PC servers are restarting in:
.
They should be back up in approximately .
Sony servers are restarting in:
.
They should be back up in approximately .
Xbox servers are restarting in:
.
They should be back up in approximately .

Hacked Accounts

How plausible is this situation?

You're reading a build-thread on these forums and want to look at the passive tree. You click on the link to the build http://www.pathofexile.com/passive-skill-tree/AAAAAgMA37BXKw==. You are presented with a login-screen completely identical to the one on www.pathofexile.com. Except it is on www.pahtofexile.com. You type in your credentials and get presented with the build on the pathofexile.com domain.

In the meantime you've just inserted your credentials into a phishish site.

Would you notice if it happened? If i was tired in that situation i'd blindly type in my username and password, thinking the server had a reset or something.

That's a typical phishing situation. It's follows a not uncommon flow of actions, but there is one tiny step replaced.

It's fairly easy for someone to change http://www.pahtofexile.com/passive-skill-tree/AAAAAgMA37BXKw== into http://www.pathofexile.com/passive-skill-tree/AAAAAgMA37BXKw== right after you changed your credentials and are expecting to be presented the skill-tree.
Last edited by kligson on Feb 28, 2013, 10:38:21 AM
Got this email at 4 AM this morning...

"Your Path of Exile account has been locked because someone logged in from a location that you don't typically play from - "Ningde, Fujian, China"."

Logged in today and all my valuable currency from my stash is gone, along with my amulet that I won in a race over a year ago, Demigod's Presence. My currency is replaceable but that amulet is not.

None of my other game accounts have been hacked before, not even D3. No keyloggers on my computer. Pretty disappointing...
"
ardikus wrote:


Logged in today and all my valuable currency from my stash is gone, along with my amulet that I won in a race over a year ago, Demigod's Presence.


When was the last time you played? You shouldn't have anything from a year ago since the final character wipe was last month.
"
Azuri21 wrote:
"
ardikus wrote:


Logged in today and all my valuable currency from my stash is gone, along with my amulet that I won in a race over a year ago, Demigod's Presence.


When was the last time you played? You shouldn't have anything from a year ago since the final character wipe was last month.


Demigod's was the one exception. It was the only thing people were allowed to keep apart from their character names, because it's so special.
"
MonstaMunch wrote:
"
Azuri21 wrote:
"
ardikus wrote:


Logged in today and all my valuable currency from my stash is gone, along with my amulet that I won in a race over a year ago, Demigod's Presence.


When was the last time you played? You shouldn't have anything from a year ago since the final character wipe was last month.


Demigod's was the one exception. It was the only thing people were allowed to keep apart from their character names, because it's so special.


That's exactly why it's so upsetting.
"
MonstaMunch wrote:


Demigod's was the one exception. It was the only thing people were allowed to keep apart from their character names, because it's so special.


I was not aware of that. Incidentally I got an email saying my account was locked this morning from the same location. I've not been able to check my contents yet since I'm at work on a smartphone.

I've not had a account compromise ever prior to this my gut feeling tells me there is another underlying issue we don't know about. I doubt GGG knows either.
i just have been hacked too :/
1 alch - 1 chaos shop ... and more http://www.pathofexile.com/forum/view-forum/306
I don't understand how people are still getting hacked. When hacker login is from somewhere else the account gets locked, do the hackers have access to victim's email or something?
"
wonko33 wrote:
I don't understand how people are still getting hacked. When hacker login is from somewhere else the account gets locked, do the hackers have access to victim's email or something?


I can't confirm until I actually get home looking at my account online everything looks intact and the lock worked as intended but for others if I read it correctly their accounts got stripped before the lock kicked in?
Someone attempted to hack my account this AM as well, they didn't make it in due to the email verification. Probably my fault for using a 'common' password for several things (already in the process of phasing that out though).

I think the reason PoE has the significant hacking problem is the rarity and value of currency combined with the difficulty in farming it. It probably sells well for real $$ and is a pain to farm for so the easy answer for the sellers is hack any and every account they can.

Report Forum Post

Report Account:

Report Type

Additional Info