Hacking scandal???

#0 - June 1, 2010, 2:45 a.m.
Blizzard Post
I recently had my acct hacked. I've always been very good about not falling for all the stupid spam messages in /2, and I even report every one I see in a ticket. I have scanned my hard drive mulitple times and I've come up clean each time. I've made no recent changes to add-ons or any such activity that could possibly lead to any comprimising of my acct..............except joining the Elitist Jerks forums just 2 days before being hacked.

I'm not sure that's what happened, nor am I directly accusing them of being associated w/ acct hacking, but I do find it to be an odd coincidence. I admit to making the mistake of using the same acct name and password for both my WoW acct and my Elitist Jerks acct. This was foolish on my part, surely.

I had just waited my 1 day waiting period to be allowed to post on the EJ forums, made my initial post and had it deleted by mods the next day. I received an email from EJ letting me know the post had been removed and that I'd received a 1pt penalty to my EJ acct along w/ a rather douchey message explaining why it had been deleted. Within a matter of a couple hours, my acct was being hacked.

I am curious to ask the masses of ppl whom have been hacked if they'd also been members of the EJ forums prior to the hacking. I suspect its something most ppl would overlook, but I've taken careful precautions to not be hacked and this is the only thing that I'd changed in my normal routine in quite some time.

On another note, I'd like to comment on the irony of Blizzard's implimentation of acct authenticators intended to be used to secure our accts, when it seems to have become rather commonplace for these acct hackers to now be using these authenticators to assist in their thievery. Once they gain access to an acct, they place an authenticator on it to prevent the original owner from logging in and bumping the hacker off the stolen acct. I had discovered my acct being hacked before any damage had been done, but because I couldn't get into my acct to kick the hacker offline, I wasn't able to stop him. I did go to my acct manager page and change my password immediately, even while the hacker was logged in on my toons beginning to liquidate my assets. Sadly once he was logged in he could bounce from toon to toon without having to re-enter any password so the change had no effect on him unless he logged out and tried to re-enter later. In the meantime, he'd installed the authenticator and gone to work picking me clean.

If anyone else has had a similar experience, I'd love to hear about it. If there is indeed something fishy going on at EJ, we'd all be better off if it was exposed. I'd also like to hear if there is any plan to counteract hackers using authenticators as hacking tools.

As GM of the top Alliance raiding guild on my server, I hope that my acct restoration doesn't take too long. I don't care so much about getting my gear/gold/mats back. I'm sure that will all happen in due time and I am a patient man. I would however, like to get the authenticator that has been placed on my acct bypassed so i can at least log in and communicate w/ my guild and function in a leadership role, even if I can't participate due to the lack of my gear. I just don't want my ppl left hanging w/o direct contact from me for very long.
#12 - June 1, 2010, 3:29 a.m.
Blizzard Post
If you believe a particular site to be compromised, Balian, it would be best to contact the Web Master of that site and notify them. If you believe there is suspicious behavior involved with the site you are welcome to report it to our Hacks Department, they should be able to check it out.

http://us.blizzard.com/support/hackswebform-us.xml