Hacked Possibly?

#0 - Sept. 17, 2010, 5:56 a.m.
Blizzard Post
Well on Tuesday (9/14/10) after the update, I tried to log onto my account only to have it say my password is invalid. I changed my password, and log into the game, everything is fine nothing is touched, and a guild mate told me she had the same thing happen to her like a month ago and nothing occured after that.

Well everything was fine until tonight (9/16/10) when the password again was considered invalid. I did a virus and malware scan and nothing came up, and now I've changed my e-mail address and password again to something non-copyable. I really don't want to reformat, and thinking if the password is messed up again, that it might be Blizzard's fault and/or that I'll have to reinstall Windows 7.

Any responses would be great, and wondering if this has happened to anyone else recently or if my e-mail address happened to be hacked.
#6 - Sept. 17, 2010, 6:27 a.m.
Blizzard Post
Q u o t e:
Well on Tuesday (9/14/10) after the update, I tried to log onto my account only to have it say my password is invalid. I changed my password, and log into the game, everything is fine nothing is touched, and a guild mate told me she had the same thing happen to her like a month ago and nothing occured after that.

Well everything was fine until tonight (9/16/10) when the password again was considered invalid. I did a virus and malware scan and nothing came up, and now I've changed my e-mail address and password again to something non-copyable. I really don't want to reformat, and thinking if the password is messed up again, that it might be Blizzard's fault and/or that I'll have to reinstall Windows 7.

Any responses would be great, and wondering if this has happened to anyone else recently or if my e-mail address happened to be hacked.


While this is always possible it's an authenticator desync'ing - in this case, sadly - it's not.

A malicious party has been trying mightily to change your password and get in - your authenticator has saved you from a compromise.

This started back on 9/3 and has continued through 9/17. They are getting enough of your information to change your password - but they can't do more than that.

Changing your email may help - if you find this continues, that tends to point to more of a system infection.


#8 - Sept. 17, 2010, 6:34 a.m.
Blizzard Post
9/3 might not have gone through, or you may not have noticed, but that is indeed the first attempt at this.

Not sure if that date is at all helpful, but might point up something if you were elsewhere around that time - perhaps work or a friends house?
#10 - Sept. 17, 2010, 6:51 a.m.
Blizzard Post
Q u o t e:


Don't remember being anywhere specific or typing in my info at another computer at that date.


They don't necessarily compromise an account right away.

Also, if you use the same password anywhere else (which is very risky), could be luck that it worked for WoW and they made the attempt.

I recommend folks use a unique and totally unrelated email for their Battle.net accounts. Use it NO WHERE else, post it NO WHERE else, give it to NO ONE at all. One advantage of Battle.net over the old system, changing your email address effectively changes your account name. That was never possible before.

I'd just check back on this if it seems to happen again. If it does, they are getting current information somehow.