Beware: Phishing For Your Account Info.

KALEL114

Returned
Joined
Aug 27, 2003
Messages
14,659
Reaction score
8
Points
58
A little surprised there is no thread about this yet. This seems to be getting a lot of traction, so watch you account info.

So late last year, people began to complain that their Xbox Live accounts were being "hacked". Microsoft said no, they weren't, but acknowledged there was an issue with unscrupulous types "phishing" for account info.

"It's not a hack, it's really just a different way to monetise stolen accounts", Microsoft's Doug Park said at the time.
Well, that was a few months back, and still, people are complaining that this is happening.


One such person, whose story makes for pretty grim reading, is 23 year-old Xbox Ambassador Susan Taylor, who claims that not only has her Xbox Live account been illegally accessed, but that when contacted about the problem Microsoft endlessly bounced her around customer support divisions then ultimately failed to lock her account, and as a result she's lost over $300 in purchases taken straight off her PayPal account, around half of it disappearing after Microsoft were supposed to have suspended her account for security purposes.


The scam supposedly works like this: an Xbox Live account holder's login information is somehow obtained (how exactly this happens is unclear, and is why this has been bubbling along for a few months now). The "hacker" (or however they obtained the info) buys a Family Gold Pack, which lets the culprit gift Microsoft Points to nominated accounts. They then buy a ton of Microsoft Points, set up new Xbox Live Gold accounts and siphon the points into these new accounts. Finally, on the black market these loaded accounts are sold to customers for less than it would cost to subscribe to Xbox Live Gold and buy the points themselves.


Susan tells Kotaku that she has never played FIFA 12, the title which is most often thought to have been the cause behind the scam. She also tells us that her PayPal account and Xbox Live account did not share either a username or password (though they were obviously linked via her Xbox system).


Microsoft's inaction had a slight upside, though, as she also says the fact she could still log into her Xbox meant she could track down and message one of the people who received the stolen points.


That user claims he purchased the Xbox Live account from a Polish auction site, and hands over some of the details of the person they bought the account from so Susan could track them down.
What sucks here is that, if the story checks out, Microsoft's failure to lock her console down once notified of the breach resulted in Susan losing even more money. What sucks even more is that, three months after this mess first blew up, it's still happening, and that even though Microsoft claims this is not a "hack", users are still losing accounts and money and receiving very poor customer service in return.


To see how poor, check out Susan's full account at the link below.
We've also contacted Microsoft for comment, and will update if we hear back.
http://kotaku.com/5873604/is-microsofts-xbox-live-hacking-problem-worse-than-theyre-letting-on/

More on the story can be found here:

http://www.joystiq.com/2012/01/04/xbox-live-fifa-hack-concerns-continue-to-escalate-microsoft-s/

http://www.thesixthaxis.com/2012/01/06/xbox-hacking-continues-microsoft-still-quiet/

http://www.mcvuk.com/news/read/new-questions-asked-about-xbox-live-security/089435
 
Thanks for the heads up Kal. I will be passing this along to my friends as well. Hopefully Microsoft will put a stop to this soon.
 
Moral of the story ? Don't use or save Pay Pal or Credit Card info on XBOX Live. Can't trust Microsoft to do **** about it. People say the Points System sucks. But when people can hack accounts with Credit Cards & what not on them. Start buying Points & delete any info
 
Guess that is the best way to be safe. Pretty crap of Microsoft all this.
 
Yea i started deleting ALL of my credit card info once Sony allowed my stuff to be jacked. right after that happened i deleted my info from MS's service and now just go out and buy one yr gold cards and MS points as needed. I also turned off auto renew.
 
I had the complete opposite experience in which I can't get a hold off my account after I switched credit cards. I've not been able buy Xbox live points from the marketplace for months. Credit card companies say there are no holds on my account and yet their site is the only site that does not accept them. I have to buy them via amazon.
 
Didn't Steam just get hacked like a month ago?
 
The forum did but thats a seperate entity to your steam account.
Even if they get your password and usename, it still needs verified.

[YT]gYs9nS8LlZ8[/YT]
 
Is that guy in the hat the same guy at this CES who accidentally pressed play on a gameplay video on stage and then pretended to be playing it, and then lied to the audience saying someone was playing it off stage?
 

Users who are viewing this thread

Back
Top
monitoring_string = "afb8e5d7348ab9e99f73cba908f10802"