test content
What is the Arc Client?
Install Arc

How many?

PWE and STO account have been recently TRIBBLE?

I am careful, my OS, anti-virus, firewall & anti-malware software is all up to date.
I do not share passwords or give out my details to others.

Yet to today my STO account got TRIBBLE.

First sign was an email from PWE saying my email address for my account, had been changed at "my" request.

This was at 8:54am GMT, I swiftly reacted and despite getting control of my account back at 9:17am GMT. 3 of my 4 characters had been stripped of all EC, refined dilithium, my account bank emptied of EC and all the saved ZEN I had was gone.

I literally interrupted the guy in the act, as I was checking what had gone, I was de-friended by "@*******", an account handle I do not know.

I had saved over 60million EC up for a Tholian Recluse Carrier or Jem'Hadar
Dreadnought, still had not made my mind over which to go for.

I had over 7000 ZEN saved for when 'Legacy of Romulas' came out to buy a few ships.

my refined dilithium was bening saved for buying fleet ship and equipment.


ALL THIS now gone, and so is my enthusiasm for playing STO.


EDIT account handle removed, since suspicion not proof.
Post edited by silverline on

Comments

  • intrepid74656intrepid74656 Member Posts: 0 Arc User
    edited May 2013
    Maybe you can contact PWE/Cryptic so they can restore your account but I doubt they will do anything.
    [SIGPIC][/SIGPIC]
  • grouchyotakugrouchyotaku Member Posts: 0 Arc User
    edited May 2013
    Sorry for your lose, but these days, most account hacks occur due to malicious 'Flash' or 'Java' banner adds with 'keylogger' functionality. The best advice is to avoid using your Browser when you play STO.

    Cryptic/PWE does have the ability to roll back accounts, so you should send a support ticket or contact Support with 'Account TRIBBLE' as the subject...
  • silverlinesilverline Member Posts: 0 Arc User
    edited May 2013
    I run NoScript on my browser, which stop any adverts like that.
  • sollvaxsollvax Member Posts: 4 Arc User
    edited May 2013
    Zen has a cash value
    this is therefore a criminal offence
    I suggest you contact the authorities
    Live long and Prosper
  • alastairnallalastairnall Member Posts: 0 Arc User
    edited May 2013
    Same thing happened to me, it seems roughly an hour or two before it happened to the OP. It took them a day and a half to lock my account, by which time it was far too late. Then it took them another three days to unlock it once I verified my identity. I'm still waiting to see if they're going to restore all the stuff that was taken or destroyed. Been about two and a half days since their last reply.

    I think the worst part of it is how easy PWE makes it for somebody to steal. I can't speak for the OP, but the fact that the thief was able to change the email address on the account (in both of these cases it seems) with no confirmation needed from the real account holder or registered email address, thus bypassing any safeties of the "Account Guard" system they have in place...it's just insane.
  • xcom43xcom43 Member Posts: 723 Arc User
    edited May 2013
    I really Hope the account system is not TRIBBLE again.

    You need to change passwords like once a month or every 6 months.

    Another thing i don't get is how they got into the system when it has a account guard sent to your email so may be your email has been TRIBBLE as well might want to change that password as well.
    The fear of death follows from the fear of life. A man who lives fully is prepared to die at any time.
  • disposeableh3r0disposeableh3r0 Member Posts: 1,927 Arc User
    edited May 2013
    Seeing as accountguard also asks you to verifiy every time you use a different computer I would check my varification list.

    This can be accessed through the my account link then clicking on the accout guard icon.

    It will show a list of every borwser/computer verified with an ip address. As well as if account guard is enabled/disabled
    As a time traveller, Am I supposed to pack underwear or underwhen?

    Not everything you see on the internet is true - Abraham Lincoln

    Occidere populo et effercio confractus
  • disposeableh3r0disposeableh3r0 Member Posts: 1,927 Arc User
    edited May 2013
    So just for fun I changed my assigned email.

    It was prety easy.

    All I had to do was enter my password once and click a confirmation in the new email.

    But I dont think PWE can do much about it since it all revolves around a compromised email account.
    As a time traveller, Am I supposed to pack underwear or underwhen?

    Not everything you see on the internet is true - Abraham Lincoln

    Occidere populo et effercio confractus
  • grouchyotakugrouchyotaku Member Posts: 0 Arc User
    edited May 2013
    silverline wrote: »
    I run NoScript on my browser, which stop any adverts like that.
    Though, of course, this would be useless if the link to the malicious script was embedded in the webpage itself.. This happened once to the Fleet Website I visit, and was quickly detected by Google search. Took a couple of weeks to clean up that mess...
  • alastairnallalastairnall Member Posts: 0 Arc User
    edited May 2013
    The account guard doesn't even come into play.

    ** Decided to remove the details so as not to give anyone ideas. I've explained the process in my ticket and I'm sure the OP knows what I'm talking about. Bottom line is account guard only works if your account and your email address are not compromised. If the would be thief can get into your account on the website, the account guard won't protect you.
  • alastairnallalastairnall Member Posts: 0 Arc User
    edited May 2013
    And...looks like my edit doesn't matter. After I got control of my account back, I was able to get into my account guard and found the IP the thief had authorized. Although this is a bit strange....just tried from a different browser on my laptop and yes, the account guard stopped it.

    So apparently I was incorrect, or it's something that PWE has fixed since the breach. I can say with no doubt that my main email address received no requests (account guard or otherwise) outside the notification that the email address was changed. My mails go straight to my cell phone, so even if the thief had gotten access to my email account somehow and authorized himself, then deleted the mails and the trash, I would've still been pinged when the mail came in.
  • xcom43xcom43 Member Posts: 723 Arc User
    edited May 2013
    First what i would do is go to majorgeeks.com and sign up if you do not have a account all ready.

    Main site--->>http://forums.majorgeeks.com/

    Then when you are done signing up Go here.

    The maleware forum rules please read them-->>http://forums.majorgeeks.com/showthread.php?t=195272

    Follow every detail other wise they will not help.And these guys are experts.I have been using this site for over 15 years now.

    Here is the main link-->>http://forums.majorgeeks.com/forumdisplay.php?f=35

    You think you got rid of all of your virus or malware or other stuff.I would think not some times these little buggers can be hard to remove and spot.
    The fear of death follows from the fear of life. A man who lives fully is prepared to die at any time.
Sign In or Register to comment.