A password reset that i did not ask for

#0 - Sept. 2, 2010, 5:49 p.m.
Blizzard Post
I recently recieved this e-mail

Blizzard Entertainment <[email protected]> to "My Email" < My Email >
9:05am

We've received a request to reset the password for this Battle.net account. Please click this link to reset your password:
https://us.battle.net/account/support/password-reset- *I Edited out the rest of the link to be safe*

If you no longer wish to make the above change, or if you did not initiate this request, please disregard and/or delete this e-mail.

If you have any questions regarding your Battle.net account, click here for answers to frequently asked questions and contact information for the Blizzard Billing & Account Services team.

Sincerely,
The Battle.net Account Team
Online Privacy Policy



Obviously if this is real i can just disregard it and dont have to worry. I'm more concerned about (assuming this is a legit email) someone trying to reset my password. Could this be a real id "friend" of mine since they have my email? I use an authenticator by the way.

so my quesiton is, should i be concerned?
#10 - Sept. 2, 2010, 6:31 p.m.
Blizzard Post
Q u o t e:
so my quesiton is, should i be concerned?

Yes, and let me explain why.

I reviewed the account, Nijtro, and show the password reset was requested from a potentially exploitative location. This means this individual would need to know the first and last name, the Battle.net email address, and the answer to the Secret Question. Even though they knew this information, they would have also needed the information to access your email address to proceed.

Q u o t e:
I use an authenticator by the way.

This is good! Even though authenticators provide some peace of mind, you must still take preventative measures to prevent compromise. In the event you need to remove the authenticator for whatever reason, you want to be prepared.

You may wish to update the email address associated to the Battle.net account since this will change the account name itself.