Security Issue.

#0 - Sept. 3, 2010, 9:13 p.m.
Blizzard Post
I contact Account Administration ([email protected]) about an in-game email about account action on my account.


In game email I got was

Q u o t e:

From: Customer Support
Subject: Account Action Notification
Message: This message is to notify that you have received an em-mail to your registered E-Mail address in regards to possible violation of our policies. Please advised that Game Masters will unable to provide specifics on account penalties. Any disputes or questions can only be addressed by Account Administration. Please Refer to the E-Mail for Further details. Check your E-Mail Filters to allow -Mails from our In-Game Support Staff. To Verify that your E-Mail address is Correct. Contact Our Billing Department at [email protected]<mailto:[email protected]> or by Calling 1-800-592-5499 during the hours of 7 AM to 8 PM Pacific Standard Time Customers in Australia should call 1-800-041-378.


however the reply I got from Account Administration was:

Q u o t e:
Greetings,

Thank you for contacting us regarding this issue. We have recently seen an increase in these third party phishing/scam web pages and we are aware that they pose a real threat to account security. I would like to thank you for taking an active role in helping us stop these scams, and I assure you that we will be taking the appropriate actions using the information you've provided us with. Should you find any further suspicious mails with this issue, please report these to us immediately by in game ticket and include the name of the character that received the mail so we can take steps to troubleshoot this further for you.

This is what is known as a "Phishing" attempt made in an effort to gain your account credentials, or get you to follow a link to a malicious website that may look a lot like our own websites. The intent of these websites and whispers is to gain your account information and take control of your account.

****** Please be aware that Blizzard Entertainment representatives will never ask for your password.*******

Should any of these websites have been visited, it is possible that your computer has already been compromised. We highly recommend running a virus scan on your computer and reading the recommendations at http://us.battle.net/security. This site contains four sections detailing everything you ever wanted to know about Account Security, including "Blizzard's Security Commitment," "Security Checklist," "Types of Account Thefts," and "Help! I got hacked!"

These pages are part of a larger effort to provide you with the knowledge and tools necessary to identify and report threats to your account's safety, to spotlight ways in which we work to fulfill our security commitment, and to act as a helpful resource in case someone manages to steal account information from you. Moving forward, we also want to inform you of the best ways to use our system to personally combat these attempts.

One good rule of thumb when determining whether a mail is from a legitimate member of our staff, ask yourself: "Does this mail have the Blizzard Entertainment logo in the background?" If not, this is likely a Phishing attempt and the mail should be reported. If the offending mail is still available, please use the Report Spam feature by clicking the "Report as Spam" button in the top right corner of the mail. Report Spam goes to an automatic process and is very effective against these scammers, as it connects to and flags the reported account immediately. Additionally, this process will ignore the player that is sending out the mail, until you next log out.

If you believe to have provided your account information unknowingly, please call the Billing department before reporting the account as stolen. With proper verification our representatives will be able to assist you in recovering your account. Billing representatives are on hand to take your call Monday through Friday between 7 AM and 8PM Pacific Time, at 1-800-59-BLIZZARD (800-592-5499). Players in Australia should call 1-800-041-378.

Thank you for your time and patience in this matter and your continued interest in World of Warcraft.


Regards,

Game Master <Edited Out>
Customer Services
Blizzard Entertainment
www.blizzard./com/support



So from the reply I got from Blizzard I am thinking hackers are now able to hack the in game mail system and send in game emails with official blizzard logos.
#5 - Sept. 3, 2010, 10 p.m.
Blizzard Post
Hi Flob,

Based on what I can see, the e-mail you received by our account administration is to address the message you reported. Since the message does have a few mistakes it typically is a phishing attempt.

Do you still have the in game mail in your inbox? If so, give me the name of the character and the realm name. I would like to further look into this issue.

Thanks!
#9 - Sept. 4, 2010, 1:04 a.m.
Blizzard Post
Flob,

After further review it appears the in game message is legit and an e-mail was suppose to be sent with additional information. I will see if there is a way to send you a copy of the e-mail.

Let me know if you have any additional questions.