• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Grrrr! Someone stole my XBL gamertag

element

Member
Got home from work checking my email and my phone rings with a private number, which is odd. Some guy on the phone says he just bought my XBL gamertag and wanted to make sure it was ok.

He then goes on to be sad that I never sold it or had any intentions to sell it. How he spent $300 on it and how I'm a dick if I recover it. Tries to tell me he just wants the gamertag because it is 'awesome' and he was nice enough to create a new account for me. He says he wants to play some games with it, because the name is cool, and he just bought a gears of war xbox and was going to go play. I tell him it is against ToS to buy gamer tags and that his console will be banned. He asks how I know this, and I tell him I worked on Xbox (which is true), I was in the revolt beta. At that point I get an email that someone has bought 400 points and the guy hangs up.

This is where the guy is stupid. I get into my windows live id profile and there is an additional email associated to my Windows Live ID. So I copy that down, remove it, and change my password.

I sent a tweet about getting hacked, and it helps that thevowel (Director of Architecture, Xbox LIVE Operations) follows me, who had me email him with my data to pass it on to the security team.

In the meantime I called support who locked my account so they couldn't buy anything. I was told it would take three to five days to investigate and resolve.

Support was very helpful, but so frustrating. This is the 2nd time in six months that my account has been compromised. I wish Microsoft had additional confirmations when details on your account is changed. Google and Facebook do a good job, if you change major details it needs an additional contact form, typically a text message with an alpha number code.

Hopefully it all gets resolved. So pissed.
 

sixghost

Member
element said:
Got home from work checking my email and my phone rings with a private number, which is odd. Some guy on the phone says he just bought my XBL gamertag and wanted to make sure it was ok.

He then goes on to be sad that I never sold it or had any intentions to sell it. How he spent $300 on it and how I'm a dick if I recover it. Tries to tell me he just wants the gamertag because it is 'awesome' and he was nice enough to create a new account for me. He says he wants to play some games with it, because the name is cool, and he just bought a gears of war xbox and was going to go play. I tell him it is against ToS to buy gamer tags and that his console will be banned. He asks how I know this, and I tell him I worked on Xbox (which is true), I was in the revolt beta. At that point I get an email that someone has bought 400 points and the guy hangs up.

This is where the guy is stupid. I get into my windows live id profile and there is an additional email associated to my Windows Live ID. So I copy that down, remove it, and change my password.

I sent a tweet about getting hacked, and it helps that thevowel (Director of Architecture, Xbox LIVE Operations) follows me, who had me email him with my data to pass it on to the security team.

In the meantime I called support who locked my account so they couldn't buy anything. I was told it would take three to five days to investigate and resolve.

Support was very helpful, but so frustrating. This is the 2nd time in six months that my account has been compromised. I wish Microsoft had additional confirmations when details on your account is changed. Google and Facebook do a good job, if you change major details it needs an additional contact form, typically a text message with an alpha number code.

Hopefully it all gets resolved. So pissed.
This happened to me a month or two ago. Whoever did it spent like $60 on MS points, and the charges still haven't been reversed. The fact that the guy called you is just fucking odd.
 
0_o how did he get your number, jeez i'd be creeped out.

no one else uses a alt email and random phone number when signing up for xbox live?
 
element said:
He then goes on to be sad that I never sold it or had any intentions to sell it. How he spent $300 on it and how I'm a dick if I recover it. Tries to tell me he just wants the gamertag because it is 'awesome' and he was nice enough to create a new account for me. He says he wants to play some games with it, because the name is cool, and he just bought a gears of war xbox and was going to go play. I tell him it is against ToS to buy gamer tags and that his console will be banned. He asks how I know this, and I tell him I worked on Xbox (which is true), I was in the revolt beta. At that point I get an email that someone has bought 400 points and the guy hangs up.


http://www.neogaf.com/forum/showthread.php?t=446047 hmmmm. he bought your tag and got more points after i bet.
 
ArachosiA 78 said:
people pay money for gamertags? $300?? What was your gamertag? How could any name possibly be worth $300?!?

.


I want to know what name this was that someone thought it was worth $300. And where the hell he bought it from (I guess he paid someone to hack your account?)

And then he had the balls to straight up call you? Seriously? So weird.
 
Yeah, there's a six page account hack thread. I was hacked as well, but nobody called me. Also waiting for my stuff to be reversed. There seems to really be something going on here.
 

fernoca

Member
CarbonatedFalcon said:
.


I want to know what name this was that someone thought it was worth $300. And where the hell he bought it from (I guess he paid someone to hack your account?)
For all we know, the person could've been lying. I mean, how the fuck does one person buys an account, then proceed to calls the other person to make sure it's okay?

Is like I buy a stolen TV that someone got from Wal-Mart and proceed to call Wal-Mart to ask if it's okay that I return it if I have any problems... :p
 

daegan

Member
I just got gold again and finally picked up my first 360 of my own and while I have hardly any points and a crappy name, this still freaks me out.
 

Respawn

Banned
fernoca said:
For all we know, the person could've been lying. I mean, how the fuck does one person buys an account, then proceed to calls the other person to make sure it's okay?

Is like I buy a stolen TV that someone got from Wal-Mart and proceed to call Wal-Mart to ask if it's okay that I return it if I have any problems... :p
His account is locked. So how did the dude get the number? At the same time 400points were spent and the dude hung up.
I think some inside shit is going on at Microsoft
 

heavyness

Member
kamspy said:
So what's going on with XBL?

Nothing is going on with XBL. These people hack your email so they can send and read the "I forgot my password, I need to reset it" email and then change your gamertag to something else. They then take your old gamertag. They're not hacking XBL. They could do the same with ANY account you have (Facebook, Amazon, Best Buy...)

I suggest everyone use gmail and turn on the 2-Step Authorization (link). This way, when someone tried to get into your gmail, it will text you on your cel phone with a 6 digital number you have to enter before it lets someone change your password or log in on a new computer.

I know other email services have this, but not sure which ones.
 

Drkirby

Corporate Apologist
For a second, I was expecting some comedy where some guy actually managed to change your Gamer tag, then take the original for him self.

Edit: Wait, no, it more or less is. lol.
 

Freshmaker

I am Korean.
Digishine said:
How The Fuck can they do that !?

Xbox live isn't secure ???
Not really. The fact it's tied to stuff like your hotmail account etc opens you up to potential exploits.
 

element

Member
Seriously, he called you?
Yeah. I'm pretty sure he was updating information in my Windows Live ID account and saw the number and decided to call. Who knows.

Similar thing happened last time, where the person called me acting as Microsoft Support. I was a contractor at MS at the time, and I asked for his alias, and he didn't know what that was. If you don't know your alias as a higher tier support, there is something seriously fishy. He also wouldn't tell me his location, another red flag.

Any ideas on how it has been so easy for them?
My password was pretty complicated. Alpha number extended mixed 16 character password. No idea how they got in.

Who did he buy it from?
no idea, but those people hacking and selling need a swift kick in the junk.
 

fernoca

Member
Respawn said:
His account is locked. So how did the dude get the number? At the same time 400points were spent and the dude hung up.
I think some inside shit is going on at Microsoft
The account was locked, after 'element' stopped talking to him on the phone. The call, the "$300 purchase", the 400 MS Points were all done before the lock.

Which is why it wouldn't surprise me if said guy, didn't paid $300 and got the account from a friend or something, felt "bad"; got the number from the account info/settings and called to see if anyone answered.

If true that he paid $300; the guy sounds too dumb anyway by just calling 'element'. :p

Or he just made everything up, called 'element', made a "sad story" about spending $300; thinking things wouldn't matter since "he got hacked!"...at least 'element' dealt with everything nicely; so the guy sucks anyway. :p
 

Emitan

Member
It's like calling someone after paying someone to break into their car so you can ask them if it's okay. Why would you think this is okay?
 

Respawn

Banned
heavyness said:
Nothing is going on with XBL. These people hack your email so they can send and read the "I forgot my password, I need to reset it" email and then change your gamertag to something else. They then take your old gamertag. They're not hacking XBL. They could do the same with ANY account you have (Facebook, Amazon, Best Buy...)

I suggest everyone use gmail and turn on the 2-Step Authorization (link). This way, when someone tried to get into your gmail, it will text you on your cel phone with a 6 digital number you have to enter before it lets someone change your password or log in on a new computer.

I know other email services have this, but not sure which ones.
That's tied to xbox live and money is being spent. So live is getting hacked.
 

Atomski

Member
I'm sure he thought he made the transaction with the original owner.


Anyways this is really starting to sound a lot like World of Warcraft. People getting their passwords keylogged and sold off some chinese websites.
 

Derrick01

Banned
This seems to be getting worse and worse and so far there's been nothing but silence on MS front. There's obviously something going on on their end, it's hard to believe everyone is getting hit with a phishing attack or using the same password as other potential hacked sites.
 

epmode

Member
Respawn said:
That's tied to xbox live and money is being spent. So live is getting hacked.
If Live was legitimately hacked and the passwords were compromised, we would almost certainly have known about it by now.

This still sounds like widespread social engineering to me. Microsoft really needs to change their Live security policy. Maybe some kind of optional 2-step verification or something like Steam Guard.

edit: Even so, I'm glad that I already removed my credit card from my account.
 
That's scary as fuck. If someone bought my account for $300 they'd be winning. My live catalog is at least $1000+ deep. I miss frivolous spending.

Raise hell OP!! Bastard had the nerve to call you??
 

Atomski

Member
DR3AM said:
why arent gaming websites reporting this?

Because the problem is most likely not xbox live, its users not being secure on pc. If your email is hacked they can get access to anything related to that email.. such as your xbox live account.
 

fernoca

Member
Derrick01 said:
This seems to be getting worse and worse and so far there's been nothing but silence on MS front. There's obviously something going on on their end, it's hard to believe everyone is getting hit with a phishing attack or using the same password as other potential hacked sites.
The thing is that, as even other "detective GAF" threads has shown; it is quite easy and not an actual hack.

In many cases, just with the person's Xbox Live Gamertag; you can find his/her Facebook. That leads to personal info, address, emails. Or with their Twitter.

People tend to put many personal info out there; and while some focus on what they have on their Facebook accounts and making it private, they sometimes forget that they have other accounts in other websites.
 

DigiMish

Member
Yea, it's weird that the dude would call you. Maybe THAT was the scam all along. INCEPTION.

Should have asked him where he bought your gamertag.
 

fernoca

Member
Exuro said:
Don't XBL account require a live email account?
Live ID = any email, that you confirmed with Microsoft Live. For example, the account I created for GAF-Mortal Kombat; is tied to a Gmail-email.
 
Top Bottom