Maintenance for the week of November 25:
• PC/Mac: NA and EU megaservers for maintenance – November 25, 4:00AM EST (9:00 UTC) - 7:00AM EST (12:00 UTC)
• Xbox: NA and EU megaservers for maintenance – November 27, 6:00AM EST (11:00 UTC) - 9:00AM EST (14:00 UTC)
• PlayStation®: NA and EU megaservers for maintenance – November 27, 6:00AM EST (11:00 UTC) - 9:00AM EST (14:00 UTC)

My account was hacked

imalwayswishing
So my account was hacked on the 13/04/2014, i was unable to log in as an error message stating that the log in information was incorrect popped up. So i attempted to sign in via the website and discovered that the story was the same.

I then thought "well okay, i will just reset my password" but no..... the person who had hacked into my account not only changed my password but also changed the name associated with the account. I discovered this as when i put in my name and my email address into the password recovery an error messaged occurred saying " There is no account matching those details."

This was a red flag for me and i instantly contacted customer support to raise a ticket, i was duly contacted by a member of the customer support team via E-mail notifying me that they were looking into the matter, and a day later i received another E-mail addressed to the name "Xinguo" (which is not my name, i also tried this name to recover my password to no avail), requesting for the answer to my security question, of which i provided seeing as it was in reply to the ticket i had made.

2 days on i have received no further contact from customer support regarding my account and the term "irate" does not even come close to how i feel currently. I have continuously e-mailed them regarding e-mails i received about an unknown IP attempting to gain access to my account and i have asked them for information regarding their progress on the recovery of my account.

i have written this on the forums in vane hope that someone has any information regarding this, or if anyone has experienced this or if a member of the support team sees this to get into contact with me.

Thank you for taking the time to read this.
  • imalwayswishing
    I also forgot to add that the e-mail marked the status of this ticked as "solved" which is clearly not the case.
  • kittybockub17_ESO
    Sadly, my husband had some folks from a large guild we are allied with that they had been hacked, this has not been verified, however.

    That said, Rich and I both have/ had accts. We have been receiving numerous "email resets" from the game, stating we are at a different IP address, I'd assumed this was when UVerse assigned new IP's....I noticed yesterday that our IP DID change when power went down due to a storm and we did not receive said email, plus I'd received one on Sat and he did not, etc. I am not slamming ESO, I am posting here as I think someone may be mimicking the games validation attempts.

    Due to what I've found online regarding this, Rich and I have both cancelled our subs, at least for now. We played EQ2 back @ the time they went through some garbage and we'd rather wait until the kinks are worked out of your system. I did want to state here though, about the odd repeated emails...as it may help you track down possible issues.

    thanks,

    Kitty
  • SafeForSure
    SafeForSure
    ✭✭
    This sucks hard. :( Right now the game is full of goldfarmers/spammers on stolen accounts, grief campers at ww and vamp spots killing al the spawns and charging tons of gold, Bots in almost every higher open dungeon boss and so on. And Nothing gets fixed. hope they wil help you.
  • imalwayswishing
    I have re-submitted my ticket in the hopes that i can get it resolved again.
  • Elsonso
    Elsonso
    ✭✭✭✭✭
    ✭✭✭✭✭
    I would make sure your system is clean from all viruses and spyware before you proceed too far down the path to recovery.

    I say this because your first warning should not have been that you could not log in. Your first warning should have been emails from Zenimax about changes being made to your account.
    ESO Plus: No
    PC NA/EU: @Elsonso
    XBox EU/NA: @ElsonsoJannus
    X/Twitter: ElsonsoJannus
  • Armitas
    Armitas
    ✭✭✭✭✭
    ✭✭✭✭
    What lord said.

    It's suspicious that you do not have any emails as to the change. After you secure your PC change your email password. On most email accounts you can actually see the login times and locations. So if you see an odd login/location then your email is compromised.
    Retired.
    Nord mDK
  • Isyldra
    Isyldra
    ✭✭✭✭
    This is terrible. Good luck getting back into your account.
    Proud member of Alacrity
    Proud member of The Psijic Order
    Twitter: @Isyldra
    Twitch: twitch.tv/isyldra
    There's a special place in hell reserved for people who leave the worms and take the flower.
  • Pur31ucK
    Pur31ucK
    Same thing happened to me. God 15 years of mmo gaming and this is the 1st one I've been hacked in. =( Ohh and its been 2 days and still no contact from the investigation team. Really sux cuz I'm dying to play and I was enjoying the game.
    Edited by Pur31ucK on 16 April 2014 01:05
  • imalwayswishing
    i have already fully scanned my computer for spyware, malware viruses and the such, it all came up clean, and i have changed the password on my E-mail address.

    I thought it was strange that i received no confirmation of changes to my account and this is what concerned me, i have only received a tonne of emails regarding attempted login's to my account from an unknown IP (by a tonne i mean about 16-28 in the space of 18 minuets)

    I feel the security based around the game is little more than a joke as the give out your user name and it only takes a clever hacker about 30 minutes to background check you and get all the relevant information they need to hack into your account, it only takes a skilled hacker an extra 5 minuets to hack into your E-mail anyway (i now change my E-mail password every 4 days for security reasons)
  • imalwayswishing
    its a shame that the support team are not providing any help in this matter and i am struggling to get my account back myself
    Edited by imalwayswishing on 16 April 2014 11:31
  • wrlifeboil
    wrlifeboil
    ✭✭✭✭✭
    Did you have an authenticator on your account?
  • imalwayswishing
    ESO does not allow an authenticator to be issued to accounts at this current moment (i agree that this needs to be implemented but atm its not available)
  • wrlifeboil
    wrlifeboil
    ✭✭✭✭✭
    ESO does not allow an authenticator to be issued to accounts at this current moment (i agree that this needs to be implemented but atm its not available)

    For a hacker to get your account, he would need access to your email account to grab the code that ZOS sends to you when he logs in from an unfamiliar ip address.

    So if you have an authenticator on your email account, the hacker can't get the code that ZOS sends to your email account when someone logs in from a different ip address.

    If the hacker can spoof your ip address and not trigger ZOS's email verification, only then are you s.o.l.
  • imalwayswishing
    my E-mail account does not have an authenticator. i have no idea how they managed it but they took my account, i believe they spoofed my IP and then changed my details. i have no idea how it happened or why they went through the process of hacking my account.

    i can confirm now that i have uncovered the name that my account was change to and have reset my password myself via the password recovery and the hackers name. It's appalling how lapse the CS staff are regarding the loss of sensitive information of their customers.

    I strongly urge Zenimax to look into the failures of their customer support team, as a lot of people on this forum have expressed that the CS team has just marked their issues as "solved" when they are not.
  • ipkonfigcub18_ESO
    ipkonfigcub18_ESO
    ✭✭✭
    People getting hacked are usually the fault themselves:

    1. visiting sites you shouldn't be visiting
    2. Buying gold / or other quick leveling services
    3. Sharing passwords with friends
    4. Poor choice of passwords
    5. Not keeping the system updated (drivers, virus software, ect)

    If you want to help protect your game, start using better passwords, and I mean 'better'.

    Example of a high-bit password:
    • ҰΩFd˜Øñ¦°5ÓTëb»)D¾~-õ«Jß{Z+Æ»

    The password you see above is a 235 Bit password, almost unhackable using BruteForce, which is the most common method used to guess passwords.

    All of my passwords use a difficult, high-bit characters to create a difficult password. (be sure that whenever you're using ASCII characters on a website/software that it excepts those types of characters as a password, ect.)

    Can't remember them? Easy, use KeePass.

    KeePass stores you passwords and encrypts them for security (so long as you make the password into its database difficult to obtain).

    When you need the password you open the software, copy the password (it's simple, trust me) and paste it into the program/game requesting your password. KeePass will remove the password from the systems memory and clipboard after 10sec (you can set this time). Even when the password is in memory, it is encrypted and wiped shortly after.

    You can also have this synced up to your DropBox (which encrypts your files via 256bit but your db for KeePass will be locked down, too) with an iPhone/Android software that will allow you to access those passwords while using a mobile device -- all of which is protected very well.

    Start being smarter than the average hacker and you'll save yourself heacaches. This isn't the 1980's anymore - be smart.

    URL for KeePass:
    http://keepass.info/
    Edited by ipkonfigcub18_ESO on 16 April 2014 18:09
  • Ysne58
    Ysne58
    ✭✭✭✭✭
    @ZOS_GinaBruno‌ There are several people in this thread complaining of stolen accounts.
  • Jake211049
    my account has also been hacked, get the "your login information is incorrect" at game login & cant login to account management, I didn't get any emails about unfamiliar ip address or anything, no emails about password or userid change, no emails at all, just happened, submitted a ticket online and now also waiting.
Sign In or Register to comment.