Another phishing e-mail

#0 - July 22, 2010, 4:21 a.m.
Blizzard Post
This had me worried for a little while when I read it on my mobile device. Until I logged into the online account manager and my password/authenticator took hold. I am still wondering how they got my email address.


from Blizzard Entertainment <[email protected]>
reply-to [email protected]
to [email protected]
date Wed, Jul 21, 2010 at 8:50 PM
subject World of Warcraft Account Security verification
mailed-by hotmail.com
hide details 8:50 PM (1 hour ago)
Greetings ,

We have determined that your World of Warcraft account has been accessed/compromised by someone not authorized to do so by the World of Warcraft Terms of Use (http://www.worldofwarcraft.com/legal/termsofuse.html).

To protect your privacy and security, we have temporarily disabled this account. Any recurring subscriptions have been suspended to prevent further monetary charges. In order to regain access to the account, you must complete the steps below to secure the account and your computer.

Please keep this email for your reference until the account recovery process has been completed.


STEP 1: SECURE THE ACCOUNT, YOUR COMPUTER AND YOUR EMAIL ADDRESS
Account compromises most often occur when a player shares login information with an unauthorized third party or plays on a computer that has a virus, Trojan, or key-logger. We recommend following the http://us.battle.net/security/checklist.html on our Account Security site at http://us.battle.net/security/index.html.


STEP 2: RECOVER THE ACCOUNT
We now provide a secure website for you to verify that you have taken the appropriate steps to secure the account, your computer, and your email address. Please go to this site and follow the instructions:
http://us.battle.com/account/support/password-reset-confirm.htm?ticket=BC9E6EFC85206C409C5A42AE45F2373752E47BCA161020F76C40DC2D8C7
[Linked to http://us.battle.blizzard-support-confirm.com/]


STEP 3: VERIFY YOUR SUBMISSION WAS RECEIVED
We will contact you with further instructions once we have received and processed your submission. If you do not receive a reply within 48 hours of submitting this form, please resend it from the address listed above.


Please be aware that if unauthorized access to this account continues after the recovery process is complete, it may lead to further action against the account.


Regards,

Neil G.
Game Master Bahrdrak
Customer Services
Blizzard Entertainment
Message ID 9oufutyjcdes52d9iwbum5irfuv4falwhfllvgerwhx1
Identity ID sev9vdwe50joq2asylvihby7n3m2tnzjvqg3mfzjfoff
#1 - July 22, 2010, 5:30 a.m.
Blizzard Post
That is actually one of the more 'legitimate' type phishes. The mailed by hotmail is an absolute red flag that although that may be a version of a 'real' email - it didn't come from us.

This has got to be the hardest variety of these to catch. In essence, they take 'real' emails, doctor the links to go to fake sites.

Great catch!