How did I get hacked?

#0 - May 7, 2009, 3:31 p.m.
Blizzard Post
Yesterday my wow account got hacked.
someone logged into wow, took everything from guild bank of value and my bank and auctioned it.
took all my gold, basically ran off with over 35k in gold

so i wonder how did it happen?
my computer was recently formatted to put windows 7 last week
i run antispyware and anitivirus software
i only use one computer to play wow and i'm only person to use my computer
my wow account has a unique password. i've been playing wow for nearly 4.5 years now, never been an issue until now.

but there is a tell tale.
when I went to login it asked me for a mobile authenticator code. I don't use those and never have yet my account some how was associated with it!

i have an iphone 2G with firmware 2.2 on it, so i check the apple app store and sure enough there is a free battle.net mobile authenticator app, i could not d/l and install because it requires firmware 2.2.1

but is it possible via this app, to hack into someones account? how did they associate the account with the mobile authenticator

a big thank you to blizzard, they suspended the account due to suspicious activity, once the 3 hour ban was over, i tried to login but could not at which point i called account management tech support.

the irony is blizzard does provide phone support for the mobile authenticator. i was able to have them remove the authenticator association to my account, reset my password which let me login.

nothing is impossible, maybe a trojan or keylogger who knows but somehow they associated my account to that mobile authenticator which can be downloaded from the apple app store. so be careful maybe there is way to exploit it as i'm very confident no one knows my password.

how did they get my account name i wonder? how they got the password bewilders me.
#31 - May 8, 2009, 4:15 p.m.
Blizzard Post
Good morning, Zen.

Unfortunately, it's virtually impossible for me to determine the point of entry in which a malicious party gained access to your account information, but it's entirely possible that your unrelated reformat has knocked out any malicious software previously installed on your machine.

A common misconception we see on a daily basis is the idea that all compromises occur immediately after malicious software is installed on a computer. It's entirely possible that your account information has been known for an extended amount of time, and the compromising party simply had not yet made themselves known. As such, it can be incredibly difficult to determine exactly how a compromise has occurred.

My best advice would be to continue scanning your computer regularly. Additionally, you may find the following threads useful for both recovering and securing your account:

Computer Security Recommendations:
http://forums.worldofwarcraft.com/thread.html?topicId=1778038509&sid=1

Account Compromise Info Center:
http://forums.worldofwarcraft.com/thread.html?topicId=14318909866&sid=1

As always, please feel free to let us know if you have any questions.