NCsoft Master Account Security Issues
Quote:
Two of my friends who play Aion have had this happen in the last two weeks. I wouldn't touch Aion with a 10' pole right now.
How would you feel if you found out this bug gave someone else access to your account and when you complained you get told by Customer Support that they are banning your account because they assumed you used an RMT site rather than admit there is something wrong on their end.
|
Together we entered a city of strangers, we made it a city of friends, and we leave it a City of Heroes. - Sweet_Sarah
BOYCOTT NCSoft (on Facebook)
https://www.facebook.com/groups/517513781597443/
Governments have fallen to the power of social media. Gaming companies can too.
Quote:
Just yesterday I got the automated email saying someone had changed the contact info on my Aion account. I don't even have an Aion account! What's up with that??
|
I get those all the time threatening to close my WoW account. I've gotten about 40 of them in the last month.
Care to guess what game I've never played in my life?
Quote:
Originally Posted by Dechs Kaison See, it's gems like these that make me check Claws' post history every once in a while to make sure I haven't missed anything good lately. |
It looks like there is nothing we can do about this. I'm not worrying.
The site Aionsource (not an official NCSoft site) had a virus, and many who went to it were hit, your account info isn't stolen by playing Aion.
Quote:
I recently received an email that purported to be from NCSoft telling me (in bad English, and encoded in base64 in the body of the email, which nothing I've ever gotten from NCSoft has been) that my Aion account was to be suspended for chat violations, and that if I wanted to prevent the suspension, I needed to go to (URL redacted -- the hostname was "secure.ncsofti.com").
Just yesterday I got the automated email saying someone had changed the contact info on my Aion account. I don't even have an Aion account! What's up with that??
|
With mail like this, even with the obvious fraudulencies in the mail, I make a habit of opening the raw view of the mail, which the automated mail headers (the ones added by the mail system, not the person spoofing fields like 'From:') showed that it came from a Yahoo user, and showed that the phisher who was sending them out was insufficiently competent to keep the Yahoo mail system from identifying his IP address in the mail headers. NCSoft support has the email now, and has added it to the various phishing attempts they're investigating.
"But in our enthusiasm, we could not resist a radical overhaul of the system, in which all of its major weaknesses have been exposed, analyzed, and replaced with new weaknesses."
-- Bruce Leverett, Register Allocation in Optimizing Compilers
Quote:
Several of my friends who played have in the past few months due to this have cancled and closed there entire account because of possible Id theft. They told me because they wanted me to know they weren't coming back and to make sure to remove them from the sg/vg incase there characters become active again to prevent base item theft.
Two of my friends who play Aion have had this happen in the last two weeks. I wouldn't touch Aion with a 10' pole right now.
|
I was sad because it means they will not be coming back at all.
AV
Quote:
by Star Ranger 4 WIN LOSE OR DRAW, WE WILL FIGHT. WE ARE HEROES This is what we DO! |
Decide that this will be another day in which you Walk The Talk.
MA #14724 Operation: Discredit @American Valor
Sentinel Of Liberty SG
Quote:
A friend of mine lost his account to one of these in exactly the same way. A warning that someone had changed his account password came, directing him to confirm or deny the change. He did, then found his account's password changed, then when he recovered it, found his characters stripped of items.
I get those all the time threatening to close my WoW account. I've gotten about 40 of them in the last month.
Care to guess what game I've never played in my life? |
The moral of the story is that you should NEVER follow links provided in support e-mails, just in case it's a phishing scam. It's always better to go to the actual support site manually and log in from there. I used to get mail notifications when I got PMs on the old forums, and I still didn't follow the link from there. I'm naturally cautious and distrusting of official communication I didn't specifically solicit.
A couple of weeks ago I got a fake hotmail account phishing scam. Who the HELL would want to steam my hotmail details? Who WANTS somebody else's hotmail account?
Quote:
Samuel_Tow is the only poster that makes me want to punch him in the head more often when I'm agreeing with him than when I'm disagreeing with him.
|
Quote:
The point I was making is that I don't HAVE a WoW account. I've never played the game in my life. They're trying to steal my account, and have met with abject failure because it is impossible to steal what doesn't exist.
A friend of mine lost his account to one of these in exactly the same way. A warning that someone had changed his account password came, directing him to confirm or deny the change. He did, then found his account's password changed, then when he recovered it, found his characters stripped of items.
The moral of the story is that you should NEVER follow links provided in support e-mails, just in case it's a phishing scam. It's always better to go to the actual support site manually and log in from there. I used to get mail notifications when I got PMs on the old forums, and I still didn't follow the link from there. I'm naturally cautious and distrusting of official communication I didn't specifically solicit. A couple of weeks ago I got a fake hotmail account phishing scam. Who the HELL would want to steam my hotmail details? Who WANTS somebody else's hotmail account? |
And in answer to the question at the end: People will try to gain access to other people's email accounts so they can use them to spam or phish while keeping their identities hidden. Most of the people who do this have the hacking skill to hide their IP address.
Quote:
Originally Posted by Dechs Kaison See, it's gems like these that make me check Claws' post history every once in a while to make sure I haven't missed anything good lately. |
I don't think they have any way of knowing if you do or don't have a WoW account. As far as I'm aware, WoW is famous enough to where a blind phishing scam has a decent chance of hitting on someone who both HAS a WoW account and IS rather very gullible.
Quote:
Samuel_Tow is the only poster that makes me want to punch him in the head more often when I'm agreeing with him than when I'm disagreeing with him.
|
I did. I also just edited the link in the quote to be safe.
Spines/ D A lvl 50 Scrap, stone/wm lvl 50 tank, Kat/reg lvl 50 Scrap
Grav/Kin lvl 50 Cont, Fire/Enegry lvl 50 Blast
Warshade lvl 50, PB lvl 39, nightwidow lvl 50, crab lvl 42
plant/thorns lvl 50 dom, ice/fire lvl 40 dom, grav/nrg lvl 41 dom