15 years, never been hacked, until...

15 years, never been hacked, until...

in Account & Technical Support

Posted by: Bolthar.4172

Bolthar.4172

I have to say I think this is insane. I have been playing MMOs for the last 15 years. I use strong passwords and I do not use the same userids and passwords on all mmorpgs. I never share account information and I always pretty much stay as a loaner in games.

Along comes GW2. I play it, I get a character to level 80 and then I make about 3 others to kind of test the waters of all the different “flavors” that are out there. I then participate in the Halloween festivities and once the big Halloween event on the 31rst is over with I do not log in at all. In fact I have been so busy home life wise I have not had a chance to do much of anything.

This last weekend (11/18) I go to log in and I can not get in. It indicates my account information is not valid. I go through all my anet e-mails ,the purchase ones, the account creation ones, and finally I look at the new stuff. There I notice that someone had attempted to change the e-mails address on the account. I promptly contacted Anet support.

This is where the waiting began. I had a small glimmer off hope when Anet sent me an e-mail saying my account had been restored and that I had a new password. I logged in and this is when my heart dropped.

1) All my new flavors of characters are now gone.
2) All my items I saved up karma to buy are now gone.
3) All my items had been put up on the Black Lion market and converted to gold.
4) All gold was stripped off my character.
5) They even went as far as stripping off my bags and deleting things that would not make them any money.

I was also restored in the middle of Frostgorge Sound (which I had not visited since I was in my 70’s) where since I had no gear I immediately died and don’t even have enough money to even resurrect as I have a total of 86 copper to my character.

Does Anet really consider this customer support? Sure you restored my account to an “active” state. To say this is all that is to be done with the account for someone who has supplied money for this account is really shoddy. I still have not had any answer to the question if player X is last logged on Monday, and then someone takes the that account on Tuesday, on Wednesday when the account is recovered why can’t they recover from Mondays last logon?

Anet this will be my last contact I am sure but you may have restored an account but you lost yourself any hope of having me as a future customer. Also be aware if your strong password users are not sharing their passwords/accounts and their still getting hacked you have serious internal account issues.

15 years, never been hacked, until...

in Account & Technical Support

Posted by: marnick.4305

marnick.4305

Anet this will be my last contact I am sure but you may have restored an account but you lost yourself any hope of having me as a future customer. Also be aware if your strong password users are not sharing their passwords/accounts and their still getting hacked you have serious internal account issues.

That, or you have a serious account issue yourself somewhere. Seems far more likely to me. Do you have 2-factor authentication? Is your password unique? Is it different from your email password? Is your email separately secured? Do you have any keyloggers?

In this time and age security isn’t a given anymore. It took me the better part of an afternoon to set up vastly increased security everywhere. If you don’t have my phone, you’re not getting into any of my accounts anymore.

If I can’t play Guild Wars 2 at work, I won’t work in Guild Wars 2 either.
Delayed content is eventually good. Rushed content is eternally bad. ~ Shigeru Miyamoto

15 years, never been hacked, until...

in Account & Technical Support

Posted by: Torgrim.3642

Torgrim.3642

Same thing happend to me 5 days ago, I haven’t been hacked ever since I started playing MMO with UO.
Only thing that was missing was my gold and my stuff I had in the bags and some things in my banks but the toon itself was intact so was all my mats, so I guess It just gotten hacked when I logged in.
So now I’m in the process to change email to yet another newly created one.
I suspect there is a new email hack out now which is much easier to hack emails even if It’s newly created since we have email as login and not a chosen login name which I prefer.

15 years, never been hacked, until...

in Account & Technical Support

Posted by: Bolthar.4172

Bolthar.4172

Anet this will be my last contact I am sure but you may have restored an account but you lost yourself any hope of having me as a future customer. Also be aware if your strong password users are not sharing their passwords/accounts and their still getting hacked you have serious internal account issues.

That, or you have a serious account issue yourself somewhere. Seems far more likely to me. Do you have 2-factor authentication? Is your password unique? Is it different from your email password? Is your email separately secured? Do you have any keyloggers?

In this time and age security isn’t a given anymore. It took me the better part of an afternoon to set up vastly increased security everywhere. If you don’t have my phone, you’re not getting into any of my accounts anymore.

Sounds a bit nieve for you to just be out there attacking those who have had things happen. 1) I can’t two factor because I don’t have a phone (not everyone is in the same boat as you and priviledged enough to have one) 2) I don’t have any keyloggers and the password is infact very unique. Even unique enough that others in my own family don’t even know it. 3) My e-mail is 100% secured and I log into each time and the passwords do get changed. 4) I scan weekly this means for the 3 weeks I didn’t play its would have found it 3 times but it has found nothing wrong at all.

The bottom line is I take “reasonable” care of my account and its information. I have for 15+ years. This “suspect” e-mail account I have had even longer than this and noone has had any access to it yet someone is able to get into my account remove everything to the point where a user is unuseable and the only thing Anet will do is change a couple of characters on the acount to get the login back to you.

1) No restores done.
2) No account security for changes once your in it.
3) No customer service for support.

Here is a hint Anet – have security questions and make it that people have to input them to make changes so anyone that does any kinds of attempts has to know more than just a password.

Like I said I am not coming back to anet as this is the first time this has happened and to be honest anything short of a full restore to the condition I logged off would not bring me back. I am sure it will be my last as long as I reasearch which games I play and don’t just jump on a day 1 purchase like I instintively tried to do here and I play games I know at least have the account security levels I require to play.

I hope the other poster gets their accounts looked at. Anet you need to look at customer service and determine exacly where your willing to let future sales affect current state.

Anet has stated over and over gaain this game was not about a gear grind if that is the case then there should be no problems at all restoring those “non grinded” items to a hacked account. Whats really sad is anet lost this a dedicated player who had a whoping 6-8 gold in his account. Even restoring the gold itself would not kill the economy.

Okay now that I have just checked back here I wish you all well on your future endevors.

15 years, never been hacked, until...

in Account & Technical Support

Posted by: ShiningSquirrel.3751

ShiningSquirrel.3751

Anet this will be my last contact I am sure but you may have restored an account but you lost yourself any hope of having me as a future customer. Also be aware if your strong password users are not sharing their passwords/accounts and their still getting hacked you have serious internal account issues.

That, or you have a serious account issue yourself somewhere. Seems far more likely to me. Do you have 2-factor authentication? Is your password unique? Is it different from your email password? Is your email separately secured? Do you have any keyloggers?

In this time and age security isn’t a given anymore. It took me the better part of an afternoon to set up vastly increased security everywhere. If you don’t have my phone, you’re not getting into any of my accounts anymore.

Don’t be so quick to blame the op.
In the first 2 weeks, I had people from outside the country trying to access my account.
Since I got the email to allow the connection or deny, it means thay already had my password. I do computer security for a living. I am the one who makes sure passwords are secure and the one who keeps viruses off of our workstations. I am very good at my job, used a very secure password, brand new clean machine that I had built just for gaming, and yet they still had my password? Somehow, somewhere, there was a security breach and passwords where compromised. Not blaming anyone, but somehow the hackers/gold sellers where able to get passwords to accounts, either from the game servers or the forums right here.

15 years, never been hacked, until...

in Account & Technical Support

Posted by: Maetel.2130

Maetel.2130

Theyjust hacked me…
Dunno how to block account

You guys have serious security issues, now I’ll lose everything and you can forget my money in the future

(edited by Maetel.2130)

15 years, never been hacked, until...

in Account & Technical Support

Posted by: Gaile Gray

Gaile Gray

ArenaNet Communications Manager

Somehow, somewhere, there was a security breach and passwords where compromised. Not blaming anyone, but somehow the hackers/gold sellers where able to get passwords to accounts, either from the game servers or the forums right here.

No. That is not the case.

Stop and think: If there were a breach of ArenaNet security, we’d have thousands, tens of thousands, even hundreds of thousands of posts, tickets, emails, smoke signals, and carrier pigeons letting us know there was an issue. Instead, we see the number you might expect when people (1) use insecure passwords, (2) share their accounts, (3) reuse a password across more than one account, (4) host a keylogger or other back-end system, (5) [insert other reason].

While judging “Is there an issue?” solely by volume isn’t a 100% assurance that there is no issue, coupled with the monitoring systems in place it’s a pretty solid indicator that these are individual breaches, not a systemic issue.

I sympathize about this situation. I also understand that it’s hard to track everything that an individual may have done that lead to the compromise on one’s account. But it’s incorrect to point in our direction.

I trust you’ll understand I’m not “speaking the company line” but am answering as truthfully and transparently as possible, just as I believe we will remain on all things related to security.

Gaile Gray
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet