Something went wrong. Try again later
    Follow

    World of Warcraft

    Game » consists of 9 releases. Released Nov 23, 2004

    World of Warcraft is an MMORPG that takes place in Blizzard Entertainment's Warcraft universe. At its peak, it boasted a player base of over 12.5 million subscribers, making it the most popular MMO of all time.

    So... account hacked?

    Avatar image for cgoodno
    cgoodno

    172

    Forum Posts

    26

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #1  Edited By cgoodno

    Looks like it based on the two e-mails I got today (yes, they're official and not phishes, and I've confirmed by trying to log into my account, which is now suspended).
     
    Anyone else been hacked and how did it happen?  I'm thoroughly confused since:

    1. I use Firefox + NoScript + ABP
    2. I use LastPass for site logins
    3. I've never visited a gold selling site
    4. I always have BitDefender up and running
     
    Currently scanning using SpyBot S&D to see if there's anything, but it's very unlikely.  I'm sure I'll hear back from Blizzard in the next week on my account, hope I don't have to start all over again *sighs*.  Hell, I might as well just screw it if I do.
     
    Quick Update: SpyBot found nada.  Yay.
    Avatar image for deegee
    DeeGee

    2193

    Forum Posts

    54

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #2  Edited By DeeGee

    They guessed your password.

    Avatar image for fritzdude
    FritzDude

    2316

    Forum Posts

    3064

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #3  Edited By FritzDude
    @DeeGee said:
    "They guessed your password.

                       

                    "

    This seems logically.
    Avatar image for helushune
    Helushune

    214

    Forum Posts

    535

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #4  Edited By Helushune

    Is it linked to your facebook account?  That's an incredibly easy way to get your password and account info.

    Avatar image for cgoodno
    cgoodno

    172

    Forum Posts

    26

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #5  Edited By cgoodno

    Ah, yes, ever so helpful!  They must have guessed my e-mail address as well, which is saved in my login profile ... *sighs*
     
    Anyone of help or just jokers?

    Avatar image for deegee
    DeeGee

    2193

    Forum Posts

    54

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 4

    #6  Edited By DeeGee

    There are plenty of ways to find out your email address.

    Avatar image for themustachehero
    TheMustacheHero

    6647

    Forum Posts

    120

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 0

    #7  Edited By TheMustacheHero

    My account has been hacked twice- Then I grew a brain and downloaded the Authenticator app on my iPod, haven't had any problems since.
     
    You should do the same...if you've got an iPod touch.

    Avatar image for cgoodno
    cgoodno

    172

    Forum Posts

    26

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #8  Edited By cgoodno
    @DeeGee said:
    " There are plenty of ways to find out your email address. "

    And how would they know to find out my e-mail address specifically?  I'd need to have downloaded one of their keyloggers or similar... which I'm completely free of after scanning with BitDefender, AVG, and SpyBot.
     
    @Helushune said:

    " Is it linked to your facebook account?  That's an incredibly easy way to get your password and account info. "

    Absolutely not.  
     
    @TheMustacheHero said:

    " My account has been hacked twice- Then I grew a brain and downloaded the Authenticator app on my iPod, haven't had any problems since.  You should do the same...if you've got an iPod touch. "


    I'll have to do this.  I've been searching on this and no one seems to know much on anything tangible other than the typical "visited a gold selling site", "learn to use firefox", "stop watching p0rn", etc.
     
    Thanks for a helpful response.
    Avatar image for skytylz
    Skytylz

    4156

    Forum Posts

    9

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 6

    #9  Edited By Skytylz

    I would probably have heart failure if I played WoW and I got hacked.  That sucks dude, hope you get it figured out.

    Avatar image for helushune
    Helushune

    214

    Forum Posts

    535

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #10  Edited By Helushune
    @cgoodno: Heh, you never know.  I watched three friends of mine foolishly link their accounts and all get hacked within the week. 
     
    But yeah, grab the blizzard authenticator for your smartphone/iDevice.  Doesn't make it hack-proof but it's better than nothing.  They also offer a phone-in service that supposedly tracks what IP you normally log in from and if it detects anything out of the ordinary it requires you to call a number and enter a pin from a phone that you setup.
    Avatar image for crixaliz
    Crixaliz

    809

    Forum Posts

    78

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #11  Edited By Crixaliz

    I got the same email and my account is also frozen. I logged on and all my characters were still there (couldn't see the gear since they are inactive).
    Just attach the Authenticator, i just did that myself. 
    Do you by any chance have an account on some WoW related website?

    Avatar image for ganglymonster
    GanglyMonster

    42

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #12  Edited By GanglyMonster

    owned

    Avatar image for cgoodno
    cgoodno

    172

    Forum Posts

    26

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #13  Edited By cgoodno
    @Crixaliz said:
    " I got the same email and my account is also frozen. I logged on and all my characters were still there (couldn't see the gear since they are inactive). Just attach the Authenticator, i just did that myself.  Do you by any chance have an account on some WoW related website? "
    Nah.  Just here and N4G, and they use different credentials.
    Avatar image for levio
    Levio

    1953

    Forum Posts

    11

    Wiki Points

    0

    Followers

    Reviews: 9

    User Lists: 0

    #14  Edited By Levio

    Blizzard is probably fake-hacking accounts to push the sales of authenticators.
     
    Remember, Bobby is in charge now.

    Avatar image for epicsteve
    EpicSteve

    6908

    Forum Posts

    13016

    Wiki Points

    0

    Followers

    Reviews: 89

    User Lists: 11

    #15  Edited By EpicSteve

    It happens a lot in WoW now. Most serious players have some sort of protection, like having two passwords.

    Avatar image for cgoodno
    cgoodno

    172

    Forum Posts

    26

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #16  Edited By cgoodno
    @Levio said:
    " Blizzard is probably fake-hacking accounts to push the sales of authenticators.  Remember, Bobby is in charge now. "
    The one for the iPhone is free, though...
    Avatar image for shirogane
    shirogane

    3647

    Forum Posts

    132

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #17  Edited By shirogane

    Yeah, my account got hacked sometime mid last year, while i didn't have an active sub. They actually referred themselves and got me a sub month, then did weird stuff with my account which got it banned, which got me a message from Blizzard, which is how i knew. No idea how they got my account info though, i hadn't logged on for ages, didn't even have WoW installed.
    Avatar image for gilbert64
    Gilbert64

    64

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 0

    #18  Edited By Gilbert64

     It's always the same reasons
     In the order of likeliness
    1. you shared your account info (friends,leveling service etc.)
    2. you used the same password for multiple sites
    3. you got drive by malware on some shady website/download
    or something people talk about all the time but never happens, some super hacker hacked blizzard, they guessed your password (or i hope your password wasn't 1234) or they are trying to sell authenticators (strange since the app is free)
     
    in your case I would guess (assuming your not stupid and did 1.) your LastPass database that got comprised since its a fairly fat target.  (i.e. nr. 2)
     
    You should never store your password in digital format if it's something you really care about .
    Easiest thing is just to write it down on a piece of paper, unless physical security is an issue.

    Avatar image for cgoodno
    cgoodno

    172

    Forum Posts

    26

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 3

    #19  Edited By cgoodno
    @Gilbert64 said:
    "  It's always the same reasons  In the order of likeliness 1. you shared your account info (friends,leveling service etc.) 2. you used the same password for multiple sites 3. you got drive by malware on some shady website/download or something people talk about all the time but never happens, some super hacker hacked blizzard, they guessed your password (or i hope your password wasn't 1234) or they are trying to sell authenticators (strange since the app is free)   in your case I would guess (assuming your not stupid and did 1.) your LastPass database that got comprised since its a fairly fat target.  (i.e. nr. 2)   You should never store your password in digital format if it's something you really care about . Easiest thing is just to write it down on a piece of paper, unless physical security is an issue. "
    Actually, LastPass is better than re-entering a password and login credentials you use often.  It's encrypted and easily deleted from a computer and can't be tracked by malware.  It doesn't solve any issues with there being vulnerabilities on sites that may have issues in sending username and password data to and from the server in an unsafe manner.  As for my case, my password isn't the same as any others that I use.
    Avatar image for toowalrus
    toowalrus

    13408

    Forum Posts

    29

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 3

    #20  Edited By toowalrus

    My roommate was hacked too, and was just as careful as you. He refused to use an authenticator. First, you're going to have to get everything straight, open tickets, get all your shit back in the in-game mail- it'll probably take a week. Then, you should follow the advice I gave him before he even started playing- Get an authenticator, dumbass.

    Avatar image for impendingfoil
    ImpendingFoil

    587

    Forum Posts

    23

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #21  Edited By ImpendingFoil

    This just happened to me last week.  I emailed Blizzard and they sent me some kind of appeal form I need to fill out.  I have not touched WoW in years but I do enjoy Starcraft II from time to time.  I should probably be filling the form out soon.

    Avatar image for bloodgraiv3
    Bloodgraiv3

    2730

    Forum Posts

    2380

    Wiki Points

    0

    Followers

    Reviews: 9

    User Lists: 9

    #22  Edited By Bloodgraiv3

    Be smarter with your info next time, and don't link it to fb >>
    Avatar image for marz
    Marz

    6097

    Forum Posts

    755

    Wiki Points

    0

    Followers

    Reviews: 5

    User Lists: 11

    #23  Edited By Marz

    I sleep better at night knowing i have one of these.

    No Caption Provided
    Avatar image for cl60
    CL60

    17117

    Forum Posts

    -1

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 5

    #24  Edited By CL60
    @Marz said:
    " I sleep better at night knowing i have one of these.

    No Caption Provided
    "
    Me too...me too..
    Avatar image for zimbodk
    ZimboDK

    863

    Forum Posts

    20

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 2

    #25  Edited By ZimboDK

    weee, I just got hacked too.
     
    So, my account was created back when I didn't really have any password policies. Oh, and so was my gmail account. Got an email from Blizzard: Blah blah, account locked. Sure enough, I can't login. Just in case, I look in my deleted mail folder. Empty. Spam folder: 2 password reset mails from Blizzard. Well, fuck. They accessed my gmail account. I looked in access details and sure enough, an IP from China and one from Korea. Sign out all sessions, change password. I have seperate accounts for all my Blizzard games, so I only have WoW on that account, no big deal.
     
    My password was a random combo of different letters, so there's no way they could've just guessed it out of the blue.
     
    There are basically 4 options:
     
    A trojan or keylogger was installed on my PC. Nope. I scan my PC religiously and run almost everything sandboxed, so that can't be it. I looked for unknown processes just in case, but there was nothing unusual.
     
    Back when I did play WoW a lot, I may have bought some gold. That was years ago though, and I'm not totally convinced they would save that data for years and just try it out randomly. 
     
    Yesterday, I installed Chrome and some extensions. There is a very remote chance that a trojan could have been embedded in one of the extensions. I seriously doubt that though.
     
    Also yesterday, I installed a new hard drive on my nephew's PC. While we were waiting for his Steam folder to be copied over to the new drive, I checked my gmail. Then we started talking about WoW, and I visited the WoW site. I think that may have been a mistake. He's 14 and downloads a ton of stuff that may not be entirely legal. He's basically an internet noob. I've done what I could to educate him on Internet safety, but he still seems to be very indiscriminate about what sort of files he opens. And I think he has one or more trojans on his comp. I'm going over there tomorrow to check it out.

    Avatar image for melcene
    melcene

    3214

    Forum Posts

    1475

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 9

    #26  Edited By melcene
    @Levio said:

    " Blizzard is probably fake-hacking accounts to push the sales of authenticators.  Remember, Bobby is in charge now. "

    Actually, I have heard many stories that make me wonder about this.  There are just too many careful people out there who get hacked.
     
    I got hacked myself in Sept 09.  I was also a guild leader at the time so that really sucked.   What really ticked me off is that the hacker was still on my account at the time I found out (my husband was logged into his own account and saw my toons running around).  I CALLED Blizz and told them, and asked if they could IP ban the hacker or anything.  They told me they "are not an investigative unit" and couldn't do anything about the hacker, but would change the password on the account for me.
     
    Authenticators are pretty much necessary now. 
     
     
    @ZimboDK said:
    "  Back when I did play WoW a lot, I may have bought some gold.  "  
     This made me laugh.  :)
    Avatar image for hexx462
    hexx462

    506

    Forum Posts

    0

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 1

    #27  Edited By hexx462
    @ZimboDK said:
    "  Back when I did play WoW a lot, I may have bought some gold. That was years ago though, and I'm not totally convinced they would save that data for years and just try it out randomly."
    I wouldn't put it past gold sellers to pull stunts like that. I do know people that bought gold and were hacked later on. Have to say it serves them right though, supporting gold farmers is such a douche move.
    Avatar image for alphiehyr
    Alphiehyr

    1177

    Forum Posts

    -1

    Wiki Points

    0

    Followers

    Reviews: 0

    User Lists: 2

    #28  Edited By Alphiehyr
    @cgoodno said:

    " Looks like it based on the two e-mails I got today (yes, they're official and not phishes, and I've confirmed by trying to log into my account, which is now suspended).
     
    Anyone else been hacked and how did it happen?  I'm thoroughly confused since:

    1. I use Firefox + NoScript + ABP
    2. I use LastPass for site logins
    3. I've never visited a gold selling site
    4. I always have BitDefender up and running
     Currently scanning using SpyBot S&D to see if there's anything, but it's very unlikely.  I'm sure I'll hear back from Blizzard in the next week on my account, hope I don't have to start all over again *sighs*.  Hell, I might as well just screw it if I do.  Quick Update: SpyBot found nada.  Yay. "
    Here's a way to never get hacked:
    1. Buy a second Hard Disk. The only things you should have in that Hard Disk is an Operating System, Kaspersky or Norton 2010, fully updated windows and World of Warcraft.
    2. Create a email solely for WoW.
    3. Only browse WoW's main site and email mentioned on step 2. Bookmark them if you need to.
    4. Do not click on any third party links which are usually found on WoW's forums. Take caution when clicking on official links such as the ones found on the announcements. Do not click on any emails that aren't from Blizzard - the official ones should appear on Contact Us link, displayed on their official website. Junk/Phishing Scam/Delete the rest.
    5. Always have a password that is long and unfamiliar. Change your password every month or if your paranoid, once a week.
    6. If you need to browse music, websites, videos or use a voice communication program, either have a laptop handy or turn off your comp, plug in your first hard disk (after unplugging your second HDD).
     
    It's a shame after all these years people still get hacked. It must be true when they say the newer generations are more stupid.
    Avatar image for artelinarose
    artelinarose

    1999

    Forum Posts

    470

    Wiki Points

    0

    Followers

    Reviews: 1

    User Lists: 0

    #29  Edited By artelinarose

    Just to add my useless advice here, I use barcodes for my passwords. Find something and keep it nearby so you can reference the numbers as you memorize it. Interject random letters as you see fit. I switch mine every time I buy a new game.

    This edit will also create new pages on Giant Bomb for:

    Beware, you are proposing to add brand new pages to the wiki along with your edits. Make sure this is what you intended. This will likely increase the time it takes for your changes to go live.

    Comment and Save

    Until you earn 1000 points all your submissions need to be vetted by other Giant Bomb users. This process takes no more than a few hours and we'll send you an email once approved.