Welcome, Guest. Please login or register.
April 19, 2024, 02:32:47 PM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  The Gaming Graveyard  |  World of Warcraft  |  Topic: My WoW-account's been compromised 0 Members and 1 Guest are viewing this topic.
Pages: 1 ... 8 9 [10] Go Down Print
Author Topic: My WoW-account's been compromised  (Read 114685 times)
SurfD
Terracotta Army
Posts: 4035


Reply #315 on: January 17, 2011, 10:24:07 PM

My account gets locked every time I forget to turn on the vpn back to my home network and attempt to log in to my WoW account while traveling.

Blizzard must have some sort of geo-location or ip address logging service running to catch hackers.
I think that is part of the new security measures that went in when they launched the Dial In Authenticator thing.  Now there is a chance that if you log in from an IP that is not one you usually use, they will lock your account on suspicion of chineese hackers.

Darwinism is the Gateway Science.
Sir T
Terracotta Army
Posts: 14223


Reply #316 on: January 22, 2011, 11:25:55 AM

I got this email today

Quote
Greetings:

Thank you for your attention in this matter regarding the compromised World of Warcraft account you are using. Unfortunately, multiple parties have contacted Blizzard Entertainment seeking restoration of the account in question. This message contains an updated Account Retrieval process, which will enable the rightful user of the account to resume their adventures in the World of Warcraft.

The investigation will be continued by Blizzard administration to determine the action to be taken against your account. If your account is found violating the EULA and Terms of Use, your account can, and will be suspended/closed/or terminated. In order to keep this from occurring, you should immediately verify that you are the original owner of the account.

To verify your identity please visit the following webpage:
{redacted}

Only Account Administration will be able to assist with account retrieval issues.

Please help us to avoid any further delays in restoring Account access by following the instructions exactly and in their entirety. We will contact you again once all information has been received and thank you in advance for your patience and cooperation in resolving this account issue. Please be sure to provide all pertinent data as soon as possible since Blizzard Entertainment is unable to offer any type of reimbursement for the time an account is locked for verification and investigation purposes.

In the meantime, please make sure to scan the computer system you are using to remove all viruses, Trojan files, and key loggers. For more computer/Internet security tips, please visit
{redacted}

In addition, World of Warcraft account passwords should be periodically changed by visiting :
{redacted}

Any inquiries concerning this account retrieval process can only be addressed by Account Administration. To learn more about how Account Administration is able to assist you, please visit us at :
{redacted}

Thank you for your patience and anticipated cooperation in this matter.

Sincerely,
Account AdministrationBlizzard
Entertainment
{redacted}

I did play WOW. On a trial CD I picked up for 2 euro. For a week and a half. In 2009.

This looks legit.

{edit} links redacted
« Last Edit: January 22, 2011, 12:19:16 PM by Sir T »

Hic sunt dracones.
Minvaren
Terracotta Army
Posts: 1676


Reply #317 on: January 22, 2011, 11:29:04 AM

Might want to obfuscate or un-HTML the very first link in your post, Sir T...

"There are many things of which a wise man might wish to remain ignorant." - Ralph Waldo Emerson
Polysorbate80
Terracotta Army
Posts: 2044


Reply #318 on: February 23, 2011, 11:40:27 AM

Authenticator ordered.

Logged in this morning to find both my main and my wife's main have been rebound to Netherstorm and have apparently been busy farming Botanica.  Y'know, to fill up the bag/bank space that had all been emptied, except for hearthstones (hers was even still on cooldown, they've been busy li'l devils)

A round of password changes later, Blizzard's emails tell me everythings back where it was though, with only about ~3 hours to do it.  The design team may not think their job is providing customer service, but fortunately their actual CR people haven't bought into that  awesome, for real

“Why the fuck would you ... ?” is like 80% of the conversation with Poly — Chimpy
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #319 on: February 23, 2011, 12:10:38 PM

If her hearth was still on CD you might have booted them offline right then.  Found out that little feature of the game back in vanilla when I booted my wife offline by logging into her account.   I get why they do it, so you don't have to do the oldschool EQ dance of "am I offline yet? What about now? What about now? when you're DC'd.  It does make for some fun times when you want to mess with someone whose password you know, however.

The past cannot be changed. The future is yet within your power.
Koyasha
Terracotta Army
Posts: 1363


Reply #320 on: February 23, 2011, 03:44:49 PM

EQ also booted you offline when someone tried to log in.  It would take a minute or so for you to be able to get in, but just the attempt to log in would disconnect the person playing.

And yeah, ever since my accounts got hacked somehow way back, I've had an authenticator on mine, as much as I've had the rabble rabble of not using the goddamn piece of junk that requires manual input.  I hate the thing and it annoys me every single time I pick it up to use it, but when they can apparently find my passwords even when I haven't been playing for a year, no amount of personal 'caution' or security is going to make a difference, it seems.

Even with the authenticator I stay paranoid by having an email devoted purely to contact with Blizzard and nothing else; if anything else ever comes over that email I'll switch it on my account.

-Do you honestly think that we believe ourselves evil? My friend, we seek only good. It's just that our definitions don't quite match.-
Ailanreanter, Arcanaloth
Mattemeo
Terracotta Army
Posts: 1128


Reply #321 on: February 28, 2011, 04:30:30 PM

This is a delight in every sense!

Quote
Greetings,

NO.FH54GGSGD4SFA94

***Please read this e-mail carefully, as it is related to your account state of World of Warcraft ID.

Deathwing the Destroyer returns to Azeroth. There is a serious saturation point in the World of Warcraft ID(s) and it is very difficult for players to creat a role. That we may delete some of the same as role's ID(s) to ensure to get a better gaming experience for players.

Sorry, because the part ID(s) which is not logged on ,for a long time. For our regular check may cause your ID(s) is cleared. We need you to submit the further questionnaire in person. In order to confirm that you are still in Azeroth. Please click

hilariouslybadurl://NO.FH54GGSGD4SFA94.us.battle.cataclysm.blizzardid.net/login.html?ref=https://us.battle.net/account/management/index.xml&app=bam&t

Login to your account, In accordance following template to verify your account.

*We look forward to seeing you back in Azeroth.

Once we verify your account, we will reply to your e-mail informing you that we have given up deleting.

Game Masters:

Game Masters (GMs) are Blizzard Entertainment personnel that are available in-game to assist you with your gameplay related questions, problems, etc. Learn more about Game Masters, including how to contact them at .blizzard.com/support/wowgm/

Best regards,
World of Warcraft Account Administration Team
.blizzard.com/support/wowaa/
Blizzard Entertainment

Haven't had a phish this wonderfully bad in a long time!

If you party with the Party Prince you get two complimentary after-dinner mints
Azazel
Contributor
Posts: 7735


Reply #322 on: March 30, 2011, 12:05:08 AM

Found this in my Spam folder...



Too Many Attempts Warning No.46

Quote from: scammer
Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your Computer

In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail Account

After you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your account

We now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: LOLINK

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at LOLINK.

Sincerely,
The Battle.net Account Team
Online Privacy Policy

 awesome, for real

http://azazelx.wordpress.com/ - My Miniatures and Hobby Blog.
apocrypha
Terracotta Army
Posts: 6711

Planes? Shit, I'm terrified to get in my car now!


Reply #323 on: March 30, 2011, 06:02:55 AM

Found this in my Spam folder...



Too Many Attempts Warning No.46

I've been getting one of those a day for a few weeks now. To an email address that has never been used for any WoW accounts.

"Bourgeois society stands at the crossroads, either transition to socialism or regression into barbarism" - Rosa Luxemburg, 1915.
taolurker
Terracotta Army
Posts: 1460


Reply #324 on: April 11, 2011, 07:00:59 AM

Just received an email that is the best imposter phishing email I've ever seen.


The email shows it coming from newsletter@email.blizzard.com, but the links contained within the email direct to www-wowgm-battle.org (which appears to be pretending to be a European WoW login page).

The return path of the email in the Headers shows the message actually originated in Taiwan, and the below visual traceroute actually allowed me to get right down to the exact address.


Even better was the WHOIS information on record for the site that's part of the links:


What's truly funny about this is I've never ever had ANY Warcraft account (not even a free trial) and the only battle.net account I ever had (for Diablo 1/2) was a totally different email address completely.

Beware phishing scams, and I already forwarded this to hacks@blizzard.com just like their website suggests... But then again their site also says "The most important thing to avoid becoming a victim of a malicious website is to make sure your browser and anti-virus software are up-to-date." but mentions nothing about Spyware/Malware (but does recommend: "Check to make sure your browser’s phishing filter is activated.").


I used to write for extinct gaming sites
details available here (unused blog about page)
raydeen
Terracotta Army
Posts: 1246


Reply #325 on: April 11, 2011, 08:09:29 AM

I'm going to start saying 'haha hengheng' now when I think something is funny.

I was drinking when I wrote this, so sue me if it goes astray.
Der Helm
Terracotta Army
Posts: 4025


Reply #326 on: April 11, 2011, 07:48:46 PM

Hm. I got almost the same email, but my links seem to point towards https://www.worldofwarcraft.com/account/claim-promotion.html?promoId=SEVEN_DAYS_PROMOTION

I almost clicked those links. Did I dodge a bullet or did some spammer copy a legit email from blizzard ?

"I've been done enough around here..."- Signe
taolurker
Terracotta Army
Posts: 1460


Reply #327 on: April 11, 2011, 09:18:34 PM

I copied the link and didn't click it (and never visited the site itself), plus part of the link after the www-wowgm address was a login address for the Warcraft page. I have no idea if it was a copied Blizzard email, but I am pretty sure I'd be wary of any offer like this. Also check the message Headers to make sure it's origin was really from Blizzard.


I used to write for extinct gaming sites
details available here (unused blog about page)
Mattemeo
Terracotta Army
Posts: 1128


Reply #328 on: April 12, 2011, 05:38:16 AM

Just received an email that is the best imposter phishing email I've ever seen.


The thing that I noticed instantly that made me think that graphic wasn't quite right is at the very top...

"Dear Players"...

Blizz tend to be more personal. I have a similar promotion graphic but it adresses me by my first name.

The other thing I noticed (but don't know if you decided not to include it in the image you posted) is
that it's missing a whole bunch of legal bunf at the bottom framed in black; ERSB, privacy policy etc.

Still, it's a worryingly sophisticated phish; for all that we laugh at the terrible ones it's worth remembering
there are scammers out there who actually try.

If you party with the Party Prince you get two complimentary after-dinner mints
taolurker
Terracotta Army
Posts: 1460


Reply #329 on: April 12, 2011, 08:45:25 PM

The other thing I noticed (but don't know if you decided not to include it in the image you posted) is
that it's missing a whole bunch of legal bunf at the bottom framed in black; ERSB, privacy policy etc.
There was no legal at the bottom, below the image, and where the screenshot ended was exactly where the image on the phishing email did.

Quote
Still, it's a worryingly sophisticated phish; for all that we laugh at the terrible ones it's worth remembering
there are scammers out there who actually try.
It was very sophisticated, with no usual bad spelling or grammar, and was using a Blizzard logo'd image.


I used to write for extinct gaming sites
details available here (unused blog about page)
WindupAtheist
Army of One
Posts: 7028

Badicalthon


Reply #330 on: June 22, 2011, 04:31:14 AM

Man these Chinese account thieves sure are getting sophisticated.


Looks legit!  awesome, for real

Meanwhile I logged into my actual WoW email for the first time in months to find a still-empty inbox. Which is good since it's never been used for any other purpose ever.
« Last Edit: June 22, 2011, 04:32:57 AM by WindupAtheist »

"You're just a dick who quotes himself in his sig."  --  Schild
"Yeah, it's pretty awesome."  --  Me
Der Helm
Terracotta Army
Posts: 4025


Reply #331 on: July 21, 2011, 05:09:04 AM

What the fuck happened here ?

Quote
Hello zhang,

Welcome to Battle.net!

You have successfully created the following Battle.net account:

myreal.name@googlemail.com

The Battle.net account is a centralized account system that will let you manage all of the Blizzard Entertainment games you play, including World of Warcraft and future games, in one place without having to remember multiple sets of login information.

We highly recommend that you take this opportunity to verify your e-mail address. Verifying your e-mail address will unlock extra Battle.net account features, including the ability to register Blizzard games you own so that you can download them, free of charge, any time you want. To do so, simply click here:

https://sea.battle.net/account/email/confirm.xml?ticket=*snip*

In addition, you may also merge any World of Warcraft accounts you play with this Battle.net account. After merging, you will log in to the game and its associated online services such as World of Warcraft Account Management, the World of Warcraft Forums, and the World of Warcraft Armory, using your Battle.net login information. You can begin the account merge process at the Battle.net account homepage, located at http://www.battle.net/account.

Please retain this e-mail for your reference.

For more information, click here for answers to Frequently Asked Questions or to contact the Blizzard Billing & Account Services team.

Sincerely,
The Battle.net Account Team
Online Privacy Policy

My name is not Zhang, btw.

"I've been done enough around here..."- Signe
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #332 on: July 21, 2011, 05:30:35 AM

Spammer fails at understanding mail merge fields!

The past cannot be changed. The future is yet within your power.
raydeen
Terracotta Army
Posts: 1246


Reply #333 on: July 24, 2011, 07:34:05 AM

Here's a new one. Great idea and they were doing so well up until the second paragraph...

Greetings!

When you take to the skies astride a blazing, eagle-winged lion, your comrades will know you mean business. Serious business. So saddle up, because this flying mount will travel as fast as your riding skill will take you, and it can even travel at 310% speed if you have at least one other 310% speed mount.
Once activated, this World of Warcraft in-game pet key applies to all present and future characters on a single World of Warcraft license.
we will be complimentary seat to the 5,000 players. You can log Web site application, we will be lucky players randomly.
Please click this link to apply
http://us.battle.net.login.worldofwarrcraft.tk/battle_net_account.html?ref=https%3A%2F%2Fus.battle.net%2Faccount%2Fmanagement%2Findex.xml&app=bam&t=1

If your account passes the check successfully, we will send a code for the Winged Guardian flying mount to you in the form of e-mail.
The World of Warcraft Support Team
Blizzard Entertainment

I was drinking when I wrote this, so sue me if it goes astray.
Kail
Terracotta Army
Posts: 2858


Reply #334 on: September 24, 2011, 07:31:29 PM

Here's a new one. Great idea and they were doing so well up until the second paragraph...

Greetings!

When you take to the skies astride a blazing, eagle-winged lion, your comrades will know you mean business. Serious business. So saddle up, because this flying mount will travel as fast as your riding skill will take you, and it can even travel at 310% speed if you have at least one other 310% speed mount (etc. etc.)

Jesus, just got this one (except slighty improved grammar, and it was faking the EU WoW site) and almost died to it.  It had background art and everything, and it got through my spam filter (which usually doesn't let anything through).  Fortunately, my virus checker kicked me in the balls when I hit the link.
Ironwood
Terracotta Army
Posts: 28240


Reply #335 on: October 02, 2011, 09:22:42 AM

I gave up playing about a year ago.

I've just got an actual legitimate mail from Blizzard banning me for bad stuff.  I sort out the account issues and look at the account to find someone applied a gamecard to the account for this purpose.

What the fuck ?

 ACK!

"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Xuri
Terracotta Army
Posts: 1199

몇살이세욬ㅋ 몇살이 몇살 몇살이세욬ㅋ!!!!!1!


WWW
Reply #336 on: October 02, 2011, 10:10:44 AM

Interesting. Just checked my own account + account history, and while the account history shows that my three-month subscription lapsed in november 2010, under "Game time" on the main page it now says "Expired: 2/5/2011 12:24 PM". Hrm.

-= Ho Eyo He Hum =-
Ironwood
Terracotta Army
Posts: 28240


Reply #337 on: October 02, 2011, 10:12:31 AM

As far as I can see, someone used my account to log on, shout shit in general, get banned and that's it.

And it cost them to do so.

I'm really, really not seeing the point of this.  Nor how they managed it.  I'm clean as a whistle.

"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Rokal
Terracotta Army
Posts: 1652


Reply #338 on: October 02, 2011, 01:39:46 PM

Use the same login/password on shitty websites like kotaku or random forums > website/forums get hacked > hackers try the username/password on every MMO > profit.
Ironwood
Terracotta Army
Posts: 28240


Reply #339 on: October 02, 2011, 02:46:40 PM

Yeah, I get that.  I have one WoW Password.  It has it's own E-mail account.

I really don't get it.

Edited to add :

The amount of fucking ORE they left on my chaps and GOLD on my other alt is fucking unbelievable.  I mean, really, really unbelievable.  Given that I don't play anymore, I shouldn't have bothered to report this and just sent the whole lot to the Guild or my wife or something.

Online games are mental.  The idea that there's a market in this is just MENTAL.

I used to wade through it without bothering, but when it's filling your bags, it really makes you think.
« Last Edit: October 02, 2011, 02:49:15 PM by Ironwood »

"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #340 on: October 02, 2011, 03:49:06 PM

You've never used that e-mail account anywhere else? Not even your old guild's forums or as a Wowhead login or something similar?

Sounds like it wasn't the usual gold spammer looking to strip an account but someone stole the account and sold it.   If you haven't played in a year I don't get why they would have, since you'd be lacking the expansion.

The past cannot be changed. The future is yet within your power.
Fordel
Terracotta Army
Posts: 8306


Reply #341 on: October 02, 2011, 04:22:37 PM

Maybe it was a middle man mule or whatever?

and the gate is like I TOO AM CAPABLE OF SPEECH
Lantyssa
Terracotta Army
Posts: 20848


Reply #342 on: October 02, 2011, 04:28:52 PM

Probably that or a miner bot since it was loaded down with ore and gold.

Hahahaha!  I'm really good at this!
Ironwood
Terracotta Army
Posts: 28240


Reply #343 on: October 03, 2011, 02:11:41 PM

Yeah, there was defo Botting going on.  I have all the 'oversized' bags and they were fucking full of Eternium and Pyrite.  Enough to make well over 550 bars.

My drood was clearly the fence, since he had about 100,000 in AH mail in his inbox and about 50,000 on his person.

Which is more gold than I've ever, ever had, I suspect.

It was mental.  Utterly mental. 

Since I told Blizzard that the Timecard wasn't mine, they took that away also.  So I can't even log in to find out what state I was left in.


"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Mattemeo
Terracotta Army
Posts: 1128


Reply #344 on: October 04, 2011, 11:43:05 PM

Phishers are getting fast. 24 hour gap between the legit Blizzcon Foo Fighters e-flyer and the scam Foo Fighters e-flyer that got filtered to my junk folder. Little fuck ups include a ? instead of a © and bullet points, and replacing my name with 'Warrior of Azeroth'. Oh, and the ludicrously long url hyperlinks on mouse-over, naturally.

If you party with the Party Prince you get two complimentary after-dinner mints
Phred
Terracotta Army
Posts: 2025


Reply #345 on: October 24, 2011, 10:22:19 AM

I gave up playing about a year ago.

I've just got an actual legitimate mail from Blizzard banning me for bad stuff.  I sort out the account issues and look at the account to find someone applied a gamecard to the account for this purpose.

What the fuck ?

 ACK!

That happened to me last summer after not having played for almost a year as well. I sorted it out with support and asked them to leave my account banned so no one could steal it again. Some one told me at the time that Battle.net had no anti-brute force stuff applied at all. i.e. you could spam it with password guesses and it wouldn't even slow down much less stop talking to you.



« Last Edit: October 24, 2011, 10:31:22 AM by Phred »
Azazel
Contributor
Posts: 7735


Reply #346 on: October 24, 2011, 09:13:36 PM

Yeah, happened to me as well just before Cata came out. I ended up with a free month and a half since they left the gamecard time on there even after they restored my stuff.


http://azazelx.wordpress.com/ - My Miniatures and Hobby Blog.
Pages: 1 ... 8 9 [10] Go Up Print 
f13.net  |  f13.net General Forums  |  The Gaming Graveyard  |  World of Warcraft  |  Topic: My WoW-account's been compromised  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC