• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Hey, has your Xbox Live account been hacked/FIFA'd? Post here!

Kurtofan

Member
Garcia el Gringo said:
I assume unique/complicated passwords for every account (especially for your Windows Live ID and your EA accounts) and to check your computer for keyloggers.
I don't have an EA account, Windows Live ID is the Xbox account right?
 
Kurtofan said:
What can I do to avoid being hacked?

Change your password to something unique, long and very complicated, keep an eye on your XBL account (check it at least once-twice a day), check the email account that's associated with your XBL account regularly.

If you haven't already done, remove your CC/DC as a precautionary measure.
 
One of the questions being asked should also be if they were a part of any other leaks of info like with PSN and a few MMO games.
 
larvi said:
Another good point of information that would be useful would be how strong the passwords were on the accounts that got hacked:

https://www.microsoft.com/security/pc-security/password-checker.aspx

If it's only weak passwords getting it cold just be brute force tyoe of hacking that is getting the pws

this password checker is lame, it only goes by length, i typed in a like 20 times and it gave me best, however my real password it said was weak
 

Smokey

Member
So the guys getting 8,000 points taken from their accounts...I'm assuming you guys have your CC info linked to your XBL account. Unless you just have THAT many points lying around? I don't have my CC linked to my XBL account anymore and have only used point cards/subscription cards. Do I have anything to worry about?
 
Speedymanic said:
For sure and they are probably already being flooded with them. Standard practice nowadays is to contact your bank who take of everything from refunding the money to contacting the police who, I assume, issue a CRN for insurance purposes. (at least that's my understanding of the procedure, but I admit my knowledge in the area is very limited and I might be wrong.)
Actually it's the other way around (or was a few years ago when I worked alongside the fraud team at a bank). To make a claim of fraud you had to provide a CRN, kind of to prove you weren't just taking the piss, I guess. There may have just been a threshold the claim had to go over, I don't fully remember, but people were definitely asked to obtain CRNs and come back.

Either way, I haven't heard a single person claim to have contacted the police about this in any of the 37 threads about it, and if everyone starts doing it then people will start taking notice. I mean, if the police start getting hundreds of crimes reported with similar circumstances they might think something of it.
 
toythatkills said:
Actually it's the other way around (or was a few years ago when I worked alongside the fraud team at a bank). To make a claim of fraud you had to provide a CRN, kind of to prove you weren't just taking the piss, I guess. There may have just been a threshold the claim had to go over, I don't fully remember, but people were definitely asked to obtain CRNs and come back.

Either way, I haven't heard a single person claim to have contacted the police about this in any of the 37 threads about it, and if everyone starts doing it then people will start taking notice. I mean, if the police start getting hundreds of crimes reported with similar circumstances they might think something of it.

I stand corrected. I only assumed it was that simple as that's all my GF had to do some months ago when she was hit with some charges she didn't make. It was only £48 worth though, so maybe there's a threshold to the claim as you said.
 

Chindogg

Member
-9/18
-6000 MS points
-Situation Resolved
-Played FIFA 11
-Unique Password
-5 years old
-After several back and forth conversations between MS, Paypal, and my bank the situation has been resolved. All purchases refunded and two months of XBL rewarded for my troubles.
 

Kurtofan

Member
Speedymanic said:
Change your password to something unique, long and very complicated, keep an eye on your XBL account (check it at least once-twice a day), check the email account that's associated with your XBL account regularly.

If you haven't already done, remove your CC/DC as a precautionary measure.
Is an account useless to hackers without CC info on it?
 

Zoe

Member
Kurtofan said:
I don't have an EA account, Windows Live ID is the Xbox account right?

For someone in another thread, they actually created an EA account because she didn't have one.

Until the source is found, keep you CC off your account.
 
A question to those saying they had unique EA passwords. How did you enter your own password? From what I can recall (it's been a long while so I might be wrong/mistaken), it was done automatically. I don't remember there even being an option to enter my own password when I played BC2 or ME2 for the first time.

Do you have to do it via the website?
 
Kurtofan said:
Is an account useless to hackers without CC info on it?

Not really, they can still use any points you have to buy those gold packs. Unless you don't have enough points, then I'm not sure what would happen.
 

Pug

Member
My account was hacked on the 21st of october. My 5500 point were used to buy various arcade game and character add on for games i dont own. 4400 point also bought. Card suspended hack still being investigated. Im not happy.
 
Lyphen said:
I noticed this yesterday while on Xbox.com (I've become paranoid and check my profile page once a day to make sure there haven't been any logins). Hoping it's a new 2-step authentication for Windows/Xbox LIVE accounts.

http://i.imgur.com/N4Kpf.png[IMG][/QUOTE]
This better be a 2-step authentication, and it better be ready asap. It's something they should have had a long time ago.
 
Are there any keywords or tricks to get support to get your investigation done asap? I can't believe that some people are reporting that they're getting their account back within a week or so. It really can't just be luck, right?

I'm more interested in finding out that than how I got hacked.
 

JambiBum

Member
Got hacked on the 26th of October.

Lost 7600 points. Luckily they were points that I got for free so I didn't lose any real money.

The guy bought actual games with my account. Three arcade games and three games on demand. Also bought one fifa pack.

I noticed it when my twitter said that I was playing fifa which I don't own.

EA account and live had the same passwords. Since changed them.

Called MS and got the 25 days spiel. Decided since I didn't lose actual money I didn't want to have my account locked. The guy I talked to was really helpful. Said that I can call back any time if I decide to do something about it.
 

Thoraxes

Member
-The date it occurred: August 28th.
-Your "damages" (points spent, games played you don't own, etc.): No record of where the points were spent, MS erased them fast but didn't refund my money. I had $75 stolen from me.
-Your current situation with MS (if your account is suspended, under investigation, etc.): Don't know anymore. I gave them a month and just went to my bank to fix it. My bank and the BBB got my money back in less than 2 days compared to the month I had to wait for MS to do absolutely nothing.
-If you have an EA account of any kind, or have played any EA games in the past few months: I had a Spore, Sims, and ME2 account. I now also have an Origin account.
-If your password, to your knowledge, was a unique one between your EA and MS account:The one in my MS account was different from the other one.
-How old your Gamertag/Live account is, and: 3 years old it is. I used it to buy AoE on PC when it was $1.
-Your compensation, and whether it's been resolved or not: My bank compensated me. MS didn't do shit, even after 5 phone calls. I assume my bank had better luck.
 

big_z

Member
Microsoft should blacklist FIFA from accessing online until ea fixes this shit.

Now I'm worried about adding points to my account. Activated points cards don't expire do they?
 
-The date it occurred
-October 19th

-Your "damages" (points spent, games played you don't own, etc.)
-10000 MSP purchased with saved credit card. 3 FIFA 12 "Gold Packs" purchased, along with 5 FIFA achievements.

-Your current situation with MS (if your account is suspended, under investigation, etc.)
-Suspended Xbox live account under investigation, "up to 25 days usually".

-If you have an EA account of any kind, or have played any EA games in the past few months
-EA account w/same name as Xbox Live account. Last EA game played was Alice for pc, and Dead Space 2 on 360 back in March. Never once played an EA sports game.

-If your password, to your knowledge, was a unique one between your EA and MS account.
-Not sure if unique to each, but all passwords everywhere have since been changed to unique ones :/

-How old your Gamertag/Live account is, and
-Gamertag from 2005

-Your compensation, and whether it's been resolved or not.
-Nothing yet. Points removed, no money refunded, no Xbox live service or vouchers for lost time.
 
-The date it occurred
-November 3rd

-Your "damages" (points spent, games played you don't own, etc.)
-~4100 points on account, all spent on FIFA packs

-Your current situation with MS (if your account is suspended, under investigation, etc.)
-Suspended Xbox live account under investigation, "up to 25 days usually".

-If you have an EA account of any kind, or have played any EA games in the past few months
-Haven't used my EA account since last time I played Mass Effect 2

-If your password, to your knowledge, was a unique one between your EA and MS account.
-I believe it was similar.

-How old your Gamertag/Live account is, and
-Since 2005

-Your compensation, and whether it's been resolved or not.
-Nothing so far.
 
chubigans said:
Alright, since gaming sites seem to not give a crap about the recent, what seems to be increase of Xbox Live hacks, I thought we'd set up a more organized official topic and compare notes to see if we can get any closer to how/why this is happening.

If your Xbox Live account has been hacked, please post the following info:

-The date it occurred
-Your "damages" (points spent, games played you don't own, etc.)
-Your current situation with MS (if your account is suspended, under investigation, etc.)
-If you have an EA account of any kind, or have played any EA games in the past few months
-If your password, to your knowledge, was a unique one between your EA and MS account.
-How old your Gamertag/Live account is, and
-Your compensation, and whether it's been resolved or not.

GAF has solved major issues before. Maybe we can get to the bottom of this too!

- 10/29/2011
- 6,360 points spent, FIFA 12 shows up but I don't own it
- Haven't contacted MS yet due to the points not being charged to my card but were existing points I had redeemed over time
- I do have an EA account and I believe the last EA game played was NHL 12
- Don't recall if the passwords were the same or not. I don't believe so though
- Live account has existed since the original beta on the Xbox; I have a 9 next to my gamertag
- Nothing yet because I'm not sure I'm going to report it yet over points hat didn't cost me anything. Not sure it's worth 5 weeks of my 360 becoming a brick since it's the holidays.
 
Garcia el Gringo said:
I assume unique/complicated passwords for every account (especially for your Windows Live ID and your EA accounts) and to check your computer for keyloggers.

HOW DO YOU CHECK FOR KEYLOGGERS!

No my caps isn't broken, I'm yelling because I don't know how.
 

Sanchito

Member
-Occurred on August 13th
-Jerks used my Paypal account to buy 4000 MS points
-Account was suspended and is STILL under investigation.
-I have an EA account. Have it for Dragon Age, Mass Effect 2.
-I am pretty sure that my passwords were different. (Between EA and my live account).
-I've had a live account since Jan 2006.
-I've called numerous times.. had my account flagged several times to get "looked at sooner". I finally made a complaint to the BBB over a week ago. I got an email from customer service, and yesterday I wrote them asking what the hold up was. I got a call back from some lady while I was at work. I called her back and she said she was busy with someone else, that she would call me back later. She never called me back.

This is getting so aggravating.
 

Pumpkins

Member
-The date it occurred
October 26th

-Your "damages" (points spent, games played you don't own, etc.)
Hacker bought RIFT and spent up the majority of my remaining points on the account. Thankfully my credit card on file is a gift card with $1 dollar on it (lol). As for the points, I'm not very torn because I got them for free. My main concern was the fact that someone got into my account.

-Your current situation with MS (if your account is suspended, under investigation, etc.)
I called them and the lady said my account was in lock down and that I would get my points back. My account never went into lock down and I'm still able to play on XBL. I'm not going to bother calling them again because like I said, the points I had were ones I got for free.

-If you have an EA account of any kind, or have played any EA games in the past few months
Yes. ME2 and BC2.

-If your password, to your knowledge, was a unique one between your EA and MS account.
They were the same, but I changed them since this whole thing.

-How old your Gamertag/Live account is, and
I think I have a 3 next to my gamertag.

-Your compensation, and whether it's been resolved or not.
Hasn't been resolved. I think the lady I called made some mistake with filing my issue, but I'm just going to leave it alone. I changed my information and I'm hoping this won't happen again. I'm also NEVER going to put a credit card on my account with Xbox.
 
There really seems to be a common trend here of EA account and Live and many with same emai and/or password. I am surprise this thread haven't gone into several more pages since many seems to think this is really wide spread issue.

Anyway, Microsoft really need to step up and add another layer of authentication for purchasing.
 
ElFly said:
What's the idea behind buying so many FIFA packs? Do they resell them or what?

Yes you can sell them on eBay and in essence convert those Microsoft points into cash. I don't even want to think how bad account hacking will be with Diablo III allowing you to selll stuff for real cash. I haven't play WoW in 6-7 months and log in last month to play Starcraft and noticed my WoW account was locked. I called and they told me that my WoW account was hacked and they noticed it and froze the account. I have since got authenticator for it.
 

graywolf323

Member
I was hacked but oddly no FIFA

all the hacker did was add 400 points and then later bought The Sims 3: Late Night of all games

Microsoft has been slow as hell at fixing it though :| I want my 2870 points back

-October 10th, 2011
-400 points bought and then they used all my points to get The Sims 3: Late Night
-under investigation (still >_<)
-yes played Madden on 360 recently
-different passwords
-had a gamertag since Xbox Live first existed and an EA account even longer than that
-not resolved yet
 
strem said:
12,000 points. Under suspension now. PS3 I now love you
Wow. 6,000 prepaid points. Suspension. Uncharted 3 has really helped me through this. Skyward Sword is next.

I game on all the platforms. 360 is my platform of choice. Honestly, I don't even know now...
 

eastmen

Banned
Speedymanic said:
This site seems to agree that it's a strong password,

http://howsecureismypassword.net/

I think the main thing to take away from these sites is that they aren't really reliable. Trust your own judgement.


This site tells me that password I had used when I was hacked would take about a Billion years to hack.

The new one is about 435 trillion years
 
-The date it occurred - Early August



-Your "damages" (points spent, games played you don't own, etc.) - 9200 points, FIFA 09 (really)



-Your current situation with MS (if your account is suspended, under investigation, etc.)
- Other than despising them as a company, we're cool (and resolved)



-If you have an EA account of any kind, or have played any EA games in the past few months


Yes and yes. I play all EA sports games and most of their major releases.



-If your password, to your knowledge, was a unique one between your EA and MS account.


I don't remember, it's possible they were the same at that point.



-How old your Gamertag/Live account is, and

Xbox 1 beta for XBL




-Your compensation, and whether it's been resolved or not.


2 free months of live and I got my points back. Took 6 weeks. Couldn't take my account online that whole time.
 
antiquegamer said:
There really seems to be a common trend here of EA account and Live and many with same emai and/or password. I am surprise this thread haven't gone into several more pages since many seems to think this is really wide spread issue.

Anyway, Microsoft really need to step up and add another layer of authentication for purchasing.

Yep. I'm still waiting/hoping for an answer about how those who had unique passwords changed them as I don't recall there ever being an option to choose a unique password to access EA's servers when first booting up Burnout Paradise, ME2, etc.

Was a simple procedure of pressing 'A' a couple of times and it was done, but it's been while since I last had to do it, so maybe I'm wrong/not remembering all the steps.
 
-Late September

-No damages, they did it at 3 am but they didn't know I work from 9pm to 8am so I was up when they changed my password.

-Account is fine.

-I have a EA account and the password was the same.

-Been on live since day 1 on Xbox.
 

bs000

Member
Speedymanic said:
A question to those saying they had unique EA passwords. How did you enter your own password? From what I can recall (it's been a long while so I might be wrong/mistaken), it was done automatically. I don't remember there even being an option to enter my own password when I played BC2 or ME2 for the first time.

Do you have to do it via the website?

I think you only have to enter your account information for the very first EA game you ever played on your gamertag. After that it's linked and you get logged in automatically for every EA game you play after that.
 

manzo

Member
Jeesus christ at this thread.

I just emailed Microsoft to have my CC info removed from my account.
 
manzo said:
Jeesus christ at this thread.

I just emailed Microsoft to have my CC info removed from my account.

Call them. Don't leave something like that to email correspondence.

bs000 said:
I think you only have to enter your account information for the very first EA game you ever played on your gamertag. After that it's linked and you get logged in automatically for every EA game you play after that.

That's what I thought, but I don't remember it ever asking me to enter my details when I booted up Burnout Paradise. (which was my first online EA game this gen)

But it was years ago, so maybe my memory just sucks.
 

chixdiggit

Member
-The date it occurred 11-6-11
-Your "damages" 10,000 points charged to my credit card
-Your current situation with MS account suspended
-If you have an EA account of any kind, Yes
-If your password, to your knowledge, was a unique one between your EA and MS account.Probably same
-How old your Gamertag/Live account is, 8 years
-Your compensation, and whether it's been resolved or not. They said it could take up to 25 days
 
- 21st October 2011
- ~2000 points spent on FIFA packs (no card on account), FIFA 11 played (2 achievements)
- Account under investigation
- Hacker set up a new EA account (which I cancelled when I read the mail)
- Yup, unique password
- ~ 4 years
- Not yet resolved
 

drizzle

Axel Hertz
If your Xbox Live account has been hacked, please post the following info:

-The date it occurred
4th of July

-Your "damages" (points spent, games played you don't own, etc.)
6000 + 4000 mspoints purchase on Credit Card that was attached to the account. Also, I had 5000 points I already had on account used. Fifa 12 was played on my account and all the points were used to buy multiple copies of the FIFA "PREMIUM BUNDLE JUMBO"

-Your current situation with MS (if your account is suspended, under investigation, etc.)
Account was fully returned to me on July 19th. In other words, 15 days after.

-If you have an EA account of any kind, or have played any EA games in the past few months
Yes, I have an active EA account. I'm stupid and had the same password for both EA and Live. I also had the same password PSN before the PSN hack. Yes, both accounts are linked up. I use my EA account constantly, as I'm a very avid Battlefield Player. I quickly changed passwords.

-If your password, to your knowledge, was a unique one between your EA and MS account.
No it wasn't. I had the same password on EA, PSN and Live. Yes, it's stupid. Yes, I am aware of that. No, it's no longer like that.

-How old your Gamertag/Live account is, and
5 years

-Your compensation, and whether it's been resolved or not.
It's been resolved and i've been given like 500 extra MSpoints because there was a mistunderstanding of how many points I had in the acount prior to the "attack". I'm pretty sure I wouldn't have gotten any kind of compensation if there wasn't the points misunderstanding.


I don't think this has any connection between EA and Microsoft other than the fact that EA has a system in which is very easy to exchange Microsoft Points for actual currency.


EDIT:

If you have been hacked, can you please check with MS to see if your secret question has similarly been changed to a foreign language as well?
My secret question was not changed, but that's because I was super quick to figure it out. The moment my account got hacked and points purchased on my Credit Card, my bank sent me a SMS message saying that a purchase was made on my CC (which I only used on Microsoft).

I quickly logged into the account and changed passwords. I though I was being safe, because The dude didn't even start spending the points.

After a little while, I double checked and the points started to go away. He managed to log into profile with an XBox (which meant I couldn't log into the gamertag with mine, unless I retrieved it). I chose not to, because I would lose the MS points already spent.

That's when I called Microsoft and started the "oh shit my account was stolen" deal.
 
It's not stupid, many people (including myself) used the same password across both services. Who wouldn't when they assume both services will be very secure and won't end up being breached.

I've since changed my XBL password numerous times, so I'm not really at risk (I hope), but don't blame yourself or think it was stupid to use the same password for both services.
 

chubigans

y'all should be ashamed
OP updated with a request if you hacked folks talk with MS again. I think that's the most interesting bit of new news we have on all this so far.
 

Sean

Banned
chubigans said:
EDIT: the stats so far out of the 30 cases posted in this thread (as of post #95):

It seems a majority/almost all cases had EA accounts, however there's no indication of being "hacked" via having the same passwords between EA/MS accounts, since many had different passwords.

I'm not sure what exactly having an EA account proves. They are the largest video game publisher and put out like three dozen games each year in all different genres (sports, racing, music, shooters, etc). Probably 100% of Xbox Live users have played an EA game online at some point in the last nine years. I bet if you ask everyone in this thread if they've played Call of Duty they'd all have that in common too. Just saying..

The "secret question" answer being reset is a more interesting lead to follow up on. This seems like phishing/social engineering rather than some kind of hack. Anyway, hope everyone here gets their account issues resolved ASAP.
 
edit - wait a fucking second - i think my account security question WAS changed! if anyone can confirm that "what is my pets name?" or something along those lines was one of the questions you can pick, then please let me know! if it was, then it was definitely changed...it sort of makes sense considering after telling both microsoft reps around 4-5 "favorite fictional characters", they werent the right ones! interesting!

-10/26/2011.

-they changed my windows live id and password (every time i try to log in to xbox.com, it tells me "That Windows Live ID doesn't exist. Enter a different ID or get a new one."). if i go onto xbox.com and view my profile, it shows that fifa 12 was played, next to marvel vs capcom 3 and perfect dark. i dont even own fifa 12, let alone even played it before. not too worried about CCs and stuff, as i always used prepaid xbox live and point cards. however, i had around 1400-1500ish points remaining on my account and im not sure if they are gone (cant even check online) - im willing to bet they are.

-called microsoft in the previous xbox live hacked thread, and unbelievably, they said they didnt seem to find anything suspicious on the account, but they went ahead and opened up an investigation, got it "escalated", and was quoted 3-4 weeks/25 days. that was all on 10/26/2011. called yesterday for a status update, and of course its still under investigation. weirdly, they asked me "who my favorite fictional character on the account" was, but i had no idea. of course, i cant even change it because my windows live id isnt recognized anymore.

-have an EA account from need for speed: hot pursuit. havent touched it since late last year/early this year. have not put in a single EA game since. hmm, reading other peoples replies, i just now changed my EA account password, and the only games that showed up were nfs:hp and madden 2011 - my friends must have downloaded the demo and tried it, but i deleted it promptly. that was last year though, before i even got nfs:hp.

-not sure. i tried logging into my EA one with my usual passwords and none of them worked. i literally just changed my EA account password, so now they are totally different. again, it doesnt help that microsoft doesnt even recognize my windows live id anymore, so i cant even reset my password, let alone log in.

-gamertag is just about to be 3 years old. i bought my xbox 360 during black friday 2008.

-definitely NOT been resolved, and have gotten absolutely no compensation at all.
 
Top Bottom