Unauthorized charges and no reply from support?

No one is asking for your simple online security advice. Chargeback is needed if the company is not responding to support tickets about fraudulent activity.

In fact, if more of these cases start appearing, GGG might have a lawsuit on their hand. A website with poor security, no 2FA option, and it allows purchases without 2FA verification is ripe for review.
"
No one is asking for your simple online security advice. Chargeback is needed if the company is not responding to support tickets about fraudulent activity.

In fact, if more of these cases start appearing, GGG might have a lawsuit on their hand. A website with poor security, no 2FA option, and it allows purchases without 2FA verification is ripe for review.


To me it seems like security advice is needed when random ppl have access to your account ...
Why a lawsuit - your account security is also your responsibility not just theirs.


Also damages on their side are pretty limited since even when they refund you at some point they can just retract keys, disable MTs and pretty much have lost nothing.

Even if someone bought a million keys with your account they could simply deactivate all of them and refund the money - since they are selling nothing outside of their own ingame store i doubt that there is a high risk for big damages.
Last edited by _N0ctus_#6387 on Dec 20, 2024, 9:07:23 AM
"
vandald#7309 wrote:
Same thing happened to me this morning. I wasn't playing either PoE, and I didn't even have any browsers open, but I got 8 (4 from PayPal, 4 from XSolla) emails about 4 purchases that I didn't make.

Wonder how widespread it could be.


Change your password asap. And if you use that password anywhere else - change it aswell.
"
_N0ctus_#6387 wrote:
"
No one is asking for your simple online security advice. Chargeback is needed if the company is not responding to support tickets about fraudulent activity.

In fact, if more of these cases start appearing, GGG might have a lawsuit on their hand. A website with poor security, no 2FA option, and it allows purchases without 2FA verification is ripe for review.


To me it seems like security advice is needed when random ppl have access to your account ...
Why a lawsuit - your account security is also your responsibility not just theirs.


Also damages on their side are pretty limited since even when they refund you at some point they can just retract keys, disable MTs and pretty much have lost nothing.

Even if someone bought a million keys with your account they could simply deactivate all of them and refund the money - since they are selling nothing outside of their own ingame store i doubt that there is a high risk for big damages.


Failure for a company to provide security to its consumers data is grounds for a lawsuit. There are plenty of lawsuits like this, just google it.

Their website lacks basic security controls that are common to most websites in 2024. Prime example is 2FA. My 100 person church has 2FA on their website, it is not hard to implement. It shows a lack of concern for consumer data safety.

Telling someone who just had $150 stolen from them to "change their password" is just rude. People are angry their money was taken, and GGG is partly to blame for making it so easy for hackers to access accounts.
"
"
_N0ctus_#6387 wrote:
"
No one is asking for your simple online security advice. Chargeback is needed if the company is not responding to support tickets about fraudulent activity.

In fact, if more of these cases start appearing, GGG might have a lawsuit on their hand. A website with poor security, no 2FA option, and it allows purchases without 2FA verification is ripe for review.


To me it seems like security advice is needed when random ppl have access to your account ...
Why a lawsuit - your account security is also your responsibility not just theirs.


Also damages on their side are pretty limited since even when they refund you at some point they can just retract keys, disable MTs and pretty much have lost nothing.

Even if someone bought a million keys with your account they could simply deactivate all of them and refund the money - since they are selling nothing outside of their own ingame store i doubt that there is a high risk for big damages.


Failure for a company to provide security to its consumers data is grounds for a lawsuit. There are plenty of lawsuits like this, just google it.

Their website lacks basic security controls that are common to most websites in 2024. Prime example is 2FA. My 100 person church has 2FA on their website, it is not hard to implement. It shows a lack of concern for consumer data safety.

Telling someone who just had $150 stolen from them to "change their password" is just rude. People are angry their money was taken, and GGG is partly to blame for making it so easy for hackers to access accounts.


Yes but it wasnt a failure of a company. Pretty sure that there is no case like this with a chance of winning. If you mean the cases where companies got hacked - thats a completely different story.

I hate that everything has 2FA these days - its mostly annoying - important stuff optional but everything - no thanks.

If your car gets stolen because you loose your keys then its also not the car companies fault.

Also as i said - there is no real damage in this case - everything buyable can be disabled by them and refunded. I cant think of a scenario where there would be real damage.


Telling someone who has just lost money is not rude - its helpful and probably needed advice. Also as i said - i doubt that any of this money is lost.
How is GGG making it easy? 2FA isnt used in many places and also wasnt used just some time ago.

Yes there can always be something out of your control - but as i said - i doubt there will be damage in this case since there is no possible way to transfer the money stolen into anything outside the direct influence of GGG.

If someone hacks your account and buys 2k keys - GGG just disables the keys and refunds - where is the damage?
Last edited by _N0ctus_#6387 on Dec 20, 2024, 9:28:59 AM
I filed a dispute with Paypal and got the fraudulent charges reversed almost instantly.

I'm not waiting on Xolla or whatever they're called to realize they've been breached internally or by someone else.

I'm surprised and grateful that Paypal acted so quickly. - This may indicate that this is a more widespread issue with this company.

Folks, I would suggest that you remove your payment information from your game account and change your passwords.
"
I filed a dispute with Paypal and got the fraudulent charges reversed almost instantly.

I'm not waiting on Xolla or whatever they're called to realize they've been breached internally or by someone else.

I'm surprised and grateful that Paypal acted so quickly. - This may indicate that this is a more widespread issue with this company.

Folks, I would suggest that you remove your payment information from your game account and change your passwords.



There is a 99% chance that they werent breached internally.

Also by doing a chargeback you actually also break your contract with GGG. You shouldnt wonder when your account gets locked.

Also looking at this forum - this isnt a widespread problem - so chances are there has been no leak/hack or whatever in regards to the game or payment itself.

Just a tip for the future when you will complain that your account got locked - at least temporarily.

Only do chargebacks when you have no other way within the timeframe you can do them.

Im waiting for your next thread about losing access.
Last edited by _N0ctus_#6387 on Dec 20, 2024, 9:34:49 AM
"
_N0ctus_#6387 wrote:


There is a 99% chance that they werent breached internally.

Also by doing a chargeback you actually also break your contract with GGG. You shouldnt wonder when your account gets locked.

Also looking at this forum - this isnt a widespread problem - so chances are there has been no leak/hack or whatever in regards to the game or payment itself.

Just a tip for the future when you will complain that your account got locked - at least temporarily.

Only do chargebacks when you have no other way within the timeframe you can do them.


I'm not interested in a company playing around with money or security. It's their responsibility to offer 2FA or protect my PI when I give them money legitimately.

That's fine if they want to ban my account because of their own security issues, I absolutely will gladly do another chargeback for the early access key I legitimately paid for earlier this month. No game is worth my financial peace of mind
Last edited by VaasMontenegro#3577 on Dec 20, 2024, 9:39:12 AM
"
_N0ctus_#6387 wrote:
"
"
_N0ctus_#6387 wrote:

To me it seems like security advice is needed when random ppl have access to your account ...
Why a lawsuit - your account security is also your responsibility not just theirs.


Also damages on their side are pretty limited since even when they refund you at some point they can just retract keys, disable MTs and pretty much have lost nothing.

Even if someone bought a million keys with your account they could simply deactivate all of them and refund the money - since they are selling nothing outside of their own ingame store i doubt that there is a high risk for big damages.


Failure for a company to provide security to its consumers data is grounds for a lawsuit. There are plenty of lawsuits like this, just google it.

Their website lacks basic security controls that are common to most websites in 2024. Prime example is 2FA. My 100 person church has 2FA on their website, it is not hard to implement. It shows a lack of concern for consumer data safety.

Telling someone who just had $150 stolen from them to "change their password" is just rude. People are angry their money was taken, and GGG is partly to blame for making it so easy for hackers to access accounts.


Yes but it wasnt a failure of a company. Pretty sure that there is no case like this with a chance of winning. If you mean the cases where companies got hacked - thats a completely different story.

I hate that everything has 2FA these days - its mostly annoying - important stuff optional but everything - no thanks.

If your car gets stolen because you loose your keys then its also not the car companies fault.

Also as i said - there is no real damage in this case - everything buyable can be disabled by them and refunded. I cant think of a scenario where there would be real damage.


Telling someone who has just lost money is not rude - its helpful and probably needed advice. Also as i said - i doubt that any of this money is lost.
How is GGG making it easy? 2FA isnt used in many places and also wasnt used just some time ago.

Yes there can always be something out of your control - but as i said - i doubt there will be damage in this case since there is no possible way to transfer the money stolen into anything outside the direct influence of GGG.

If someone hacks your account and buys 2k keys - GGG just disables the keys and refunds - where is the damage?


Damages come in all forms, more than just monetary. Loss of personal data is considered damages. You do not seem to know what you are talking about. Security for a website is solely in the hands for the company who runs the website. 2FA is standard for website security. Password and phrases just are not secure anymore due to the high number of data breaches occurring worldwide.

Also, your analogy does not apply here. I did not lose my car keys in this case. Using your analogy, a copy of my keys was stolen from the car company due to a lack of security by that company and then used to steal my car.

And it is quite rude. The money is probably going to be refunded, however, some people cannot wait for their $150 to be refund. That could have been grocery money. It could have causes them to go negative in their bank account, leading to more money lost in fees. Coupled with the fact that GGG is not responding to refund requests in a timely manner, chargebacks are the only solution for many. I am not saying GGG is wrong for locking accounts (it is probably an automated process), but they are making themselves look bad in the process.
Exactly. This _N0ctus_#6387 user has no clue what they are talking about.

Report Forum Post

Report Account:

Report Type

Additional Info