So, I've been hacked.
Not the first nor the last person in Universe to face that
BUT the details are interesting.
Logged into the game as usual and saw a new lvl 1 character. Then i saw my Astral Diamonds are gone. And yes I was foolish enough to buy the 200 euro founder's pack.
So, I checked my email and saw a confirming message that a browser with an IP from IRAN was sucessfully saved.
Then i checked the email activity (gmail has this nice feature) and my email was accessed ONLY from my IP's.
This makes me conclude that my email was NOT hacked.
Also I do have different passwords for game account and email account.
On a side note, if they see that I logged in 100 times from somewhere in Europe and suddenly I log in from Iran, shouldn't this raise a flag somwhere?
So can anyone explain what happened?
Is this game even safe to play? Considering you are "free to pay" for it?
Cheers.
Comments
pop a support ticket and see what they can do.
Ability Scores || All Attribute Roll Combinations || My Cleric Stream \o/
only the gateway.playneverwinter.com via mobile browser or pc browser. no apps are officially launched (by Cryptic or PWE) so i wont download any until then.
Ability Scores || All Attribute Roll Combinations || My Cleric Stream \o/
Did that one week ago.
As expected I only got an automated answer. Waiting for the second automated answer to tell me to resubmit the ticket as they lost the first one.
From what i've heard this is common practice for them :rolleyes:
No I didn't.
By ; @pestilence149
Gladiators of Dhara (Easy) & (Hard)
ELIGIBLE FOR THE DAILY FOUNDRY REWARDS!
Search by Best : Name/Summary/Short-Code ; Gladiators
NW-DJJS7OWZI (For easy)
NW-DPT9I8RKF (For hard)
Any feedback and suggestions are welcome please enjoy!
Was it brute force or something?
I am really reluctant to invest any time or money in a game that can't guarantee my account safety.
1: Your info (account name/email/password combination) was on a 'list' somewhere and they just tried it to try it. More possible if you've used this account name and this password in an MMO before.
2: fake site. Do you use, for example, the Neverwinter Wiki? It's possible the hackers got a fake website up top on google and were able to get a keylogger onto you while you were following the links on NW wiki or a fake gateway one day.
My only conclusion is that the breach of my original password occurred from PW's side as I don't use gateway nor have I purchased any gold, zen and such, just the $60 pack. As soon as whomever saw that I had 600k AD, the access attempts started.
If you responded to any official looking PM's that had links in them you may have given away your password and account name.
If your account name is fairly straight forward or the same as your forum name and your password isn't super secure you could have suffered a brute force hacking attack on it. Or if you use that account name/password combination in another game.
If you gave your account name and password to any friend no matter how trustworthy, or guildy.
If you have a keylogger or other trojan designed to steal game information and send it on on your computer.
If you used a 3rd party app to access the gateway website. [You said not this]
If you use a 3rd party app to make your gaming easier. [some of them/a lot of them are not at all trustworty. Some are very trustworty.]
And there are others though those are the most common.
[SIGPIC][/SIGPIC]
The $60 pack goes through a different vendor than zen purchases do. And it sounds like someone got only your account name and tried to brute force hack it.
[SIGPIC][/SIGPIC]
Also not using bots or other **** like that
Still, even if my game password was hacked, if the hackers accessed the game from a different IP then the ones I have validated, they should have used a confirmation code sent to my email. And my email was not hacked.
Or is it something that I don't understand here?
This is the part that scares me. So far, it looks like people who bought any kind of packs are the ones who are being targeted. I could be wrong here, but has anybody who hasn't bought a pack (or spent money in any other way) been hacked?
Again, I still do not understand how was I hacked without my email being hacked.
This is really scarry and people that buy packs should be made aware of it.
There justification....but it had four stars and the guy who made it answered questions in the review. :rolleyes:
Honestly unless it comes from PWE or cryptic don't use it.
So what's the point of the email verification code then? If you can be hacked bypassing the email code pwe sends, it's all useless.
Also, Day 10 w/o any real answer from pwe (except the automatic macro)