Strange Emails

#0 - Aug. 28, 2010, 1:37 a.m.
Blizzard Post
I've gotten a couple of suspicious emails as of late. I think they're fake, but I'd like a Blizzard employee to double check for me to be sure.

Here's the first one. It's telling me that my account was locked because multiple computers tried to log into it at the same time and provided links to unlock it. It looks completely legitimate and I didn't question it at first until the second one made me suspicious and I decided to check for myself and found that I was perfectly capable of logging in and wasn't locked out at all.

Q u o t e:

From [email protected]
Battle.net Account Locked - Unregistered IP Notification

Dear customer,

Due to suspicious activity, the Battle.net account [my email] has been locked. You tried to login your account on 2010-8-22 from several different IP.

We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your Computer

In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail Account

After you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your account

We now provide a secure website for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: [link]

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at [link]

Sincerely,
The Battle.net Account Team
Online Privacy Policy
Message ID e3dj8km8zegxp4mfz96vvcrnzlnd4ukv4owopvpc69fc
Identity ID jfbjxvxsknayqbqnc70cfdyejzifsylzxbc4ylrbdjmq


Note that the last two lines were hidden and I didn't see them until I highlighted it just now.

I ran my anti-virus program and it found a trojan that I promptly got rid of it so I thought it was legit. But if it was, then I wouldn't be able to log in unless the hacker got into my e-mail, restored my account, and put my password back just like I had it. That just doesn't make sense, especially since all my stuff is still there (as far as I know anyway). Why would they do that?

Now here's the second one. This one tells me that my subscription has been reset. I don't even know what that means. But here's the real kicker, it's supposedly from WoW EU. My account is a US account. That's what ended up making me suspicious of both this one and the first.

Q u o t e:

From: [email protected]
Battle.net Account - Subscription Reset Notification

We have reset the subscription for the Battle.net account associated with this email address. To choose a new subscription or check the subscription status, please click the following link and follow the instructions:
[link]

If you did not request the reset, it is possible that this Battle.net account has been accessed by someone not authorized to do so. If you notice issues with the Battle.net account or associated games after logging in with your password, please contact the appropriate support department for assistance immediately: [link]

Please remember that it is your responsibility to keep your login information confidential. You may not share access to the account with anyone who is not expressly permitted in the Battle.net Terms of Use and the Terms of Use for the games you play. You are also responsible for every use of your login information, whether you have authorized it or not.

COMPUTER AND ACCOUNT SECURITY:

Account compromises can occur when a player shares login information with a n unauthorized third party or plays on a computer that has a virus, Trojan, or keylogger. In a case where you believe your account has been accessed by an unauthorized party, we would like to suggest that you review the following pages for various security awareness tips (as well as how to recover i n-game items or characters) before you log back into the account:

- Security Checklist: [link]

- Types of Account Thefts: [link]

- Account and Computer Security: [link]

- What to do if the Account has been compromised: [link]

- Account Security and Recovery FAQ: [link]

- Email Address Security: [link]


Billing and Account Services can be reached directly at 1-800-592-5499. Players in Australia and Singapore should call 1-800-041-378 and 800-2549927 respectively if unable to connect via the first number. Our representatives are available seven days a week, between 8:00AM and 8:00PM Pacific Time. Al ternately, our support team can be reached via email at [email protected].

Thank you,

Blizzard Entertainment


So could a Blizzard employee please look into my account and see if any of these actions have actually been taken against it? I kind of doubt it, but the first one looks so legit it makes me wonder. The whole thing just seems so weird. My Authenticator can't get here soon enough.
#2 - Aug. 28, 2010, 1:41 a.m.
Blizzard Post
Both are fake, Adellith, and as you noticed there has been no actions on your account. Odds are at least one of the links in the e-mail actually lead to a site that looks very official but are designed to steal your account information.

More information on these types of attempts and how to verify if an e-mail is legitimate please check out the following thread.

Fake E-mails from "Blizzard Entertainment"
http://forums.worldofwarcraft.com/thread.html?topicId=965511383&sid=1
#7 - Aug. 28, 2010, 1:54 a.m.
Blizzard Post
Q u o t e:
Why they're trying so hard to get an undergeared Rogue with only 200G is beyond me.


Even if they are unable to get much from stripping the character it would be a legitimate account that they could use to advertise or perhaps farm materials. There are many nefarious purposes behind their attempts, hopefully we can all remain vigilant and recognize such attempts when they are made.