Hacked

#0 - Aug. 9, 2010, 3:22 a.m.
Blizzard Post
My account got hacked this morning and is still under suspension (I'm posting under my husband for some helpful advice, hopefully).

I have run full Norton system scans on both my computers, ensures all my firewalls, router security, etc. is in place. Found a tracking cookie that was deleted.

I also downloaded Malwarebytes, as I saw it was a recommendation by many. That found 5 adware agents, 2 trojan.agent, and 1 trojan.virtool on the main computer and 1 trojan.agent on my laptop. (Definitely a good example for those that believe their normal antivirus is cutting it.)

I plan on putting in an in-game ticket to try to get my gear/gold back when I can log in again. My only concern is whether or not I've gotten whatever keylogged me in the first place. (Guess I'm luck it didn't get both accounts.) I am very careful about spam e-mails and phishing, so I know it isn't from that route.

Any extra suggestions from anyone? Now I'm paranoid about the more important things that could get hacked like bank accounts.


In extra reference, for those that don't think blizzard does anything, they had already identified strange activity and locked the account before I even realized it had been hacked this morning.
#9 - Aug. 9, 2010, 4:16 a.m.
Blizzard Post
Q u o t e:


Rofl same here, and my response was way off topic, they saw my suggestions and sent a message about that instead of my account being compromised. Maybe they were impressed with my suggestions.

Have to submit another ticket and wait like 3 more days now.


Juice, your compromise is in process, it's in the queue.

I'm sorry if there was any confusion on any responses we may have sent - but this was entered into the system for investigation and is currently awaiting processing.
#10 - Aug. 9, 2010, 4:51 a.m.
Blizzard Post
Q u o t e:

errr yes and I reported my account was compromised 19 hours ago had a GM response 18 hours ago and the hacker is still farming ramps.


You also have a compromise in process for investigation, Ganksterz.

In your case, you have a significant issue here. They are into your email without a doubt.

To have added an authenticator, they had to have been able to respond to a confirmation email. This also isn't the first one they've put on or removed themselves.

I'd recommend a complete security scan of any systems you've used and I'd ALSO recommend changing your email address after that is done. At the very least, you need to change your email password and verify there has not been any forwarding shenanigans done in your email account.

One advantage of Battle.net is changing your email address also changes your account name.

Now, since they are into your email, and also in your account at the moment, I'm asking this be locked down to prevent any further damages.

If you like, you could contact Billing by phone to help with an email change.

Billing and Account Services
Phone Support - 1 (800) 59-BLIZZ (1 (800) 592 5499)
Live Representatives Available 7 days a week, 7am to 8pm Pacific Time
E-mail Support - [email protected]
    Players in Australia should call 1-800-041-378
    Players in Singapore should call 800-2549-9273
    Players in Chile should call 1230-020-5554
    Players in Mexico should call 001-888-578-7628
    Players in Argentina should call 0800-333-0778
    All other international players should call: (949) 955-0283


This sticky may also prove useful.

Account Hacked? Security Issue? Look Here!
http://forums.worldofwarcraft.com/thread.html?topicId=24702231244

You may also want to look into getting an authenticator for your account. It's no substitute for good security habits, but it will help keep them out of your WoW account.

Blizzard Store
http://us.blizzard.com/store/browse.xml?f=c:6

Mobile Authenticator
http://us.blizzard.com/support/article.xml?locale=en_US&articleId=26109

Now, there is an email we normally send out (as well as a password change), but since the compromiser will most likely get hold of those as well, not going to send those at this time.

Once you are certain your system and email is secure - or you can change your email, please respond on this webform that security has been taken care of.

http://us.blizzard.com/support/article/securitywebform

This can take a little time, a compromised email address does make it a bit more complex, but we'll certainly do our best to help.






#11 - Aug. 9, 2010, 4:55 a.m.
Blizzard Post
Q u o t e:
My account got hacked this morning and is still under suspension (I'm posting under my husband for some helpful advice, hopefully).

I have run full Norton system scans on both my computers, ensures all my firewalls, router security, etc. is in place. Found a tracking cookie that was deleted.

I also downloaded Malwarebytes, as I saw it was a recommendation by many. That found 5 adware agents, 2 trojan.agent, and 1 trojan.virtool on the main computer and 1 trojan.agent on my laptop. (Definitely a good example for those that believe their normal antivirus is cutting it.)

I plan on putting in an in-game ticket to try to get my gear/gold back when I can log in again. My only concern is whether or not I've gotten whatever keylogged me in the first place. (Guess I'm luck it didn't get both accounts.) I am very careful about spam e-mails and phishing, so I know it isn't from that route.

Any extra suggestions from anyone? Now I'm paranoid about the more important things that could get hacked like bank accounts.


In extra reference, for those that don't think blizzard does anything, they had already identified strange activity and locked the account before I even realized it had been hacked this morning.


I'd need a character name/realm to look into this further, Draigar.

You could go ahead and report this ingame using this account - just be sure to be specific as to which account is in question in that petition.

There are many ways security can be breached. Malware is of course one of the more common, but compromised email accounts, phishes and general social engineering are also very common.

This may prove useful.

Account Hacked? Security Issue? Look Here!
http://forums.worldofwarcraft.com/thread.html?topicId=24702231244

You may also want to look into getting an authenticator for your account. It's no substitute for good security habits, but it will help keep them out of your WoW account.

Blizzard Store
http://us.blizzard.com/store/browse.xml?f=c:6

Mobile Authenticator
http://us.blizzard.com/support/article.xml?locale=en_US&articleId=26109
#14 - Aug. 9, 2010, 5:52 a.m.
Blizzard Post
I occasionally see mixed reports from users in Singapore about that number - and I'm uncertain if it doesn't work in all areas, or exactly why there could be an issue.

Have you thought about using something like Skype? Many of our international players have reported very good results from that.
#17 - Aug. 9, 2010, 6:12 a.m.
Blizzard Post
Q u o t e:
Hello Orlyia,

It appears that we cant use the 800 number system through a home line but can through a cell phone, I am currently on my 300th(exaggerating) retry, the number is heavily engaged. I shall also look into Skype in a short while.

Thanks again :)


Are you trying to call right now? If so, the office has been closed for some hours. All Billing is based off Pacific coast time.
#20 - Aug. 9, 2010, 6:17 a.m.
Blizzard Post
Q u o t e:


In-game GMs work 24/7.


Indeed, Billing and tech have shorter hours, the rest of us are here round the clock....every day of the year :)