Something went wrong. Try again later
    Follow

    Guild Wars 2

    Game » consists of 3 releases. Released Aug 28, 2012

    Guild Wars 2 is an online RPG developed by ArenaNet, and continues the subscriptionless business model of the original Guild Wars. The game is set about 250 years after the events of its predecessor in a world devastated by the ancient elder dragons resurfacing after millennia of slumber.

    BEWARE-email "guild wars 2 password reset"

    Avatar image for announakis
    announakis

    153

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #1  Edited By announakis

    if like me you received an email with such a title looking very legit (because apparently it is, I do not know how anet fucked up but they did), breathe and do not hit the link if you did not request it yourself...a lot of people are being hacked at the moment...

    here is the link to the discussion on guru

    http://www.guildwars2guru.com/topic/56227-beware-do-not-click-password-reset-email-links-from-arenanet/

    Avatar image for deactivated-5e49e9175da37
    deactivated-5e49e9175da37

    10812

    Forum Posts

    782

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 14

    Oldest phishing trick in the Massively Multiplayer Book.

    Avatar image for announakis
    announakis

    153

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #3  Edited By announakis

    @Brodehouse said:

    Oldest phishing trick in the Massively Multiplayer Book.

    apparently this is not phsshing trick, this is the sad part: people report that there is no ASCii trick in the adress of the sender, the sender is indeed Anet...

    Avatar image for emem
    emem

    2063

    Forum Posts

    13

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #4  Edited By emem
    @announakis said:

    @Brodehouse said:

    Oldest phishing trick in the Massively Multiplayer Book.

    apparently this is not phsshing trick, this is the sad part: people report that there is no ASCii trick in the adress of the sender, the sender is indeed Anet...

    Mails like that are never from the developer, it's always a slightly different address...
    Avatar image for barrock
    Barrock

    4185

    Forum Posts

    133

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #5  Edited By Barrock

    I got that as well. Just figured someone just entered my email from a big list.

    Avatar image for thecreamfilling
    TheCreamFilling

    1235

    Forum Posts

    832

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #6  Edited By TheCreamFilling

    The developers are hacking their own game?

    Avatar image for deactivated-5c5cdba6e0b96
    deactivated-5c5cdba6e0b96

    8259

    Forum Posts

    51

    Wiki Points

    0

    Followers

    Reviews: 3

    User Lists: 3

    Fuck, I almost clicked the link, thanks for the heads up man.

    Avatar image for deactivated-5c5cdba6e0b96
    deactivated-5c5cdba6e0b96

    8259

    Forum Posts

    51

    Wiki Points

    0

    Followers

    Reviews: 3

    User Lists: 3

    @emem said:

    @announakis said:

    @Brodehouse said:

    Oldest phishing trick in the Massively Multiplayer Book.

    apparently this is not phsshing trick, this is the sad part: people report that there is no ASCii trick in the adress of the sender, the sender is indeed Anet...

    Mails like that are never from the developer, it's always a slightly different address...

    Here is the email.

    No Caption Provided
    Avatar image for musubi
    musubi

    17524

    Forum Posts

    5650

    Wiki Points

    0

    Followers

    Reviews: 8

    User Lists: 17

    #9  Edited By musubi

    @Bucketdeth: Thats....pretty official looking. Most phishing scams try to goad you into clicking the link by being all YOU GOTTA SORT THIS SHIT OUT MAN ELSE WE GONNA DELETE YOUR ACCOUNT. Or some other nonsense. Weird.

    Avatar image for nergrim
    Nergrim

    140

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #10  Edited By Nergrim

    I was really close to clicking the link in the mail.

    It looks exactly the same as the real change password mail you get from Anet.

    Avatar image for emem
    emem

    2063

    Forum Posts

    13

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #11  Edited By emem
    @Bucketdeth said:

    @emem said:

    @announakis said:

    @Brodehouse said:

    Oldest phishing trick in the Massively Multiplayer Book.

    apparently this is not phsshing trick, this is the sad part: people report that there is no ASCii trick in the adress of the sender, the sender is indeed Anet...

    Mails like that are never from the developer, it's always a slightly different address...

    Here is the email.

             
    No Caption Provided

    Hm, as far as I understand people can make it look like mails came from specific email addresses and if yours is a phishing mail I doubt that any of the links will lead to the real Anet/GW2 site. Anyway, the important thing is just to not click on links in general unless you have requested them yourself, it's been like that for years. If you get a suspicious mail, open your browser and go to the known official website in question and check it out.
    Avatar image for ussjtrunks
    UssjTrunks

    549

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #12  Edited By UssjTrunks

    When you change your password, you don't get a confirmation email. So these are fake. However, allowing people to change passwords without a confirmation email is not secure at all.

    Avatar image for gantrathor
    Gantrathor

    298

    Forum Posts

    474

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #13  Edited By Gantrathor

    It actually looks exactly like the email you get when you change the password to your NCSoft master account.

    Avatar image for ussjtrunks
    UssjTrunks

    549

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #14  Edited By UssjTrunks

    @Gantrathor said:

    It actually looks exactly like the email you get when you change the password to your NCSoft master account.

    Changing the password of your GW2 account on the official website doesn't send out an email (I've done it a few times already). Besides, that email is supposedly from Arenanet, not NCsoft.

    Avatar image for gantrathor
    Gantrathor

    298

    Forum Posts

    474

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #15  Edited By Gantrathor

    @UssjTrunks: I know, I was just pointing out that it looks like the NCSoft master account statement. That's why it's funny, because you don't even need to use an NCSoft account for Guild Wars 2.

    Avatar image for deactivated-5e60061752a57
    deactivated-5e60061752a57

    752

    Forum Posts

    96

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    Gotten 3 of these so far. Pretty annoying.

    Avatar image for chubbysumo
    chubbysumo

    2

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #17  Edited By chubbysumo

    Just so you guys know, but these are legit emails. They are not phish attempts, the header info checks out. The hack is a two step process. the password reset is the hacker actually just confirming that you are using a known email(either guessing based on in game character names, or from the recent MMO site hacking spree from china). It practically spits out a yes or a no. it either gives them a glaring error(email not in database), or tells them one has been sent. Once they know an email is live, they then use either pre-gleaned passwords from other MMO sites that were hacked, or then phish the shit out of your email. I can confirm that the hackers do not need access to your email account, and many are in fact losing access to their email accounts after their GW2 accounts, and those same people report that they used the same password across services. Use a clean(new) email, and a new password, and you foil their attempts at a hack/phish. There is also a server side hole, since people are getting hacked eevn without recieving the password reset email. Also, all the IPs that are being reported are from china, go figure.

    Avatar image for pekarn
    pekarn

    89

    Forum Posts

    87

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #18  Edited By pekarn

    Why would anyone click the link in a password reset mail you didn't request?

    Avatar image for eccentrix
    eccentrix

    3250

    Forum Posts

    12459

    Wiki Points

    0

    Followers

    Reviews: 4

    User Lists: 15

    #19  Edited By eccentrix

    @pekarn said:

    Why would anyone click the link in a password reset mail you didn't request?

    Especially after it specifically tells you not to in the email.

    Avatar image for magickeys
    Magickeys

    43

    Forum Posts

    34

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #20  Edited By Magickeys

    @Brodehouse said:

    Oldest phishing trick in the Massively Multiplayer Book.

    Yeah, I received one just this morning. This trick is getting old by the way, bunch of idiots.

    And I don't have the game yet also, double idiots :)

    Avatar image for nihilius
    Nihilius

    174

    Forum Posts

    1

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #21  Edited By Nihilius

    I got one of these today, I turned on gmail 2 step verification a few days ago so I am not all that worried. They should have given us some secret questions and answers so that this wouldn't of happened. Also the lack of a Security Token available at launch is a bad decision.

    Avatar image for robbiemac
    RobbieMac

    561

    Forum Posts

    5778

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #22  Edited By RobbieMac

    Woke up and I had 6 of them in my box. Lol, fail.

    Avatar image for ehker
    Ehker

    233

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #23  Edited By Ehker

    I didn't get one, but it seems something was up with the password reset, because they've shut it down.

    http://en.support.guildwars2.com/

    Announcements:

    • The Guild Wars 2 reset password feature is currently unavailable.
    Avatar image for jozzy
    jozzy

    2053

    Forum Posts

    1

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #24  Edited By jozzy

    I got this e-mail, and I don't even play Guildwars 2 (yet).

    Avatar image for gaff
    Gaff

    2768

    Forum Posts

    120

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #25  Edited By Gaff

    @pekarn said:

    Why would anyone click a link in an e-mail you didn't solicit?

    Fixed.

    Avatar image for bestostero
    Bestostero

    2919

    Forum Posts

    13401

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 2

    #26  Edited By Bestostero

    well im angry i didnt get a phishing email! am i not special enough for one!? lol

    Avatar image for psylah
    psylah

    2362

    Forum Posts

    100

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #27  Edited By psylah

    I got one of these e-mails, which is hilarious, because I haven't played GW 1 or 2, and I don't even have an Arenanet account!

    Anyways, pro tip:

    If you get an e-mail that makes you concerned that an account of yours has been compromised, don't click links in the e-mail, go to the website yourself and navigate to the appropriate page.

    Avatar image for maystack
    Maystack

    941

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #28  Edited By Maystack

    Just got an email saying I need to authorise a login. So glad that ANet put that system in.

    Avatar image for dagbiker
    Dagbiker

    7057

    Forum Posts

    1019

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 16

    #29  Edited By Dagbiker

    I got one of these, I also got an Email from Norman Chan:

    Hello, I'm Norman Chan Tak-Lam, S.B.S., J.P, Chief Executive, Hong Kong Monetary Authority. I need a confirmation of acceptance to handle a Business worth $47.1M USD with me. Contact me for more info.
    Avatar image for psylah
    psylah

    2362

    Forum Posts

    100

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #30  Edited By psylah

    @Dagbiker said:

    I got one of these, I also got an Email from Norman Chan:

    Hello, I'm Norman Chan Tak-Lam, S.B.S., J.P, Chief Executive, Hong Kong Monetary Authority. I need a confirmation of acceptance to handle a Business worth $47.1M USD with me. Contact me for more info.

    I'd believe it, now that he's a big star on Mythbusters!

    Avatar image for jesterroyal
    jesterroyal

    393

    Forum Posts

    336

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #31  Edited By jesterroyal

    @Dagbiker: You totally hit the jackpot. You need to act on that. 47 million dollars? These opportunities come around once in a life time. Have you contacted him back yet? Is Jamie and or Adam his angel funder?

    Avatar image for herocide
    herocide

    451

    Forum Posts

    2

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #32  Edited By herocide

    @chubbysumo said:

    Just so you guys know, but these are legit emails. They are not phish attempts, the header info checks out. The hack is a two step process. the password reset is the hacker actually just confirming that you are using a known email(either guessing based on in game character names, or from the recent MMO site hacking spree from china). It practically spits out a yes or a no. it either gives them a glaring error(email not in database), or tells them one has been sent. Once they know an email is live, they then use either pre-gleaned passwords from other MMO sites that were hacked, or then phish the shit out of your email. I can confirm that the hackers do not need access to your email account, and many are in fact losing access to their email accounts after their GW2 accounts, and those same people report that they used the same password across services. Use a clean(new) email, and a new password, and you foil their attempts at a hack/phish. There is also a server side hole, since people are getting hacked eevn without recieving the password reset email. Also, all the IPs that are being reported are from china, go figure.

    In spite of this being this guy's first post; he's right.

    Avatar image for whytepanther
    WhytePanther

    113

    Forum Posts

    80

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #33  Edited By WhytePanther

    I got one yesterday as well. Except mine didn't say it was a password change, but rather a change to the e-mail address of my account. Oh, and I also don't have a copy of GW2. I did have GW1 on that address, so I put in a ticket (after typing the address myself, of course), when I discovered I couldn't log in to the website with that address. The site said there was no account with the e-mail address, but it did seem to indicate that GW1 account should have been able to log in. That was a day ago and now after doing a little legwork, and finding the e-mail asking me to click the link to confirm the change of address in my spam folder with the exact same timestamp as the e-mail confirming it's been accepted, I've decided to redownload the GW1 client and see what happens. But I'm at PAX and my hotel has pretty crappy WiFi, so I'll have to check up on it in the morning.

    If my account was actually stolen, my guess is there are two points to this hack. First, is that they are using some known list of e-mail addresses and passwords (I had a WoW account hacked three years ago that probably had the same password then as I used the last time I actually played Guild Wars). Second, they are somehow locating the key to confirm the e-mail address without actually accessing the e-mail (or they have mine and aren't showing any other indication of that, but my e-mail is most definitely under a different password than it was then.) The fact that web password changes are down right now seems to feed that theory.

    Edit: Guild Wars downloaded to a playable state over night. GW client tells me the e-mail address is not recognized. And since I almost never delete any e-mails ever, I still have the original account activation e-mail from 2004 for my GW1 account. Still no word from ArenaNet.

    This edit will also create new pages on Giant Bomb for:

    Beware, you are proposing to add brand new pages to the wiki along with your edits. Make sure this is what you intended. This will likely increase the time it takes for your changes to go live.

    Comment and Save

    Until you earn 1000 points all your submissions need to be vetted by other Giant Bomb users. This process takes no more than a few hours and we'll send you an email once approved.