My friend's wow account was hacked last night

Hello, we aren’t sure where to go but figured the forums would help.

This is what he said.

“I was grinding WoW all day long today. I got a random whisper in game saying that I had broken a rule and that if I did not log into the main website my account would be suspended. It was the official website so I logged into it to make sure nothing had happened to my account. And it all looked normal, about 3 hours later I got disconnected from WoW. I asked my guild mates if they saw me online someone had hacked my account and was going through all my characters. I now have no access at all to my account. I have the credit card information used for my subscription. I just want to get my account back and make sure I add authentication which I thought was already set up.”

Server: Lone Wolf - US
Character Name : Daddyduress
Ticket Number : #98450265

He’s had this account for years since release and is worried he won’t be able to get his account back. He’s opened tickets but he has not received a reply as yet. Can anyone assist us?

Relay the following Support Article ro your friend:

Account recovery is handled by GMs, who are accessible only by submitting a ticket, such as one created via the procedures in that support article.

9 Likes

He does have a ticket open.

That, however, is NOT a Blizzard site.

It is important to know how a URL is constructed. Anything with a hyphen in it, that is not a subdomain, that’s a totally different domain.

If a Blizzard GM actually ever messages a person in-game, our text is blue, has a logo - and is in a completely separate textbox.

16 Likes

Also to add: If you can report the “GM” it is not a GM they usually have a RP appropriate name not “Blizzard” or similiar, as they cannot be reported through the right click window.

While you can report players meaning they are impersonating a GM.

8 Likes

You’re friend has fallen victim to a phishing scam, someone pretending to be Blizzard and sending him to a malicious website.

Have him/her follow the instructions in the support article that was posted above by Sniperorc. In addition, they should scan their computer to make sure that the site didn’t install anything that can be harmful on their computer. I’d also recommend that they make a new email account that is used ONLY for Blizzard.

Also tell them to be patient. Sometimes these things can take a few days because the hackers do a lot of damage to an account that needs to be tracked and repaired.

10 Likes

This!

Tickets may take several days to get answered. As long as he has a ticket number then the ticket is in queue. Blizzard can clean up the damage as long as the logs back it. The account may also get banned as a result of what the hacker did. If so, he should open the compromise ticket again and ask for that to be fixed.

While he waits he needs to ensure his computer is clean and other accounts are secure.

  • Run a malware scan with update malware tools, such as Malwarebytes. The free version is fine.
  • Run a virus scan with an updated virus scanner. Windows Defender is fine as long as it is updated.
  • Have him set up a NEW email that he uses for nothing else. The hacker knows his current one so he needs a new one. Select one that has secondary authentication on it such as Gmail. Then he can secure the email and keep them out. Either he needs Blizzard to put that on the account, or he will need to do it when he gets the account back.
  • When he gets the account back he needs to setup the Authenticator app on it. That is now integrated into the Bnet Launcher, not a standalone app anymore.
  • If any of his other accounts use that email or password he is going to want to change them. Those are organized groups of criminals who steal accounts and they will try his email and password on other services.

Last thing - if they reply via email telling him he needs to give info showing he is the registered account owner - DO NOT REPLY TO THE EMAIL. They really mean do-not-reply when they send from there.

He should open a new Ticket, reference the first ticket number just like you did, and provide the info via ticket.

Good luck!

10 Likes

Yes, he has filled that information out and he has submitted a ticket last night

Thank you so much, he is currently formatting his PC as i type this. He was a bit panicked but all the replies has calmed him down. Thank you again everyone. He created a new email only for blizzard as suggested since the email attached to that account was compromised as well.

4 Likes

He needs to get that email to us so the process can be finished.

9 Likes

How can he get the email to you? He’s looking for his ticket but it’s closed. Should he open a new ticket to provide the email?

1 Like

He can pop in another ticket on the same account he submitted the report on.

7 Likes

Okay he has done that. The updated ticket is: US98461304

3 Likes

Yep, that’s what they do. They liquidate everything so that they can try and sell off your gold to people who are dumb enough to think that buying illicit gold is a victimless crime.

As you’ve already got a ticket in, part of the restoration process will be to get you your gold and items back, but it takes time.

The most important thing is to secure your account immediately as they are absolutely going to try and steal it back to peddal their wares.

9 Likes

Although this is probably a case of “barn door, horses gone”, here’s a support article about recognizing Blizzard account phishing tactics.

5 Likes

Ticket Number: US98464208! I had to open a new ticket as the last one was closed. This ticket number has the missing items from my account on it. If you guys have time to look into this as it effects gameplay hugely! Thank you for all your help and patience with me.

awesome you got your account back so quick though, been waiting since 6am saturday for mine.

This also happened to me early yesterday. Put in a ticket 24hrs ago with no response yet, as of recently was able to get the account back and it was banned which i assume or hope happened because of a fraud flag from my ticket. The only response was from the recovered accounts ticket which i hope is not a real response saying i violated terms of service. Im sure the company has alot going on, followed all the advised steps. Took a few more for precaution. Would like to see it resovled in some timely manner,
thank you.

Also posting from account first ticket was put up on, because i cant on banned account.

i somehow am still posting on my account even though my email address was changed by the hacker. not sure how that is a thing.

Your forum login tokens are still in your browser and active. When the forum software, or browser refreshes those then you will be logged out of the forums too.

2 Likes

thanks for the info

1 Like