Jump to content

So, I finally got hacked


The Dark Lord

Recommended Posts

.

 

This brings me to the point of this thread. As of yesterday, my account was hijacked by a Hungarian neckbeard (I have the IP address) and of course my items were gone and my screen name was changed to a Nazi-themed RSN. Personally, I don't give two shits about my character, despite my years of hard work on it and raising it to very high levels (level 133 character). I've had my good times with it and have met many friends over the years through the game. I only noticed that I was hijacked because I logged in to do the Diamond Jubilee thing for that cool crown and to say 'hi' to anyone logged on. Due to my knowledge about shitty Jagex security and the fact that if you press a 'Buy Spins' button in game, I know that some nimrod can potentially spam this button over and over and use my credit card without permission. This is what I'm concerned about, so I thought about canceling membership as well as buying the most up-to-date anti-virus software possible. To my knowledge, there are NO malicious software on my computer, no friends know my password/infos, I don't use Facebook, etc. I'm a little baffled how someone managed to get into my account (I'm guessing it was probably a bruteforce/shitty account recovery system or a combination of both).

 

I would appreciate some detailed information about how to secure my credit card and prevent some jackass from making purchases with it. It's been so long since I played that I really don't know how to do so. Do you guys have other suggestions for what I can do in light of my current situation? Thanks.

 

 

P.S. I'm using this as an opportunity to officially quit since I wasn't really playing in the first place. I was going to participate in the Combat Beta, but I guess I can't do that if I cancel my subscription.

SWAG

 

Mayn U wanna be like me but U can't be me cuz U ain't got ma swagga on.

Link to comment
Share on other sites

Maybe someone recovered your account like they did me.

 

My password was hugely long and numbers/letters (no one could guess it). I was inactive for a long time and never logged on.

 

The only logical explanation for it is; someone found out information about me and over a long amount of time (somehow) and recovered the account, however, I personally think the Jagex recovery system is simply not really controlled by humans, I think if loads of attempts are made it will eventually give in and give you access.

 

I tried asking Jagex for more information regarding when the person took over access of my account and all the information I got back from them was something along these lines.

 

--> They must know a lot about you.

Link to comment
Share on other sites

To answer your question. Nope, they can't use your credit card to buy spins. There is a confirmation window asking for the security numbers.

 

 

It does not matter how complicated combination your password is. It's how you use it. If you ever used the same password as your current OR PREVIOUS RuneScape password on anywhere else other than RuneScape (IE tip.it), the hacker knows it. That's half of the account recovery process. The other half requires knowing your location, isp and account creation date which are very simple to find out if you go around blabbing so much about yourself (I first started playing in late 2005 and played this game heavily througho blahblah) If you ever recovered an account, you would know it answers one of the questions there and it's quite an important one.

 

May the force be with you, Dark Lord.

Link to comment
Share on other sites

Moved to Help and Advice

 

As Kaur said, they FINALLY fixed it so they have to confirm before buying. If you happen to reconsider cancelling your membership, you can un-link your CC info from your "profile" following the instructions here: http://www.tip.it/runescape/index.php?news&id=2735

hzvjpwS.gif

Link to comment
Share on other sites

(I first started playing in late 2005 and played this game heavily througho blahblah) If you ever recovered an account, you would know it answers one of the questions there and it's quite an important one.

 

Honestly, that's sort of impossible to avoid anyway, considering the fact that many people join these fansites around the time that they start playing the game in order to receive advice, etc. Our join dates pretty much give that information away. It's a pretty silly thing to take that sort of information with more than a grain of salt when recovering accounts. :\

 

@Kimberly: Thanks, I'll check that out. :)

SWAG

 

Mayn U wanna be like me but U can't be me cuz U ain't got ma swagga on.

Link to comment
Share on other sites

Maybe someone recovered your account like they did me.

 

My password was hugely long and numbers/letters (no one could guess it). I was inactive for a long time and never logged on.

 

The only logical explanation for it is; someone found out information about me and over a long amount of time (somehow) and recovered the account, however, I personally think the Jagex recovery system is simply not really controlled by humans, I think if loads of attempts are made it will eventually give in and give you access.

 

I tried asking Jagex for more information regarding when the person took over access of my account and all the information I got back from them was something along these lines.

 

--> They must know a lot about you.

 

Tbh I think they can give access pretty easily at times. I took a long break and forgot my password, so I contact jagex to recover it. They had the hidden questions and stuff you had to fill in, problem was..I'd forgotten what I'd put for those as well. So in the comments box (there's something like that) I just said look I've forgotten most of this but here's a few things which might help out my case that it's my account. I joined around April 04, my first holiday item was X which I still have, (something else about my account). They accepted it, but thing is if someone had got chatting to me in-game and asked me my first holiday item and the other thing, could they have got my password by requesting it?

cakesncats056-1.jpg
Link to comment
Share on other sites

A little update.

 

Okay, they somehow managed to get my email address, and now I can't recover my email.

 

My RSN is Panzer Pwnzs. Feel free to try to get it locked. I'm seriously concerned because I decided not to unsubscribe because I stopped having issues.

SWAG

 

Mayn U wanna be like me but U can't be me cuz U ain't got ma swagga on.

Link to comment
Share on other sites

I also need help contacting Jagex over this. I need the account locked. I don't care if I can play it again. I just want my credit card information secure because the hackers were able to steal my email account.

SWAG

 

Mayn U wanna be like me but U can't be me cuz U ain't got ma swagga on.

Link to comment
Share on other sites

hi, i recently got hacked just a few days ago from a guy wanting help with the bandos gwd boss. he wanted me to add him on skype and sent me a picture of his invent which turned out to be a virus and he ended up hacking my account and my email making it practicly impossible to recover my account without the help of jagex. i emailed jagex at [email protected] and told them my situation and they imediatly locked my account and took off the email that was on there. im sure if you emailed them telling them what happened they would help you out. first of all though i would make sure your computer is clean, and the best way to do this is probably to go to the site http://www.geekstogo.com and create a thread with a otl log in there and you should quickly get a reply telling you if your computer is clean or not. if they hacked your email to its probably a keylogger, although i could be wrong. even though there isnt many ways it could get on your computer, its always possible and worth checking out.

 

good luck with your account!

mattpreat.png
Link to comment
Share on other sites

I sent a lengthy email to Jagex via that address you provided (an admin was kind enough to PM me the email address for contacting Jagex over this issue), and I gave them a detailed description of what happened. I also provided them with previous passwords that I used on the account, screen name history, my login name, where I logged out last before getting hacked, home address where I made account, my current IP address, my ISP, my date of birth (since this was asked when I signed up for the runescape account), date when I created account, original verification email address, recent activities, Runescape Bank PIN, unique items that I had in my bank (including what slot you could find these in), etc. I didn't have any receipts that I could show them. Anyway, the email gave this information and explained what happened and requested my account be locked.

 

I hope this helps me.

 

EDIT: I ran a full scan with my anti-virus software, and nothing other than tracking cookies were on my computer. If I got a keylogger, it would've been from some custom clients for an MMO that I play, but I'm pretty sure there aren't any keyloggers embedded into them, and the anti-virus software doesn't show any such programs on my computer, so... Due to the time between both hijackings, I suspect that I was probably bruteforced. I can't remember if you can access your Runescape account and see your email address on it or not. If so, then that's how the hacker got my email. If not, then my anti-virus software probably sucks ass. :thumbdown:

SWAG

 

Mayn U wanna be like me but U can't be me cuz U ain't got ma swagga on.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.