Battle.net account keeps getting hacked

SlitheryDee

Lifer
Feb 2, 2005
17,252
19
81
I'm not sure what's going on here, but last month I tried to log into Starcraft 2 and the game told me that my account had been locked due to suspicious activity. Looking for a reason for this I found the following e-mail in my gmail spam folder:

Hello,

Blizzard Entertainment recently received a request to change the e-mail address used to log in to the Battle.net account with the username [removed]. The e-mail address k***@hotmail.com has been specified as the new username for this Battle.net account. An email has been sent to this new address containing a verification link to complete the change.

Once the new address has been verified, the e-mail address [removed] can no longer be used to log in to this Battle.net account or any World of Warcraft accounts merged with this Battle.net account.

If you did not initiate this request, please click here to contact the Blizzard Billing & Account Services team immediately.

Sincerely,
The Battle.net Account Team


I hadn't actually played starcraft or logged into battle.net in a few months, and I certainly had made no request to change the login address, but apparently someone else had acquired my login information. I sent blizzard an e-mail and had the account changed back to my login, changed the password, and set up blizzard's account protection measure where you have to call from a designated phone and enter a PIN to make any changes to the account.

Lo and behold, I check my spam folder today and see another e-mail just like the previous one, apparently being changed to the same hotmail address. Sure enough, I can't log into battle.net again. What the hell is going on here? How can someone steal my account when you have to call blizzard from my home phone to change the login info? This is pissing me off...

BTW the only computer I've logged into battle.net from since I changed the password is my shiny new sandybridge build with a fresh copy of windows installed on it. There can't possibly be any malware on it logging my keystrokes or anything like that, but I'll be checking it anyway this afternoon. In the meantime, anyone have a clue how this is possible?
 
Last edited:

fatpat268

Diamond Member
Jan 14, 2006
5,853
0
71
I dunno, happened to me too a while back.

My computer is clean (AFAIK) and I didn't click any links in phishing emails. But, once I got my account back, I bought the authenticator (which is ~$6-7, or free as a smartphone app) and I haven't had a problem since.
 

pontifex

Lifer
Dec 5, 2000
43,804
46
91
I have been getting a lot of emails about my WoW or battlenet account. Haven't played WoW in years and most are obvious spam. Got one the other day that said there was a chargeback on my account and it looked legit.

Called up Blizzard and they said it was. Apparently my account was compromised awhile back or something. I dunno...
 

SlitheryDee

Lifer
Feb 2, 2005
17,252
19
81
you sure its not just spam? i get lots of blizz spam

It's not spam because my login no longer works. Apparently the call-in system blizzard has doesn't do shit either. I still don't understand how that's possible...
 

imaheadcase

Diamond Member
May 9, 2005
3,850
7
76
Its a spam email, ever since gizmodo email list was compromised i get about 100 spam emails a day..lucky gmail detects them though.

If you look at the From field in more details. its actually a fake email account being send to look like a offical blizzard one. Its like @ea.battle.net. which is a fake one.

However, blizzard does NOT block accounts for suspicious activity based on simply requesting password for accounts...so i would look into something else.

Long as gmail account is secure you should have no problem.

Did you check to see if someone is using gmail account? Click on account actvity and it will show who has logged in from each IP address

Tell me you DID NOT click the link in the email to say it was spam..because its just a redirect to a fake website to look like official one.
 
Last edited:

thescreensavers

Diamond Member
Aug 3, 2005
9,916
2
81
Did you click on the links in the emails?

Btw, I too had not played for a year but found my shit hacked.
 

SlitheryDee

Lifer
Feb 2, 2005
17,252
19
81
Its a spam email, ever since gizmodo email list was compromised i get about 100 spam emails a day..lucky gmail detects them though.

If you look at the From field in more details. its actually a fake email account being send to look like a offical blizzard one. Its like @ea.battle.net. which is a fake one.

However, blizzard does NOT block accounts for suspicious activity based on simply requesting password for accounts...so i would look into something else.

Long as gmail account is secure you should have no problem.

Did you check to see if someone is using gmail account? Click on account actvity and it will show who has logged in from each IP address

Tell me you DID NOT click the link in the email to say it was spam..because its just a redirect to a fake website to look like official one.

A few months ago gmail warned me that my account had been accessed from an IP in china. I immediately changed my passwords for gmail and everything else that might have been compromised through gmail...except for battle.net. I haven't received any warnings since then, and my account activity has shown no more suspicious logins.

I agree that was probably how someone got my original battle.net login info, but how do you account for this more recent occurrence? My password is different now and gmail seems secure. Even if they knew my login info they shouldn't have been able to change anything without access to my home phone. If the e-mail is just spam, why does it coincide so perfectly with my inability to log into battle.net? Would blizzard lock my account if someone was making multiple unsuccessful login attempts perhaps?

And no, I didn't click anything in the e-mail.
 

coloumb

Diamond Member
Oct 9, 1999
4,069
0
81
My guess it was a customer rep who wasn't following the rules to reset passwords / provide account information - or perhaps they were and their policies aren't as strict as they should be.

This happened when I had to activate a SIM card on my work phone recently - I had the basic information with the exception of the answer to a phrase [example "What is your pets name?"] and the rep said she could continue since I was only activating a SIM card.
 

Wordplay

Golden Member
Jun 28, 2010
1,318
1
81
I haven't played WoW since last year and my account was hacked recently. My cousin actually notified me first as he seen my toon logged in. A couple of days later I got a few emails from blizzard about restoring items and gold back to my account. I logged into battlenet and my account was tagged with trials for Cata.

My PC is clean as well, not sure how they got into my account but oh well. I don't play it anymore.
 

NoQuarter

Golden Member
Jan 1, 2001
1,006
0
76
I stopped playing WoW before the battle.net transition was enforced but I set up an authenticator on my buddy's spare iPhone just to lock down the account. You can also use an iPod Touch, and the list of supported phones actually includes a few dumb phones, so I'd try to get an authenticator set up on top of everything else.

You can see the list of phones it supports here:
http://mobile.blizzard.com/us-en/t401-c12902/applications-battle-net-mobile-authenticator
 

nsafreak

Diamond Member
Oct 16, 2001
7,093
3
81
This is why I downloaded the authenticator app for my droid. It's now extremely difficult to hack my account.
 

bucala

Junior Member
Aug 5, 2012
2
0
0
Hello ///,

Blizzard Entertainment recently received a request to change the e-mail address used to log in to the Battle.net account with the username ///@///.//. The e-mail address g***@hotmail.com has been specified as the new username for this Battle.net account. An email has been sent to this new address containing a verification link to complete the change.

Once the new address has been verified, the e-mail address bucala@post.sk can no longer be used to log in to this Battle.net account or any World of Warcraft accounts merged with this Battle.net account.

If you did not initiate this request, please click here to contact the Blizzard Billing & Account Services team immediately.

Sincerely,
The Battle.net Account Team
Online Privacy Policy


pleas help me, what I should do
 

Arkadrel

Diamond Member
Oct 19, 2010
3,681
2
0
@SlitheryDee

I got a message kinda like that one... only.... IT WAS A FAKE!
There are people out there trying to get you to give them your user/password ect.

Dont get tricked by a fake email, from someone impersonateing blizzard.


I get these emails all the time for my blizzard account. Junk spam.

Nice to see Im not the only one, getting spam mail like that trying to trick me.
I just feel bad for the people stupid enough to fall for this type of tactic.
 

Grooveriding

Diamond Member
Dec 25, 2008
9,147
1,330
126
Blizzard is losing WoW subs and seems to be in a decline. It's a new marketing ploy to remind you about your battle.net accounts and World of Warcraft in the hopes you will come back. I kid, I kid.... :D I get tons of phishing spam about my battle.net account. A while back curse.com was compromised and all account emails were obtained. Since then I started getting phishing emails for my battle.net account, has never stopped since.
 

SlitheryDee

Lifer
Feb 2, 2005
17,252
19
81
It's strange that this thread should get bumped now. My brother's steam account apparently got hijacked yesterday. Actually what seems to have happened is that some guy he was playing with told him to go to a website and enter his username and password to get a free copy of Americas Army. Isn't Americas Army free regardless of how you get it? Anyway, shortly after doing that he couldn't log into steam, so I'm thinking he gave his login credentials away when he visited that website. I entered a ticket in steam's customer support for him, but we haven't heard back from them yet. How successful are people in getting back their accounts in situations like these?

Damn, I can't imagine doing something that stupid...
 

Nintendesert

Diamond Member
Mar 28, 2010
7,761
5
0
Do you use any one time passwords?? Like Blizzard has their authenticator and Gmail sends a text message if the computer isn't recognized and every 30 days.

If you're not you really need to, if you are, that's pretty scary.
 

bucala

Junior Member
Aug 5, 2012
2
0
0
I dont loged on my accout ... I have verification of the phone and I got a sms from the login information has been amended.
 

AlexAL

Senior member
Jan 23, 2008
643
0
76
I get tons of spam about my battle.net account and i don't even have one.
 

brandonb

Diamond Member
Oct 17, 2006
3,731
2
0
Actually alot of these are real. My GF, her brother, myself, etc, get these emails and have called Blizzard directly and in all cases have been from Blizzard.

I suspect that guild websites, etc, use your password that you have with them to be able to log into your account (thats why you never use the same password across all your accts.) That, or there is a trojan on the server themselves.

A friend of mine had Blizzard delete her entire account (subscription history, username/password, characters, the whole shebang) because she'd get hacked over and over again, even though she has not subscribed in 4 years. She never responds to the emails, she always calls their customer service that is listed on the website.

I've been hacked too, but I honestly don't care. I just put blizzard into my spam folder. They can have it, their games are worthless anyways (IMHO).