Hackers work for Blizzard now?

#0 - July 30, 2010, 4:03 a.m.
Blizzard Post
So I find it really suspicious this chain of events and would like someone to look into it.

A couple days ago I got really tired of seeing the [Website] hack., so I opened a request to have it looked into. As suggested, I gave the names of every Lvl one toon that was spelling out [Website]. I almost immediately got a response from a "GM" However the reply sounded like it was written by a gold farmer. No complete sentences, and every statement ended with a "?" (ie Thank you for contacting Blizzard?" It said I would get a survey, but I never got one.

The following day, I see the same Lvl 1 toons in Stormwind, no action taken obviously.
Last night, my account gets hacked. I scan my computer 5 times over, no viruses. In my email I see my password changed, then account suspended, then password changed 3 more times. I am POSITIVE my email was not hacked, so who other than a Blizzard employee can un-suspend it without that link?

Did someone not like me submitting that petition? Hmm...

Anyway, In game petition submitted to look into it, but NO response from Blizzard at all. Yes I know that you will never admit you are compromised internally.. but I don't believe this is just coincidence.
#31 - July 30, 2010, 7:15 a.m.
Blizzard Post
Q u o t e:
I almost immediately got a response from a "GM"


Yes, it looks like you received a response very soon after you submitted the petition. We have said that we have personnel that are keeping an eye out for such reports to get them dealt with as soon as possible.
Q u o t e:

However the reply sounded like it was written by a gold farmer. No complete sentences, and every statement ended with a "?" (ie Thank you for contacting Blizzard?" It said I would get a survey, but I never got one.


I'm afraid I have no idea what you are talking about, Yuna. I am looking at the in-game response and it doesn't look like the Game Master used one question mark, let alone ended all of their sentences with one. Nor do I see any broken sentences. The grammar looks pretty good.

They also said you may get a survey at the top right corner of your screen, not that you would. Surveys are randomly generated but we value them a great deal so we ask that you fill one out if it appears.
Q u o t e:

The following day, I see the same Lvl 1 toons in Stormwind, no action taken obviously.


There is nothing obvious about it, Yuna. You saw level one characters in the same location with the same or near the same name, that doesn't mean it was the same characters, and it doesn't mean nothing was done.

Obviously if the advertisement is the same it likely means the same person/company is doing it. More often than not there is a collection of names/letter combination that are generated, much of this is automated and the character may be deleted afterward. Seeing the same character name doesn't always mean it is the same character.
Q u o t e:

Last night, my account gets hacked. I scan my computer 5 times over, no viruses. In my email I see my password changed, then account suspended, then password changed 3 more times. I am POSITIVE my email was not hacked, so who other than a Blizzard employee can un-suspend it without that link?


I'm sorry but if you are referring to this account, Yuna, your account was not suspended at any point. It does look like the password was changed 3 times before a request for a password reset was received and soon completed by you. You then attached a Mobile Authenticator and changed your password again.

The fact that an Authenticator wasn't placed on the account by the compromiser would indicate that they may not have had access to your registered e-mail address, since they would need it to complete the process. It does seem that they had your password though and that is something that we at Blizzard Entertainment do not have. It is internal information that is not displayed anywhere for employees to view.
Q u o t e:

Anyway, In game petition submitted to look into it, but NO response from Blizzard at all.


Yes, because queue times are currently around 2-3 days, and it has been 20 hours since you submitted it. So, no, you would likely not receive a response yet.
Q u o t e:

Yes I know that you will never admit you are compromised internally.. but I don't believe this is just coincidence.


Actually if we were, Yuna, I believe we would have to. If such a thing did occur.

So, though your theory is vaguely interesting it is not the first time that such a theory has been stated nor will it be the last. Most importantly it is by no means even remotely true.

Compromises are usually possible through 2 main avenues. Either the person has picked up a malicious program that has gathered their account information or they have provided their information elsewhere.

They can do so through the sharing of an account (against our Terms of Use and a dangerous thing to do), they can answer a phishing e-mail or visit a spoof website and provide the account information on a page that looks like an official one. One other method would be to use the same log in information on other sites that may either be run by dubious personal or have themselves been compromised.

I truly hope that you do not continue to convince yourself that the issue is with us and you will remain vigilant regarding your security. The Mobile Authenticator is a great addition to your security so if nothing else I am very glad to see that you added it.
#35 - July 30, 2010, 7:22 a.m.
Blizzard Post
One last thing, it appears in your original report that you included the names of the characters. That is entirely unnecessary. Make sure you include the phrase "body spam" or "body advertisement" and include the general location. That is all that is need. Until the overall issue can be resolved we want to get to and address these issues as quickly and as painlessly as possible.