She lost everything she’s worked for over the last 3 years..
Our guild bank was robbed..
——————
After getting a tiny bit of sleep (emphasis on tiny bit), I wanted to elaborate on last nights fiasco.
Around 230am Laeyla and I drifted away from our computers and talked about the guild merger and other things WoW-related for a little bit. Around 3am she went back to her computer and realized that she had been disconnected from the server and attempted to log back in.
At the same time, I was out in the living room letting our dog outside before bed when I heard her muffled yelling coming from the other side of the apartment but had no idea what it was about. This isn’t something out of the ordinary since our PC’s are in seperate rooms and it’s something I normally hear while she’s on vent with her friends laughing and causing a ruckus.
Earlier in the night I had asked her to set an alarm on her cell phone for 730am to wake me up for work in case I passed out on the couch watching TV and I went in to her room to make sure she did it. This is around when she told me that her password was no longer working and explained the same thing to her friends on vent.
*Let’s do the time warp agaaaaiiiin*
Rewind a few weeks back. To my recommendation, she had downloaded Deadly Boss Mods from WoW Matrix and her computer started acting a little abnormal. Brutal lag, disconnects, crashes, pop-ups, the whole 9-yards. We thought it was just a virus contracted through a music lyrics website since those are notorious for containing them, so we downloaded Malwarebytes from their website and ran a quick scan.
On the first quick scan it picked up 58 infected files all over her computer and the problems slowed down a lot.. but 2 days later they started picking back up. Every time she scanned her PC it would find more stuff even after deleting and quarentining the infected files and running full system scans combined with running CC Cleaner and Ad-Aware’s most recent updates.
We still just figured it was a virus because it had been going on about 2 weeks and nothing was compromised but all of a sudden her password had been changed for WoW. We started to put 2 and 2 together and we’re assuming the version of DBM she picked up from WoW Matrix must have been infected with a keylogger.
Sorry for the trip in the “way back machine”, but I’m in the writing mood and wanted to explain the events in detail.
The first thing I did was go to Worldofwarcraft.com and try to change her password but received an error that her password had been reset too many times recently and that she needed to contact their Billing Dept. I logged in to her registered email and discovered 2 emails, 1 at 2:09am and another around 2:30am confirming password changes.
It boggles me how easy it is to changed your password with a multi-billion dollar company like Blizzard. You log in, click change password, provide the old password and you’re done. No email saying “are you sure?”, no security question, nothing.. just “thanks for paying us $15 per month!”
I don’t blame Blizzard for her catching a keylogger. It’s not their fault. I’m just bitter and unhappy with their lack of account security.. but anyway, I digress.
After changing her passwords on my computer, I logged in to my WoW account to notice her characters logging in and out.. in.. back out.. back in and it made my stomach cringe a bit. If you played with us you would know that Laeyla is a packrat and VERY good with money so I could only imagine what they had taken.
I mounted up and headed over to the Vae Victus guild bank to notice that everything from Silk Cloth and Tigerseye to WOTLK enchanting mats, meats, eternals and gems had been taken out. Outside of myself, the limit for gold withdraws is set to 10g and they had managed to take out 10g on her Hunter and Mage before Telkire (the author of Only One in Color) removed all of Laey’s toons from the guild.
Over vent I could hear her friend Hid saying that he was standing next to her Paladin in Dalaran and that she was only wearing half of her gear and a badge-reward shield from Burning Crusade before they logged her out and logged on to her bank that was in Undercity, which is where I was at the time.
I rode back up to the mailbox to see her level 5 Warlock bank toon most likely mailing all of stolen goods to a gold farm character before logging out again. They repeated logging in and out of her various characters for about 45 minutes before it stopped for a bit and it crossed my mind that maybe they had logged over to her old Alliance characters back on Silvermoon.
I logged out and back in to my Human Shadow Priest who was docked in Shattrath and noticed that they were logged in to her old main, her Draenei Mage. This was her old raiding toon and she busted her ass gearing it up. I noticed they were in Stormwind so I ported over and stood next to her toon while they vended her gear, piece by piece in the Inn before heading to the mailbox and logging out. They logged back in to her Alliance bank toon and I’d had enough so I logged out.
I woke up for work around 745am and she told me she got an email from Blizzard saying they believe her account had been compromised and that she’d receive an email with more information but as of now she hasn’t gotten it (checked spam folders, etc.).
My plan after work is to pick up a copy of Windows XP Professional and reformat her computer and do what I can to help her get her stuff back but I’m pretty sure our options are limited without talking to Billing, etc., so we’ll see how things turn out.
Most people that get hacked usually get their stuff replaced within a week or two so I guess all we can do is wait.. and wait some more, hoping Blizzard will replace all of her stuff on all of her toons, not just a few items here and there.
Wish her luck!