• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 08:16
CEST 14:16
KST 21:16
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL20] Ro8 Preview Pt2: Holding On9Maestros of the Game: Live Finals Preview (RO4)5TL.net Map Contest #21 - Finalists4Team TLMC #5: Vote to Decide Ladder Maps!0[ASL20] Ro8 Preview Pt1: Mile High15
Community News
Weekly Cups (Sept 29-Oct 5): MaxPax triples up2PartinG joins SteamerZone, returns to SC2 competition245.0.15 Balance Patch Notes (Live version)107$2,500 WardiTV TL Map Contest Tournament 151Stellar Fest: StarCraft II returns to Canada11
StarCraft 2
General
5.0.15 Balance Patch Notes (Live version) WoL: how does "advanced construction" work? Weekly Cups (Sept 29-Oct 5): MaxPax triples up PartinG joins SteamerZone, returns to SC2 competition ZvT - Army Composition - Slow Lings + Fast Banes
Tourneys
Tenacious Turtle Tussle Stellar Fest $2,500 WardiTV TL Map Contest Tournament 15 Sparkling Tuna Cup - Weekly Open Tournament LANified! 37: Groundswell, BYOC LAN, Nov 28-30 2025
Strategy
Custom Maps
External Content
Mutation # 494 Unstable Environment Mutation # 493 Quick Killers Mutation # 492 Get Out More Mutation # 491 Night Drive
Brood War
General
RepMastered™: replay sharing and analyzer site BW General Discussion Question regarding recent ASL Bisu vs Larva game BGH Auto Balance -> http://bghmmr.eu/ [ASL20] Ro8 Preview Pt2: Holding On
Tourneys
[ASL20] Ro8 Day 4 [Megathread] Daily Proleagues [ASL20] Ro8 Day 3 Small VOD Thread 2.0
Strategy
Proposed Glossary of Strategic Uncertainty Current Meta TvZ Theorycraft - Improving on State of the Art 9 hatch vs 10 hatch vs 12 hatch
Other Games
General Games
ZeroSpace Megathread Stormgate/Frost Giant Megathread Dawn of War IV Nintendo Switch Thread Path of Exile
Dota 2
Official 'what is Dota anymore' discussion LiquidDota to reintegrate into TL.net
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
SPIRED by.ASL Mafia {211640} TL Mafia Community Thread
Community
General
UK Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread US Politics Mega-thread The Games Industry And ATVI
Fan Clubs
The herO Fan Club! The Happy Fan Club!
Media & Entertainment
Movie Discussion! Anime Discussion Thread [Manga] One Piece
Sports
2024 - 2026 Football Thread Formula 1 Discussion MLB/Baseball 2023 NBA General Discussion TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
Recent Gifted Posts The Automated Ban List BarCraft in Tokyo Japan for ASL Season5 Final
Blogs
[AI] From Comfort Women to …
Peanutsc
Mental Health In Esports: Wo…
TrAiDoS
Try to reverse getting fired …
Garnet
[ASL20] Players bad at pi…
pullarius1
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1167 users

Account Thieves - They're pretty clever!

Blogs > HackBenjamin
Post a Reply
HackBenjamin
Profile Blog Joined January 2011
Canada1094 Posts
April 05 2011 12:35 GMT
#1
4/4/2011 6:11 AM
Subject: Too Many Attempts Warning No.53

Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your Computer

In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail Account

After you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your account

We now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: <omitted>

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at <omitted>

Sincerely,
The Battle.net Account Team
Online Privacy Policy




It's sad that people fall for this kind of shit, full of spelling mistakes, piss poor grammar, obviously fake links. What's even sadder is...

4/5/2011 2:42 AM
Subject: Too Many Attempts Warning No.42

Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps: etc etc etc



Hey wait a second...


4/4/2011 6:11 AM
Subject: Too Many Attempts Warning No.53

...

4/5/2011 2:42 AM
Subject: Too Many Attempts Warning No.42


ALMOST GOT ME SUCKERS



Just out of curiosity, how is it that these people/companies know that I have a battle.net account? It's not like my e-mail is displayed in my SC2 profile, my WoW characters, or anything like that. Having been the victim of a keylogger before, I use a separate e-mail account that is used for my Bnet account only, not for signing up for services, websites, forums, or anything else. It's completely insulated from the rest of my online life. I don't get it O_o

****
57 Corvette
Profile Blog Joined July 2010
Canada5941 Posts
Last Edited: 2011-04-05 12:50:58
April 05 2011 12:43 GMT
#2
I've seen some worse, but yeah these are getting pretty poor quality. You'd think with the amount of e-mails they send out they really want more accounts, and with a ton of spelling errors and stuff its not gonna fool many people.

[image loading]

And another one I got..

Hello (email),
Congratulations! Your world of Warcraft account (email) to receive compensation.This is Blizzard Entertainment's apology, We acknowledge a mistake, for you to lose the World of Warcraft account in order to recover our losses, We will give you 50000 gold coins free of charge and rare mounts (Dark Phoenix), I hope you can restart the game

Login here to authentication, 48 hours you will receive compensation

Description: test account and permanently disabled can not compensation



Edit: And I checked one of my e-mails...

[image loading]
Survival is winning, everything else is bullshit.
OmniEulogy
Profile Blog Joined July 2010
Canada6592 Posts
April 05 2011 12:46 GMT
#3
Time Travelers from the world of tomorrow are trying to take your account!

I'm not sure how they would know you had an sc2 account. Unless you use that same sn on a forums somewhere that also has the email you use for your account in the profile information.. it's a possibility they got it from that o.O
LiquidDota Staff
EscPlan9
Profile Blog Joined December 2006
United States2777 Posts
April 05 2011 12:52 GMT
#4
On April 05 2011 21:35 HackBenjamin wrote:
4/4/2011 6:11 AM
Subject: Too Many Attempts Warning No.53

Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your Computer

In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail Account

After you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your account

We now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: <omitted>

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at <omitted>

Sincerely,
The Battle.net Account Team
Online Privacy Policy




It's sad that people fall for this kind of shit, full of spelling mistakes, piss poor grammar, obviously fake links. What's even sadder is...


The examples you pasted here were surprisingly well written. Yes, there will be inconsistencies and fake links. The inconsistencies in the subjects and dates is because they are merely doing mass mailing. The fake links because it would make no sense to link to the real site.

I find the incomprehensible ones more interesting.
Undefeated TL Tecmo Super Bowl League Champion
Danjoh
Profile Joined October 2010
Sweden405 Posts
April 05 2011 13:16 GMT
#5
I somehow managed to lose my WoW account, way past the time I stopped playing, and I have no idea how, except for brute force. =/

Never signed up with my bnet mail to any wow related sites, when I stopped playing, I changed my password. 3 months later I get a message that a old officer in my guild got hacked, so even tho I felt safe, I changed my password yet again, and I started having some computer issues, so I formated, and while having a clean install (updated all windows updates, installed FF+noscript) I changed my password yet another time, and had at this point stopped visiting WoW related sites.
My pass is 10 characters long, alphanumerical and no word...

4 weeks after that, I get hacked, tho, blizz support was very swift about it and restored my account and gear within 3 hours from the attack happening (or so they told me on the phone).
I saw they had added a 30 day gametime to my account, so I thought I could try it the following weekend, thursday (3 days after getting the hack resolved) I still had the gametime, but on saturday when I had finally downloaded and patched the client, the gametime was removed -_-.

I still don't get why they'd remove the gametime that was added =/
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
April 05 2011 13:22 GMT
#6
On April 05 2011 22:16 Danjoh wrote:
I somehow managed to lose my WoW account, way past the time I stopped playing, and I have no idea how, except for brute force. =/

Never signed up with my bnet mail to any wow related sites, when I stopped playing, I changed my password. 3 months later I get a message that a old officer in my guild got hacked, so even tho I felt safe, I changed my password yet again, and I started having some computer issues, so I formated, and while having a clean install (updated all windows updates, installed FF+noscript) I changed my password yet another time, and had at this point stopped visiting WoW related sites.
My pass is 10 characters long, alphanumerical and no word...

4 weeks after that, I get hacked, tho, blizz support was very swift about it and restored my account and gear within 3 hours from the attack happening (or so they told me on the phone).
I saw they had added a 30 day gametime to my account, so I thought I could try it the following weekend, thursday (3 days after getting the hack resolved) I still had the gametime, but on saturday when I had finally downloaded and patched the client, the gametime was removed -_-.

I still don't get why they'd remove the gametime that was added =/


I sometimes have the feeling that blizzard or one of it's employees is selling the info, though the passwords are probably encrypted so i guess they still have to phish for it or brute force it/get the password from a phished password with the same hash.
HackBenjamin
Profile Blog Joined January 2011
Canada1094 Posts
April 05 2011 13:24 GMT
#7


I sometimes have the feeling that blizzard or one of it's employees is selling the info, though the passwords are probably encrypted so i guess they still have to phish for it or brute force it/get the password from a phished password with the same hash.


Wouldn't surprise me if it was something along these lines. Blizz sells account emails, people get spam, click the wrong thing, and bam, account jacked. Now don't you wish you had an authenticator for $7.99?

._.
Aerox
Profile Blog Joined September 2004
Malaysia1213 Posts
April 05 2011 13:38 GMT
#8
I remember where it harvested our email addresses. It was during the time when some people (not sure if they're the same people) posted here and other community sites that there were hundreds of free SC2 beta keys available and we had to enter our email addresses at a very well-designed legit-looking site.
"Eyes in the sky."
Pika Chu
Profile Blog Joined August 2005
Romania2510 Posts
April 05 2011 13:48 GMT
#9
They don't know if you have an account. I have just enough friends who receive the same mails and don't own a SC2 account. Just as i'm receiving mail like that for WoW account, which i don't have .
They first ignore you. After they laugh at you. Next they will fight you. In the end you will win.
turdburgler
Profile Blog Joined January 2011
England6749 Posts
April 05 2011 14:17 GMT
#10
On April 05 2011 22:24 HackBenjamin wrote:
Show nested quote +


I sometimes have the feeling that blizzard or one of it's employees is selling the info, though the passwords are probably encrypted so i guess they still have to phish for it or brute force it/get the password from a phished password with the same hash.


Wouldn't surprise me if it was something along these lines. Blizz sells account emails, people get spam, click the wrong thing, and bam, account jacked. Now don't you wish you had an authenticator for $7.99?

._.


i doubt the company does that, if someone blew the whistle they would be sued for millions for data protection infringements. but i think its more than likely that staff who have access to the databases are selling information on, because loads of people i know get spam no matter if they change their emails or dont click anything phishy.
Equinox_kr
Profile Blog Joined December 2006
United States7395 Posts
April 05 2011 14:39 GMT
#11
You can take out all the guesswork of authenticity by just checking where it's mailed from. Obviously the mails will come from blizzard.com and not hotmail.com, which is where 99% of these fake e-mails come from.
^-^
BottleAbuser
Profile Blog Joined December 2007
Korea (South)1888 Posts
April 05 2011 15:18 GMT
#12
It's actually trivial to spoof the from: field. Just don't trust emails.
Compilers are like boyfriends, you miss a period and they go crazy on you.
jtm33
Profile Joined November 2010
19 Posts
April 05 2011 15:32 GMT
#13
I had a really clever one in my Gmail spam folder last month:

Greetings,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s). As you may not be aware of, this conflicts with the EULA and Terms of Agreement. If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:
https://us.battle.net/account/support/login-support.xml

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.

Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.



Account Administration Team
Blizzard Entertainment
http://www.blizzard.com/support/
World of Warcraft , Blizzard Entertainment 2010

Please retain all history if you reply to this mail


And the account "login" page URL was a clickable link to a phishing site mimicking the battlenet login page. The from tags were spoofed to resemble Blizzard's. Also, the site returned a warning saying that it was a reported phishing site, but it wouldn't have when it was first made. Really easy to see how that could fool someone that didn't think about it. Of course it was obvious to me because my WoW sub had expired, it seemed an unlikely premise for Blizzard to send an email on, and the dodgy URL the link actually took me to.
Please log in or register to reply.
Live Events Refresh
Map Test Tournament
11:00
TLMC #15: Group A
WardiTV565
ComeBackTV 478
IndyStarCraft 137
Rex111
3DClanTV 62
EnkiAlexander 25
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Lowko246
IndyStarCraft 137
Rex 111
SortOf 111
ProTech66
StarCraft: Brood War
Britney 44451
Sea 3795
Bisu 2698
Shuttle 2320
GuemChi 1178
Mini 1042
Larva 503
firebathero 413
hero 318
Soma 175
[ Show more ]
Light 163
Snow 161
zelot 128
Free 107
Soulkey 100
Rush 95
ToSsGirL 95
sorry 69
Mind 60
Aegong 53
Sea.KH 50
JulyZerg 39
HiyA 28
Icarus 19
scan(afreeca) 15
ajuk12(nOOB) 13
Hm[arnc] 13
NaDa 7
Dota 2
qojqva915
Cr1tdota768
XcaliburYe211
PGG 117
BananaSlamJamma87
Dendi47
Counter-Strike
x6flipin539
allub145
Other Games
singsing1946
B2W.Neo753
crisheroes388
Pyrionflax261
DeMusliM256
byalli199
hiko93
Mew2King53
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 14 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• C_a_k_e 2620
• WagamamaTV222
• Noizen39
League of Legends
• Jankos602
Upcoming Events
PiGosaur Monday
11h 44m
Map Test Tournament
22h 44m
Tenacious Turtle Tussle
1d 10h
The PondCast
1d 21h
Map Test Tournament
1d 22h
Map Test Tournament
2 days
OSC
3 days
Korean StarCraft League
3 days
CranKy Ducklings
3 days
Map Test Tournament
3 days
[ Show More ]
OSC
4 days
[BSL 2025] Weekly
4 days
Safe House 2
4 days
Sparkling Tuna Cup
4 days
Map Test Tournament
4 days
OSC
4 days
IPSL
5 days
dxtr13 vs Napoleon
Doodle vs OldBoy
Liquipedia Results

Completed

BSL 20 Team Wars
Maestros of the Game
HCC Europe

Ongoing

BSL 21 Points
ASL Season 20
CSL 2025 AUTUMN (S18)
Acropolis #4 - TS2
C-Race Season 1
IPSL Winter 2025-26
WardiTV TLMC #15
EC S1
ESL Pro League S22
Frag Blocktober 2025
Urban Riga Open #1
FERJEE Rush 2025
Birch Cup 2025
DraculaN #2
LanDaLan #3
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025

Upcoming

SC4ALL: Brood War
BSL Season 21
BSL 21 Team A
RSL Revival: Season 3
Stellar Fest
SC4ALL: StarCraft II
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.