Author
|
Topic: My WoW-account's been compromised (Read 134660 times)
|
Merusk
Terracotta Army
Posts: 27449
Badge Whore
|
I did neither of those things and still got hacked, somehow (no trojans, viruses or other backdoors found after the incident or since).
Been to wowhead or thottbot? Guess what, you've been to gold-farmer-owned websites. Most of the aggregate info sites are. There's hinky UI mod sites out there, too. (Yet another reason not to add them out the yin-yang) AND I'd heard that the Curse Client or db was hacked some time in the past. This is big money, so they're not going to be JUST hanging around waiting on the low-hanging-fruit of stupid people and account phishing. Neither, it lets you take more things out of a given tab in a given day than the permissions for your rank allow.
This. I don't know the how, only that there's a way to do it and it's becoming more widely known.
|
The past cannot be changed. The future is yet within your power.
|
|
|
Jayce
Terracotta Army
Posts: 2647
Diluted Fool
|
I also got a tell in-game yesterday from some d00d saying that my account would be disabled immediately if I didn't go to blizz-wow-update.com/giveusyourpassword.html or something like that. As if the gold spammers weren't enough...
I get a little charge out of telling the random tells who say "Hey, got a moment?" then hit me up to buy gold. I let them make their pitch then slap them with the "report spam" button. I guess I'm easily entertained.
|
Witty banter not included.
|
|
|
brellium
Terracotta Army
Posts: 1296
|
I wouldn't be suprised if it's something like a "pop up" installer.
They reskin the pop-up so if you click on the [ x ] button it actually installs their software, I got hit with that sometime back by one of those "infected computer" pop-ups (yeah, that ended up with the os getting reinstalled).
I'm seriously considering using my VM portal to surf the internet and to nuke the user profile on occassion.
(and then log on secure websites with a second VM portal)
|
"One must see in every human being only that which is worthy of praise. When this is done, one can be a friend to the whole human race. If, however, we look at people from the standpoint of their faults, then being a friend to them is a formidable task." —‘Abdu’l-Bahá
|
|
|
Jayce
Terracotta Army
Posts: 2647
Diluted Fool
|
Just found a keylogger on my wife's laptop which I sometimes login to WoW with. I expect that if I hadn't had an authenticator attached, I might be posting in this thread to say I'd been hacked, but I appear to be good.
I changed my password anyway, after running Windows Defender full scan twice and rebooting to see if any new trojans got launched.
|
Witty banter not included.
|
|
|
Cheddar
I like pink
Posts: 4987
Noob Sauce
|
My account was closed due to exploitive behavior. Whats odd to me is I have not subbed to WoW since October of last year, and did not receive any emails noting my account was reactivated. 
|
No Nerf, but I put a link to this very thread and I said that you all can guarantee for my purity. I even mentioned your case, and see if they can take a look at your lawn from a Michigan perspective.
|
|
|
Rendakor
Terracotta Army
Posts: 10138
|
Can you still log into the account? If so, check the payment history. Also, were your WoW and email passwords the same? Its possible the account was compromised and they just deleted the emails after reactivating it.
|
"i can't be a star citizen. they won't even give me a star green card"
|
|
|
raydeen
Terracotta Army
Posts: 1246
|
If my account ever got hacked the hackers would probably just shake their heads in pity and walk away. 
|
I was drinking when I wrote this, so sue me if it goes astray.
|
|
|
Cheddar
I like pink
Posts: 4987
Noob Sauce
|
Can you still log into the account? If so, check the payment history. Also, were your WoW and email passwords the same? Its possible the account was compromised and they just deleted the emails after reactivating it.
Cannot log into the account - its definitely shut down. Yes, I was a retard and had both the same. It is possible they had deleted the activation emails etc etc. I dunno, I hope Blizzard support gets back to me with more info soon. I am curious how it all got compromised. I dunno, its just very odd.
|
No Nerf, but I put a link to this very thread and I said that you all can guarantee for my purity. I even mentioned your case, and see if they can take a look at your lawn from a Michigan perspective.
|
|
|
Koyasha
Terracotta Army
Posts: 1363
|
Sounds exactly like me, except I was lucky and caught the emails as they came in, so I managed to deal with it immediately.
|
-Do you honestly think that we believe ourselves evil? My friend, we seek only good. It's just that our definitions don't quite match.- Ailanreanter, Arcanaloth
|
|
|
Hawkbit
Terracotta Army
Posts: 5531
Like a Klansman in the ghetto.
|
My PlayNC account was just compromised for "payment fraud". All the games on that account are shutdown till I hear from them. Sad part is that I haven't logged into a PlayNC game in over a year, but last week I got into my master account to download Guild Wars just fine. Now it's shut down.
Already did a logger/virus scan, nothing. Very odd. I don't buy gold, either.
|
|
|
|
Cheddar
I like pink
Posts: 4987
Noob Sauce
|
My account was restored. I am tempted to resub just to see what was done with it. I am actually impressed at how fast they responded (I expected 0 reply from customer service). All in all very strange.
|
No Nerf, but I put a link to this very thread and I said that you all can guarantee for my purity. I even mentioned your case, and see if they can take a look at your lawn from a Michigan perspective.
|
|
|
Ozzu
Terracotta Army
Posts: 666
|
Sounds a bit like my experience a few months ago. The only thing that they did was taking mining to 300 on my hunter, mine a ton of thorium, and make me about 1k gold in one day. So, I came back with a mining gain and some money once my account was restored. I count it as payment for the inconvenience of it all.
|
|
|
|
Trippy
Administrator
Posts: 23657
|
mmorpg.com is giving out users' email addresses to WoW account phishers.
Got a WoW acccount phishing email sent to an email address I've only used once on mmorpg.com (I think it was to signup for a beta or something). If you have an account on that site I'd strongly recommend you change your email to something that isn't shared by anything important.
|
|
|
|
Tannhauser
Terracotta Army
Posts: 4436
|
My WoW account was frozen last night for 'exploitative behavior'. I haven't logged in in months. Guess I need to contact CS, I want that account for Cats.
|
|
|
|
Cheddar
I like pink
Posts: 4987
Noob Sauce
|
Interesting. So I checked payment history; I was signed up for the 10 day free trial for the Lich King expansion on 4/20, account suspended on 4/21. What is odd is I had done the trial last year. So either they offered it again (and my account was compromised) or there was an internal error at Blizzard.
Most likely my account was compromised, but it still bothers me I had no emails from them. Even if the people who compromised my account had deleted the emails my Android phone should have retained a copy and warned me I had an email. This never happened.
|
No Nerf, but I put a link to this very thread and I said that you all can guarantee for my purity. I even mentioned your case, and see if they can take a look at your lawn from a Michigan perspective.
|
|
|
Selby
Terracotta Army
Posts: 2963
|
My guild has had a rash of people getting hacked, some of whom are less than active. We're not sure why, but no one who has an authenticator has been hacked yet and I've joked that if someone gets hacked, they need to be /gkicked and prove they got an authenticator to get back in.
|
|
|
|
Koyasha
Terracotta Army
Posts: 1363
|
Interesting. So I checked payment history; I was signed up for the 10 day free trial for the Lich King expansion on 4/20, account suspended on 4/21. What is odd is I had done the trial last year. So either they offered it again (and my account was compromised) or there was an internal error at Blizzard.
Most likely my account was compromised, but it still bothers me I had no emails from them. Even if the people who compromised my account had deleted the emails my Android phone should have retained a copy and warned me I had an email. This never happened.
The emails I got disappeared even off my phone. Mine, at least, doesn't seem to save a local copy at all, if it's set to automatically synchronize, though your model may have different options available (mine's a G1).
|
-Do you honestly think that we believe ourselves evil? My friend, we seek only good. It's just that our definitions don't quite match.- Ailanreanter, Arcanaloth
|
|
|
Ozzu
Terracotta Army
Posts: 666
|
Interesting. So I checked payment history; I was signed up for the 10 day free trial for the Lich King expansion on 4/20, account suspended on 4/21. What is odd is I had done the trial last year. So either they offered it again (and my account was compromised) or there was an internal error at Blizzard.
Most likely my account was compromised, but it still bothers me I had no emails from them. Even if the people who compromised my account had deleted the emails my Android phone should have retained a copy and warned me I had an email. This never happened.
This is exactly what happened in my case. However, I did get the emails later in the day and immediately reset the password. I had already done the Lich King trial a couple of times before, so it looks like every few months they let you do it again. Within a few hours of me resetting my password and getting my account back, it was suspended for "exploiting the economy".
|
|
|
|
Mattemeo
Terracotta Army
Posts: 1128
|
Recieved an email titled 'World of Warcraft Account Management' from Blizzard Entertainment ( WoWAccountAdmin@blizzard.com) claiming that my account is being sold or traded on the 15th of May. Strange to relate, I didn't immediately follow the link provided to 'verify' as I've had a good few blatantly obvious phishing attempts from scammers attempting to get at my CoX/NCSoft accounts (no earthly clue how or why that's started) in the last month or so. I can access my battle.net account and manage WoW just fine from there, so it doesn't appear to be suspended in any way - though my subscription runs out in 3 days anyway. So what's the deal? Full transcript of the email follows in spoiler form: (hyperlinks disabled by me) No graphics were included in the email, and it seems pretty legitimate, but considering I've been largely unable to play since my GPU died and nothing appears to have changed superficially when I view my Armory details, I'm a bit non-plussed.
|
If you party with the Party Prince you get two complimentary after-dinner mints
|
|
|
Cyrrex
Terracotta Army
Posts: 10603
|
Your first assumption should probably be that the mail you received is a complete pile of bullshit. I wonder what percentage of email claiming to come from Blizzard regarding password or account issues actually comes from Blizzard? Probably something less than 1/3000th of a percent.
|
"...maybe if you cleaned the piss out of the sunny d bottles under your desks and returned em, you could upgrade you vid cards, fucken lusers.." - Grunk
|
|
|
proudft
Terracotta Army
Posts: 1228
|
|
|
|
|
fuser
Terracotta Army
Posts: 1572
|
Recieved an email titled 'World of Warcraft Account Management' from Blizzard Entertainment ( WoWAccountAdmin@blizzard.com) claiming that my account is being sold or traded on the 15th of May. Strange to relate, I didn't immediately follow the link provided to 'verify' as I've had a good few blatantly obvious phishing attempts from scammers attempting to get at my CoX/NCSoft accounts (no earthly clue how or why that's started) in the last month or so. Generally a quick look at the email header will tell you if its a phishing attack or not. A quick scan of all my archived email shows legitimate email traffic is sourced from: Received: from uw1-admin-smtp12.wowadmin.net (smtp12.us.worldofwarcraft.com [12.129.242.48]) Received: from outbound.blizzard.com (outbound.blizzard.com [198.74.38.108])
|
|
|
|
Mattemeo
Terracotta Army
Posts: 1128
|
Hadn't thought of that, but primarily because my first thought on getting the email was 'haha no'. Turns out the hover-over reveals the verification hyperlink actually wants to send me to a slightly more suspect 'h**p://www.worldofwarcraft-accountadmins-login.com/whatever.xml' and clearly not battle.net. Nice try, no cigar. Cheers for the advice, guys!
|
If you party with the Party Prince you get two complimentary after-dinner mints
|
|
|
Lantyssa
Terracotta Army
Posts: 20848
|
Granted I haven't been around much lately, but I think if one of your characters logged in and it wasn't you, we'd know.
|
Hahahaha! I'm really good at this!
|
|
|
Dren
Terracotta Army
Posts: 2419
|
The first clue is that Blizzard would never trade or sell your account themselves. If they had knowledge of said trade or sale, they would block it, not make sure you log in and say it is "ok" or "stop this now!" That email message doesn't make sense to begin with.
I've noticed a rise in in-game tells trying to phish me too. Thanks to Blizzard for the "Report Spam" tool.
The best message I received that even had me thinking twice was, "You have received a rare mount. Please log into blah blah to receive it." It was simple and cooresponded to my own knowledge that I should be getting a mount soon from the "recruit-a-friend" program. It was spelled correctly and used proper English. I thought it was a good attempt anyway right up to the point where I knew they would just send the mount in in-game mail to my chars.
|
|
|
|
Fordel
Terracotta Army
Posts: 8306
|
The first clue is that Blizzard would never trade or sell your account themselves. If they had knowledge of said trade or sale, they would block it, not make sure you log in and say it is "ok" or "stop this now!" That email message doesn't make sense to begin with.
I've noticed a rise in in-game tells trying to phish me too. Thanks to Blizzard for the "Report Spam" tool.
The best message I received that even had me thinking twice was, "You have received a rare mount. Please log into blah blah to receive it." It was simple and cooresponded to my own knowledge that I should be getting a mount soon from the "recruit-a-friend" program. It was spelled correctly and used proper English. I thought it was a good attempt anyway right up to the point where I knew they would just send the mount in in-game mail to my chars.
In game communication is the easiest to verify, Blizzard always has the actual Blizzard logo in their names/mails in game.
|
and the gate is like I TOO AM CAPABLE OF SPEECH
|
|
|
Tannhauser
Terracotta Army
Posts: 4436
|
I was cleaned out and Blizz restored all of my gold and items. I still don't know how they got me, I haven't played WoW since Dec.
Many thanks Blizz.
|
|
|
|
Righ
Terracotta Army
Posts: 6542
Teaching the world Google-fu one broken dream at a time.
|
This is clearly a false flag operation by Blizzard to get inactive players interested in their accounts again.
|
The camera adds a thousand barrels. - Steven Colbert
|
|
|
Lantyssa
Terracotta Army
Posts: 20848
|
I'm beginning to wonder if they let people input incorrect passwords all day. Vu got hacked and we haven't been able to find anything on our end.
|
Hahahaha! I'm really good at this!
|
|
|
Fordel
Terracotta Army
Posts: 8306
|
I'm beginning to wonder if they let people input incorrect passwords all day. Vu got hacked and we haven't been able to find anything on our end.
They do. Specifically, the Forums don't have a login attempt limiter and you can apparently just power through combos easily enough with whatever technique/software you know. WoW passwords are not case sensitive either.
|
and the gate is like I TOO AM CAPABLE OF SPEECH
|
|
|
Mosesandstick
Terracotta Army
Posts: 2476
|
I don't know when, but my account got compromised and I played a loooooong time ago. To stop myself from re-subbing I put my password as long, pure, gibberish. Still got broken.
|
|
|
|
Lantyssa
Terracotta Army
Posts: 20848
|
Specifically, the Forums don't have a login attempt limiter and you can apparently just power through combos easily enough with whatever technique/software you know.
WoW passwords are not case sensitive either.
Seriously!? No friggin' wonder everyone and their dog gets hacked. That's... 
|
Hahahaha! I'm really good at this!
|
|
|
Rasix
Moderator
Posts: 15024
I am the harbinger of your doom!
|
I'm getting a brand new type of phishing scam I haven't seen before: a Cataclysm beta invite that just asks me to confirm my opt in. First time I've seen this one.
Still getting two phishing emails a day trying to gank my WoW account and I haven't been playing for a few months.
|
-Rasix
|
|
|
Cyrrex
Terracotta Army
Posts: 10603
|
I get one or two a day despite not having played for about 18 months. Anybody who hacks my account would be terribly disappointed with what they found anyway. I'm probably the worst WoW player ever, in that I don't have much of either money or interesting loot.
|
"...maybe if you cleaned the piss out of the sunny d bottles under your desks and returned em, you could upgrade you vid cards, fucken lusers.." - Grunk
|
|
|
Dtrain
Terracotta Army
Posts: 607
|
I wonder how much of their CS resources are devoted to cleaning up stolen accounts. From what I understand, they do a pretty thorough job of sorting out a compromised user.
|
|
|
|
|
 |