#0 - Oct. 22, 2010, 10:17 p.m.
So I was playing my account last night, doing the Hallow's End acheivements on my priest Razcal and my Paladin Rynori (both on the US Server Turalyon, both level 80). Everything was normal, logged off around 11pm or so EST .
I've been studying all day for an exam I have tonight and when I decided to take a break, I checked my mail and saw that my new authenticator had arrived. I have had an auth on my account since the very first batches were available. My boyfriend moved in a year ago and we have been sharing the authenticator (NOT our accounts, the authenticator.) and its been rather annoying so I decided to purchase a new one. It arrived today.
When I went to remove the old one and add the new one I saw that my password was no longer working. I checked my email which I use ONLY for WoW-Battlenet and saw 4 emails. One was password recovery, and the other three were account compromised emails. One of them listed the items recovered on all my characters (Razcal, Rynori, Sahvie and Tayce .. Tayce is just a bank toon. All on the same server). The thing is, I didn't send in a form at all. I logged off at 11pm EST and went to bed. Didn't attempt to log on until sometime around 2:30pm EST today.
So, alarmed, I decided to call Blizz. Waited for a half hour (yey queue times are down!) and talked to a woman. She was wonderfully helpful, but I informed her that I had an authenticator and that there was no way I was victim of the man in the middle attack. As far as I am aware, the way the man in the middle attacks work is that you input your key, the hacker intercepts it and you are unable to log on (or you get kicked off). This never happened. I logged on, played for several hours, then logged off and went to bed. The compromise emails were sent around 4:32am EST (I was most assuredly in dream land).
She helped me reactivate the account and informed me that I had items restored to me. She however could not explain how I was compromised. I called again about an hour later to reset the password myself, and the second person I spoke to couldn't explain it either. I have items on my characters that I am still missing but I've ticketed for that. I've only had time to check Razcal and Rynori so far. I haven't checked Tayce whom is the gleader for my bank which has somewhere around 10k gold and 4 tabs worth of stuff. Haven't checked her yet.
All Im asking is, can anyone tell me how I was compromised? I ran avast! and maleware btyes and neither came up with anything. I have reset the password, and gotten a new battle.net email just to be safe, but I'm at a loss for how this happened. I have to go to my exam, so I won't be able to respond to anything right away, but I will check back to this when I get back...
For what its worth, I only visit three websites on the computer I use for WoW: facebook, my universities website, and the official forums.
Thanks to anyone who might be able to help me...
P.S. Thanks to Blizz for the speedy service so far! :)
