Hacked! Ban log ins from S h i zuishan CN!

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: diabluz.2860

diabluz.2860

Ok, this is getting ridiculous. Hackers have attempted to gain access to my account twice now in the past 2 months. Both log in attempts were from S h i z u i s h a n China.

Both times I received an email from ArenaNet asking me to approve or deny the log in attempt. They should know at this point that any log in attempt from that area or IP address are hacking attempts.

Anyone else had log in attempts from this same city/area? Following is the origination information for the attempt.

Address: 222.75.193.118
City: S h i z u i s h a n
Region: 21
Country: CN

P.S. Yes, I did change my password both times after the attempts.

(edited by diabluz.2860)

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Iruwen.3164

Iruwen.3164

Good ANet thinks for you eh? Try changing your password to something secure and maybe add real two-factor authentication if you have a smartphone.

Iruwen Evillan, Human Mesmer on Drakkar Lake

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: TwoBit.5903

TwoBit.5903

You’ll likely need to change your email as well as your password.

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Qnopsik El Qox.1269

Qnopsik El Qox.1269

Both times I received an email from ArenaNet asking me to approve or deny the log in attempt. They should know at this point that any log in attempt from that area or IP address are hacking attempts.

What about players from China?
Are they supposed to be autobanned each time they change IP?

Rozalinda El Qox 80lvl Elem
Tiny Siege Turtles member
Blacktide player

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Midnight Gypsy.9360

Midnight Gypsy.9360

They might have something on you’re PC giving them your password, like a key logger. If you’re changing it and they still have it with in a month or two it won’t matter if you change it. You need to find what they have on you’re PC and clean it out.

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: diabluz.2860

diabluz.2860

They might have something on you’re PC giving them your password, like a key logger. If you’re changing it and they still have it with in a month or two it won’t matter if you change it. You need to find what they have on you’re PC and clean it out.

Thanks for the suggestion/advice but I know that that’s not how they’re accessing my passwords. I use a Mac for one which makes me less susceptible to key loggers etc and also I have a new hard drive and fresh install of OSX since the first hack.

Somehow these hackers are gaining access to ArenaNets servers. Something needs to be done.

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: diabluz.2860

diabluz.2860

Both times I received an email from ArenaNet asking me to approve or deny the log in attempt. They should know at this point that any log in attempt from that area or IP address are hacking attempts.

What about players from China?
Are they supposed to be autobanned each time they change IP?

Why would players from China be playing on US servers for one thing and secondly these hack attempts seem to be coming from the exact same city and region. It’s pretty obvious that they’re hackers.

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Koyannis.6943

Koyannis.6943

Today I got an email with a login attempt from China as well:

Address: 183.154.167.109
City: Jinhua
Region: 02
Country: CN

This is the first time this has ever happened to me as well. I don’t even use the PC for anything but gaming (My games are all from Steam except for GW2, DDO and LOTRO, I do my web browsing /email/socail networking on my tablet). I’m not sure how they attempted to login but they did not get access.

I have two step verification on my email so they were not able to approve the IP address. I logged in to my account, changed the password and just for an extra step, added the two step authentication to my GW2 account. Now I have a question.

My account shows it has a mobile authenticator linked to it, but I can login to my account on the website and can login to the game without having to enter the authenticator code. When I used the Blizzard authenticator, it required me to enter the time sensitive passcode every time I fired up the game or tried to login on the website. This is apparently not the case here. Is there a way I can require the use of mobile authentication every single time I login to the website or to the game?

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: hoegarden.4287

hoegarden.4287

Both times I received an email from ArenaNet asking me to approve or deny the log in attempt. They should know at this point that any log in attempt from that area or IP address are hacking attempts.

As long as you deny (and I hope you did) they can’t get on your account. So go change your password.
And it’s great to make an app, but how can players like me who don’t have a freaking smartphone can use any of their fancy stuff ?

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Koyannis.6943

Koyannis.6943

Both times I received an email from ArenaNet asking me to approve or deny the log in attempt. They should know at this point that any log in attempt from that area or IP address are hacking attempts.

As long as you deny (and I hope you did) they can’t get on your account. So go change your password.
And it’s great to make an app, but how can players like me who don’t have a freaking smartphone can use any of their fancy stuff ?

I know another MMO will allow you to buy a physical authenticator that you can link to your account for two step security. It’s under $10 if I recall right. Perhaps ANet will one day support an option like this. Another suggestion is to buy a used Ipod Touch (a quick google search shows them as low as $88, might even find them for less on ebay or Craigslist). You can download the Google Authenticator to that device without needing a smartphone.

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Gaile Gray

Gaile Gray

ArenaNet Communications Manager

Next

[quote=1585190;diabluz.2860:]

Gaile Gray
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Gaile Gray

Previous

Gaile Gray

ArenaNet Communications Manager

Next

Somehow these hackers are gaining access to ArenaNets servers. Something needs to be done.

No, that is absolutely not the case. This is an individual security issue related to you: your email account, your game account, or both. But this is not an issue with Guild Wars 2 as a whole.

If you want help,
contact Support by filing a ticket through the “Ask a Question” tab on that linked page. They will be able to assist you. For tips on what information to provide in a ticket, please read this post and provide as much as possible to expedite the ticket.

Gaile Gray
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Iruwen.3164

Iruwen.3164

My account shows it has a mobile authenticator linked to it, but I can login to my account on the website and can login to the game without having to enter the authenticator code. When I used the Blizzard authenticator, it required me to enter the time sensitive passcode every time I fired up the game or tried to login on the website. This is apparently not the case here. Is there a way I can require the use of mobile authentication every single time I login to the website or to the game?

It remembers the subnet you were in the last time you logged in, you won’t be asked for a code if it didn’t change. That’s a rudimentary protection against foreign hackers at least which is better than nothing. Should only happen if you enable it though, you just cannot edit the table of allowed subnets later.

And it’s great to make an app, but how can players like me who don’t have a freaking smartphone can use any of their fancy stuff ?

You can also use a cheap Yubikey, it requires an additional piece of software though since it lacks an internal clock. We discussed that here.

Iruwen Evillan, Human Mesmer on Drakkar Lake

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Gaile Gray

Previous

Gaile Gray

ArenaNet Communications Manager

We’ve said in the past that any configurable RFC 6238 device (physical authenticator, “dongle”) should be compatible. That is another option.

And there is the email auth. For questions about E-mail Authentication, see this post.

Gaile Gray
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet

(edited by Gaile Gray.6029)

Hacked! Ban log ins from S h i zuishan CN!

in Account & Technical Support

Posted by: Frotee.2634

Frotee.2634

As a side note, you may really not want ArenaNet (or GW2 for that matter) to automatically block access from (certain) foreign countries without a way to ‘unlock’ them again. What if you ever travel there and want to have a short gaming session on your laptop?

I was just on vacation in Italy and wanted to update my faculty’s website concerning some timetable information (I should not work during vacations, but it would have beekittenMinute task…) – however, it was impossible to load the login-page from there. Even playing around with proxies didn’t really help (and it wasn’t so important that I wanted to waste hours on it).

Also, I’m pretty sure Chinese players would have to play on US servers, seeing as we only have a choice between European and US servers

Polka will never die