Stolen Account

"
Jongo wrote:
"
dannis wrote:
I doubt his account was hacked due to a keylogger. With the rash of cases lately, GGG most likely got popped. Probably what happened was some Chinese hackers compromised a server or database and stole account credentials. Then they used the credentials to log in to the game client and steal items from the Stash.

I got a similar message early this morning:
"
Your Path of Exile account has been locked because someone logged in from a location that you don't typically play from - "Yangzhou, Jiangsu, China".


This is what I suspect also, I received an email this morning saying my account had been logged in from "Shaoxing, Zhejiang, China" thankfully I roll with a 1 password per service routine so it shouldn't affect anything else if it is stolen credentials.

Annoying none the less, either way gonna spend the day seeing if I managed to download anything dodgy in the 2 weeks since I completely re installed windows :/



This.
At least they could admit they've been breached so people can stop getting freaked out about keyloggers.
Just make sure you change ur password before u unlock ur account and it's going to be ok.
"
jack7514 wrote:
If his machine was compromised, then all his other accounts would more than likely show unauthorized activity. This is/was on GGG's side of the cesspool/internet.

Agreed. I was able to log in via the website (obviously), and did not have to enter an unlock code there. I changed my account password and I have not yet logged back in to the game. You can see what items you characters have and I did notice several items missing from my Stash, but not my inventory. I feel that I will leave my game account locked and parked where it is until GGG sorts out this breach.
"
lagwin1980 wrote:
"
Dimonium wrote:
i work on IT security with professional security software and Hardware Firewall
MY PC WAS NOT COMPROMISED

GGG send me a mail where they explain that their policy does not cover damages
just leave game with my friends for this reason

good luck all


You might work in IT but your PC was/is compromised, also most,very near all cases investigated by GGG have proven this to be true, so your ignorance just because you work in IT is going to be your biggest problem... and you should know that PC's are never truly secure.


Like someone replied, it's not a keylogger issue.

A database somewhere was compromised and email/password combinations were obtained by a Chinese firm. They then try these combinations on set websites, especially email, paypal, and probably banks.

The best way I can possibly suggest is to use unique and different password for important websites. Your email password should not be the same as your paypal. In the same way, every email you own should be different.

The differences don't have to be huge, as an example, if your default password is Bl4ckM3sa, your gmail password could simply b Bl4ckgM3sa, or Bl4ckM3sag, while your paypal could be Bl4ckpM3sa.
"
veksen wrote:
Like someone replied, it's not a keylogger issue.

A database somewhere was compromised and email/password combinations were obtained by a Chinese firm. They then try these combinations on set websites, especially email, paypal, and probably banks.


How can you say with such certainty that a database was compromised? The amount of users affected by this hack is minor in comparison to the overall number of accounts. Also GGG is fairly certain they were not breached, and I'm apt to believe them on it since they've been so open about everything else.

You can speculate that a database was compromised, but you cannot say for certainty that it was, just as I cannot say for certain that all the users hacked visited a specific website, or download a specific program and it compromised their system. It is all speculation, but evidence leans more toward my speculation than toward yours.

Also, if the hackers DID get database access, there are much easier ways to steal stuff. Why not just run a command to UPDATE the table and move all the items into their account? etc.

Report Forum Post

Report Account:

Report Type

Additional Info