain access only the hackers know but just because we all run firewalls and anti-virus programs does not mean we can take the tin foil hats off.  But as to the blizzard servers being hacked, not a chance, there are millions no doubt 100,000,000 plus WoW accounts (active & inactive) out there a server hack would not go unnoticed and blizzard would have to issue a statement and ask users to change passwords etc.

     

    AKA "coffee" - serving a temporary ban cus I made a Troll cry.

  • dolphin666dolphin666 Member UncommonPosts: 55

    OP, for some strange reason, lately I've been getting these phishing emails about WOW about 3 times a week. And I haven't played WOW since 2004.

    I'm not the only one. There seems to be some kind of brute force attempt to gain access to people's personal details.

    Considering Blizzard has been talking about security issues, I wouldn't be surprised if there is some kind of group who's only goal is to completely undermine or damage WOW.

     

  • ThenariusThenarius Member Posts: 1,106

    Oh come on, stop blaming Blizzard for this.

    There are so many possibilities out there for getting a WoW password. Do you really think that running 100 firewalls and antiviruses will give you 100% protection?

    Also, "hackers" will never open an account as soon as they hacked it, they'll wait to get a huge number of them until they start looking into them.

  • TezcatTezcat Member UncommonPosts: 82
    Originally posted by coffee2


    ... it would be useless to try and take control of an active account.
     

    Not true. My account was compromised last week just after I had returned from a 9 month break. I had only been back in game for 4 days before my account was compromised. Luckily, they only had control of it for half a day while I was at work. Blizzard have now given me all my kit back.

    I have my computer pretty well locked down and I know what I'm doing with security on a pc. Nothing was found on my computer and I spent 48hrs going over it with a fine toothcombe just to make sure.

    The only area which I can see how my account could have been compromised is what an earlier poster mentioned, when I converted it to a battlenet account. Also I was GM of my own guild so that made mine quite a tempting acquisition especially with a guild bank full of stuff.

     


  • AngorimAngorim Member Posts: 466
    Originally posted by F1504u2nv


    I'm gonna throw out an idea here so put on your tin foil hats and be prepared.
     
    I received an e-mail stating that my account was banned due to ToS violations and so I went to log in to the Bnet page and sure enough someone got my account. I quickly sent off an e-mail to Blizzard and its being looked at now.
     
    Whats strange to me is that I haven't used or paid for my account since September, as such I would be posting this on the WoW main forums instead. I keep my computer up to date, my anti-virus scans nightly and auto updates, I use Firefox with ad-block and while this is never fool proof I don't feel like this was my fault.
     
    From what I can tell the account was taken less than a week ago so if I did pick up a key logger from somewhere, if I never used the user name and password how did it get it? The person who took it didn't try to change the password cause that would of alerted me early as an e-mail is sent with notification but instead put a authenticator on the account which gave them control over the account but Blizzard I guess doesn't send an e-mail for that. While people who steal accounts probably learned this over time, a Blizzard employee would know the in's and out's of such things. That's my theory.
     
    A Blizzard employee, say one in account management or the billing department has access to your account. Is it so far fetched to think that a malicious employee can get accounts and do what they wish with them? Due to the success of WoW, Blizzard's employee population has increased and every company has its bad employees. Some take advantage of the services or products, others steal or blackmail.
     
    What I'd like to think is someone at Blizzard saw that I haven't activated my account in about four months. They saw there wasn't an authenticator attached to it and I didn't come back when they released ICC so they figured I wasn't going to. They knew not to change my password as that would alert me through my e-mail. I would like to be proven wrong but I haven't typed that log-in info into my computer since I quit, I haven't shared said info with anyone, written it down anywhere or used a different computer at any time.
     
    I don't play anymore so I'm not as pissed off as I would be since I can wait patiently while they get my account back and restored hopefully. Technically I didn't plan on coming back unless something in Cataclysm peaked my interest but I would like to have my account sitting there waiting just as I left it when I do. I guess I'm looking for a reason other than "His account got hacked!!! OMG he must buy gold and use power leveling services!!"



     

    I've had the same issue happen.  I haven't played in 3-4 months and an old WoW friend of mine messaged me asking if I had returned to the game.  Apparently someone stole my account and since it was an original account and not uprgaded to bnet, they upgraded it with a new email and password.  I'm in the process of filling out a form to get it back because even if I don't plan on playing again I don't let someone else steal and use my things.

  • MoretrinketsMoretrinkets Member Posts: 730
    Originally posted by coffee2


    You all could of been hacked months and months ago, at a time you were playing WoW, the hackers were just waiting for the accounts to become inactive for a while... it would be useless to try and take control of an active account.
    As to how they gain access only the hackers know but just because we all run firewalls and anti-virus programs does not mean we can take the tin foil hats off.  But as to the blizzard servers being hacked, not a chance, there are millions no doubt 100,000,000 plus WoW accounts (active & inactive) out there a server hack would not go unnoticed and blizzard would have to issue a statement and ask users to change passwords etc.
     

     

    Yes, they should do that, but not all companies would do it because they fear to lose clients. Changing the password often is something that everyone should do regardless.

  • ThillianThillian Member UncommonPosts: 3,156

    It's a SCAM. I did never have a WoW account, yet I still recieve e-mails my WoW account has been compromised and have to log into some kind of blizzard-worldofwarcraft...whatever website. I doubt, Blizzard would officially send you an e-mail that your account has been banned even if it really was. Every e-mail like that is scam in my opinion.

    REALITY CHECK

  • DameonkDameonk Member UncommonPosts: 1,914
    Originally posted by Thillian


    It's a SCAM. I did never have a WoW account, yet I still recieve e-mails my WoW account has been compromised and have to log into some kind of blizzard-worldofwarcraft...whatever website. I doubt, Blizzard would officially send you an e-mail that your account has been banned even if it really was. Every e-mail like that is scam in my opinion.

     

    I don't understand.  How is it a scam if he logged into the BNet website and his account was banned?

    It's much more likely that a hacker got the account information while the OP was still playing and just waited until it was no longer being used.

    "There is as yet insufficient data for a meaningful answer."

  • ThillianThillian Member UncommonPosts: 3,156
    Originally posted by Dameonk

    Originally posted by Thillian


    It's a SCAM. I did never have a WoW account, yet I still recieve e-mails my WoW account has been compromised and have to log into some kind of blizzard-worldofwarcraft...whatever website. I doubt, Blizzard would officially send you an e-mail that your account has been banned even if it really was. Every e-mail like that is scam in my opinion.

     

    I don't understand.  How is it a scam if he logged into the BNet website and his account was banned?

    It's much more likely that a hacker got the account information while the OP was still playing and just waited until it was no longer being used.

    He clearly said he is not playing WoW anymore, so I assumed his account is inactive. Do you think the hackers did stole his account, then paid for the subscription? That's just ridiculous.

     

    He said he logged into BTnet website. That's exactly how the scam website looks like. It contains battlenet.worldofwarcraft..some other bullshit in it. He said he recieved an email his account has been compromised, exactly the scam email I'm recieving quite regularly, eventho I never had a WOW account. As I said, I dont think Blizzard would send him an e-mail that his account has been banned or compromised. They simply ban it and investigate it when they recieve a complain from the customer.

    REALITY CHECK

  • RaztorRaztor Member Posts: 670

     My account is active and I received emails last week saying it was compromised. Always check the address of the battle.net account before entering any info.

     

    For example, this week the link sent me to something such as ttp://eu.batle.net/ (only 1 "t") and that's how they steal information from the users. 

     

    I suggest using something like Chrome as it is very good at detecting phishing sites.

  • RdlabanRdlaban Member UncommonPosts: 396

    Rule nr 1: "Blizzard employers will never ask your for your password" 

    Rule nr 2: Never use the provided link in the email. Take the time to type the internetadress yourself. 

    Rule nr 3: Get the blizzard authentication tool. Eiter for the iphone or order it from the blizzard store.

  • AngorimAngorim Member Posts: 466
    Originally posted by Thillian

    Originally posted by Dameonk

    Originally posted by Thillian


    It's a SCAM. I did never have a WoW account, yet I still recieve e-mails my WoW account has been compromised and have to log into some kind of blizzard-worldofwarcraft...whatever website. I doubt, Blizzard would officially send you an e-mail that your account has been banned even if it really was. Every e-mail like that is scam in my opinion.

     

    I don't understand.  How is it a scam if he logged into the BNet website and his account was banned?

    It's much more likely that a hacker got the account information while the OP was still playing and just waited until it was no longer being used.

    He clearly said he is not playing WoW anymore, so I assumed his account is inactive. Do you think the hackers did stole his account, then paid for the subscription? That's just ridiculous.

     



     

    It's not so farfetched considering it just happened to me.  I haven't had my account active in months, but the armory has shown activity in the past week or so (new items, achievements, etc).

  • KyarraKyarra Member UncommonPosts: 789

    I have gotten numerous emails through the years about my WOW account being compromised even though Ihave not played since 2005 or so.  But what is funny I just got one about my Aion account (which I only  played in the beta) and that it has been compromised also. Hackers are getting desperate lol.

  • tro44_1tro44_1 Member Posts: 1,819
    Originally posted by HEYuSHOOSH


    My wow account got hacked as well. I had to e-mail blizzard and they are trying fix everything now. I think it had something to do with the merge to battle.net accounts.



     

    I think this had something to do with it as well.

     I too was hacked like the OP, even though I hadnt played WoW in 9months. But unlike the OP, I never got a Email at all. (Fake/Nor Real) from Blizzard.

    WHat Happen, in the OP case, and in mine, was that somebody hacked into your Email somehow, and used the Battlenet system to change your Password.

    The way I busted the Hacker in my Situation, was after I had changed my Password, the Hacker clicked my Blizzard Email, but forgot to switch it to Unread before they left. So when I got to my Email, the new Password reset Email from Blizzard was already read/open.

    Jumped back on WoW, and the hacker got to it again.

    I suggest changing your Email Password right away

  • LostHawkLostHawk Member UncommonPosts: 56
    Originally posted by Thillian


    He clearly said he is not playing WoW anymore, so I assumed his account is inactive. Do you think the hackers did stole his account, then paid for the subscription? That's just ridiculous.

     

    That's not ridiculous at all as that happened to me too....

    Not playing WoW for a few months (3 raid toons still max level though) then I got an email from Blizzard telling me one of my 2 account was banned for real money stuff.

    Both accounts were reactivated with 30 days game cards. All toons were stripped and there was one additional toon, level 1 orc with a chinese name, on the non banned account.

     

    After some mail to prove I was the original owner Blizzard unbanned the account, deleted the 2 game cards payments and after I reactivated the accounts, they restored all the gears and gold missing.

    I then added their free keyring authentication system on my iphone and... just cancelled the accounts as I only wanted not to let pirates use my main non banned account and use my identity. I don't care about having paid for 2 months to fix that.

     

    I tried to see how it was possible for them to hack the password. No keyloggers or such... Then I saw the day before Guild Wars player database was partially hacked and after checking, yes my username (e-mail) and password were the same than for my hacked B-Net account. That's the only possibility I see how to explain that. The other one would be an 'undetectable' key logger which I doubt.

    First and last time I use the same pwd fro two different mmorpgs.

  • ThillianThillian Member UncommonPosts: 3,156
    Originally posted by Angorim

    Originally posted by Thillian


    He clearly said he is not playing WoW anymore, so I assumed his account is inactive. Do you think the hackers did stole his account, then paid for the subscription? That's just ridiculous.

     



     

    It's not so farfetched considering it just happened to me.  I haven't had my account active in months, but the armory has shown activity in the past week or so (new items, achievements, etc).



     

    No sorry, I don't buy this. I don't believe any hacker would hack your account, pay the subscription and then play on it and complete achievements. Or let's assume he hacked it, paid the subscription and then sold it to someone. That would mean, someone bought the account with no access to the e-mail registered for the account, nor the personal Q/A. That's even more ridiculous. Sorry, I don't buy that.

    REALITY CHECK

  • tro44_1tro44_1 Member Posts: 1,819
    Originally posted by Thillian

    Originally posted by Angorim

    Originally posted by Thillian


    He clearly said he is not playing WoW anymore, so I assumed his account is inactive. Do you think the hackers did stole his account, then paid for the subscription? That's just ridiculous.

     



     

    It's not so farfetched considering it just happened to me.  I haven't had my account active in months, but the armory has shown activity in the past week or so (new items, achievements, etc).



     

    No sorry, I don't buy this. I don't believe any hacker would hack your account, pay the subscription and then play on it and complete achievements. Or let's assume he hacked it, paid the subscription and then sold it to someone. That would mean, someone bought the account with no access to the e-mail registered for the account, nor the personal Q/A. That's even more ridiculous. Sorry, I don't buy that.

    No that happen to me aswell. I quit about a week before the patch that added Dual Spec. I quit because my sub ran out of time on game cards.

     

    I stop playing for 9 months, came back only to find out my Account was locked. Called Blizzard, who stated that my Account was hacked and did the whole Gold scam thing.

    I even had a lvl 1 alt there with a strange name.

    Cool Story about that (the Gold Seller Toon):

    I left the toon on my Character sheet after I got hacked. For some reason. I believed that maybe if I ticket Blizzard, I could help then Track down the players connected to my Hacked Account, by telling the GM, to look at this alt on my page, and track down all contacts and trades.

    But later on, my Account got rehacked. Everything gone. Cleared my Friend list and all. But when I finally got it back again, I (Again some reason) decided to log on to the unknown alt, only to find that it had 5k gold.

    Damn, lucky me. The Hacker had AH mail, but never got the chance to mail the Gold Away. Got that Shit back!!, and Put the Blizzard device on my account.

    but back to topic. Yes Hackers can reopen accounts. And no,, the myth that only Gold Buyers, and Email CLickers get hacked, is just that,,, A MYTH!!!!! I never brought not Sold Gold!!!! I never Even GET EMAILS FROM BLIZZARD!!! So how Could I get a Fake EMAIL?

    Plus my Password Had No connection whatso ever to any of my other Offline Accounts and such.

    And my Secret Question has no connection to the Answer.

    Hacker somehow did get into my Email some how. That I dont know how.

  • SoludeSolude Member UncommonPosts: 691
    Originally posted by Thillian


    He clearly said he is not playing WoW anymore, so I assumed his account is inactive. Do you think the hackers did stole his account, then paid for the subscription? That's just ridiculous.

     
    He said he logged into BTnet website. That's exactly how the scam website looks like. It contains battlenet.worldofwarcraft..some other bullshit in it. He said he recieved an email his account has been compromised, exactly the scam email I'm recieving quite regularly, eventho I never had a WOW account. As I said, I dont think Blizzard would send him an e-mail that his account has been banned or compromised. They simply ban it and investigate it when they recieve a complain from the customer.



     

    Uh ya thats exactly what they are doing.  When they merged WoW into BNet my account got jacked even though it was inactive.  Last week, still inactive my WoW account got banned for gold spamming, still inactive.  Log into BNet and yep confirmed... account banned.  Followed Blizzard's jacked account process, got reenabled and looky looky my account is active and paid for, not by my VISA and the joke that karma is... reoccurring on the hacker VISA =)

  • Vaske1984Vaske1984 Member Posts: 228
    Originally posted by Rdlaban


    Rule nr 1: "Blizzard employers will never ask your for your password" 
    Rule nr 2: Never use the provided link in the email. Take the time to type the internetadress yourself. 
    Rule nr 3: Get the blizzard authentication tool. Eiter for the iphone or order it from the blizzard store.

     

    -Jup just like you said, everyone should know this 3 golden rules by now :) i got email yesterday saying my account is suspended.....yeah right, ofc i deleted email and continue playing lol.

    image

Sign In or Register to comment.