• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Diablo 3 accounts hacked, gold and items stolen

benny_a

extra source of jiggaflops
Eurogamer said:
Eurogamer has received multiple reports of Diablo 3 accounts being hacked.
[...]
The reports coincided with the EU Diablo 3 servers going offline on Sunday afternoon for around four hours, preventing players from logging in (error 33). It has been suggested that the EU servers were taken offline following a SQL injection attack, but this remains unconfirmed.

I just took a quick glance at the OT and it seems people on there were affected as well.

Reports are coming that people had their B.Net accounts logged in at the time of the hack.

Eurogamer's own Christian Donlan had his account hacked:
491x-1


Source
 

marrec

Banned
To be fair, half of everything that has happened in the last 7 days can be coincided by Diablo III server downtime.
 

bengraven

Member
Why the fuck don't they require the Authenticator to log in? Yes, it's been nice to have a break from it, but then this happens.
 

LiK

Member
i know the Eurogamer article mentioned that some people with Authenticators were affected too but it was pretty vague. Donlan didn't use an Authenticator which was kinda foolish.
 

Nibel

Member
Why the fuck don't they require the Authenticator to log in? Yes, it's been nice to have a break from it, but then this happens.

Is this effecting people that have an authenticator tied to their account as well???

Blizzard offers an Authenticator designed to provide extra security to your account. Donlan did not have the authenticator before the hack, but reports suggest accounts have been compromised even with this enabled.

Well.. :/
 

Derrick01

Banned
It's a good thing you had to make an account and have your internet on to play a single player game. Stop all those nasty and evil pirates.
 

benny_a

extra source of jiggaflops
Is this effecting people that have an authenticator tied to their account as well???
Eurogamer says the following:
Blizzard offers an Authenticator designed to provide extra security to your account. Donlan did not have the authenticator before the hack, but reports suggest accounts have been compromised even with this enabled.
 
Get authenticator and mobile alerts if you haven't already.

It's theoretically possible to get hacked with an authenticator, but it was always hard (required real time hacking and makes it obvious to the victim). Furthermore it's much harder now that the authenticator isn't required to log in every time.
 

marrec

Banned
Seems very hearsayish at least in terms of authenticator based accounts getting hacked. Sucks if that's the case, but I shall wait and see if we get more concrete info on at least that aspect of all of this.

If the Authenticator accounts have been hacked then that would be pretty good evidence of some kind of SQL dump.

Though, it would be pretty shitty of Blizzard to not store account credentials in an encrypted state, I'm thinking that these 'widespread' hacks aren't actually as widespread and is just keyloggers doin' what keyloggers do.

Just cause someone who works with Eurogamer got hacked doesn't mean he wasn't keylogged.
 
popcorn.gif

The fallout from this could be interesting, especially if authenticators are not providing ample security.
Somehow I doubt that.

Everyone should use an authenticator.
 

marrec

Banned
Should have read the op.

OP doesn't say anything about Authenticators and doesn't actually have any proof of some injection attack.

As an aside, since when did the SQL injection become the new thing that journalists assume when something is hacked? SQL is the new DDoS.

I'm certain that Blizzard would encrypt account credentials so even if there was an SQL dump there would be no way to get passwords, sounds fishy.
 

JoeBoy101

Member
Had something like this happen to me this morning. Was playing D3 when I got kicked to the login screen with the notice "Another computer has logged in on this account". In a frenzy, I did a quick scan for keyloggers, jumped over to my account management and changed my password, and then got the authenticator.

Came back into the game and still had everything on my characters, but yeah. If the notice I got was legit, I got hacked while in mid-play.

jokkir said:
I guess I should get my authenticator up and running? >__>

Got a smartphone? Then it's a free app. Do it now, unless you don't mind risking all the hours of gameplay on your characters.
 

Vanillalite

Ask me about the GAF Notebook
I guess I should get my authenticator up and running? >__>

Your crazy not to.

I said in the |OT| Diablo III thread the day before the release that we should create a separate topic on GAF urging ever GAFer with a B.Net account to make sure they had an authenticator setup. I never made a thread though. :/
 

HoosTrax

Member
How widespread is this? There were a lot of pre-orders sold, but I guess the implication is that the number of compromised accounts is higher than what would be expected solely due to phishing, keylogging, etc?
 

marrec

Banned
How widespread is this? There were a lot of pre-orders sold, but I guess the implication is that the number of compromised accounts is higher than what would be expected solely due to phishing, keylogging, etc?

It's probably about as widespread as account hacks in WoW in that it's extremely widespread if you don't protect your account in the proper ways.
 

Fersis

It is illegal to Tag Fish in Tag Fishing Sanctuaries by law 38.36 of the GAF Wildlife Act
Diablo 3 accounts looted
 
I've never gotten an authenticator because the idea of tethering my account to another password and requiring me to have my phone or that keychain dongle whenever I log in always seemed like too much of a pain.

Maybe I should finally take the plunge and secure all my shit.
 

LiK

Member
Your crazy not to.

I said in the |OT| Diablo III thread the day before the release that we should create a separate topic on GAF urging ever GAFer with a B.Net account to make sure they had an authenticator setup. I never made a thread though. :/

it's common sense at this point considering the amount of account thefts on WoW and to some extent on SC2. using an Authenticator is so simple.
 
Probably has something to do with the dozens of weekly emails I get about my bnet account that's about to be banned unless I give them my login info.
don't even have a bnet account associated to that email lol


But, an Eurogamer writer wouldn't be that stupid... right?
 

JoeBoy101

Member
I've never gotten an authenticator because the idea of tethering my account to another password and requiring me to have my phone or that keychain dongle whenever I log in always seemed like too much of a pain.

Maybe I should finally take the plunge and secure all my shit.

As I said before:

"Got a smartphone? Then it's a free app. Do it now, unless you don't mind risking all the hours of gameplay on your characters."
 

Rokam

Member
I've never gotten an authenticator because the idea of tethering my account to another password and requiring me to have my phone or that keychain dongle whenever I log in always seemed like too much of a pain.

Maybe I should finally take the plunge and secure all my shit.

You only have to enter it once a week, unless you're logging in from a different computer each time you play.
 

SMT

this show is not Breaking Bad why is it not Breaking Bad? it should be Breaking Bad dammit Breaking Bad
So this autheticator business is for real.
 

erpg

GAF parliamentarian
If you're playing a Blizzard game, knowing about all the WoW account hacks throughout its history, and aren't using the security feature they added 4 years ago... I'm sorry, but there's just no pity in me.
 
Top Bottom