• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 08:33
CEST 14:33
KST 21:33
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL21] Ro24 Preview Pt2: News Flash10[ASL21] Ro24 Preview Pt1: New Chaos0Team Liquid Map Contest #22 - Presented by Monster Energy18ByuL: The Forgotten Master of ZvT30Behind the Blue - Team Liquid History Book20
Community News
$5,000 WardiTV TLMC tournament - Presented by Monster Energy1GSL CK: More events planned pending crowdfunding0Weekly Cups (May 30-Apr 5): herO, Clem, SHIN win0[BSL22] RO32 Group Stage4Weekly Cups (March 23-29): herO takes triple6
StarCraft 2
General
BGE Stara Zagora 2026 cancelled Blizzard Classic Cup @ BlizzCon 2026 - $100k prize pool Weekly Cups (May 30-Apr 5): herO, Clem, SHIN win Rongyi Cup S3 - Preview & Info Team Liquid Map Contest #22 - Presented by Monster Energy
Tourneys
RSL Season 4 announced for March-April $5,000 WardiTV TLMC tournament - Presented by Monster Energy Sea Duckling Open (Global, Bronze-Diamond) GSL CK: More events planned pending crowdfunding Sparkling Tuna Cup - Weekly Open Tournament
Strategy
Custom Maps
[D]RTS in all its shapes and glory <3 [A] Nemrods 1/4 players [M] (2) Frigid Storage
External Content
The PondCast: SC2 News & Results Mutation # 520 Moving Fees Mutation # 519 Inner Power Mutation # 518 Radiation Zone
Brood War
General
so ive been playing broodwar for a week straight. Gypsy to Korea ASL21 General Discussion Pros React To: JaeDong vs Queen [BSL22] RO32 Group Stage
Tourneys
[Megathread] Daily Proleagues [BSL22] RO32 Group B - Sunday 21:00 CEST [BSL22] RO32 Group A - Saturday 21:00 CEST 🌍 Weekly Foreign Showmatches
Strategy
Muta micro map competition Fighting Spirit mining rates What's the deal with APM & what's its true value Simple Questions, Simple Answers
Other Games
General Games
Stormgate/Frost Giant Megathread Starcraft Tabletop Miniature Game General RTS Discussion Thread Nintendo Switch Thread Darkest Dungeon
Dota 2
The Story of Wings Gaming Official 'what is Dota anymore' discussion
League of Legends
G2 just beat GenG in First stand
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Mafia Game Mode Feedback/Ideas TL Mafia Community Thread Five o'clock TL Mafia
Community
General
US Politics Mega-thread Trading/Investing Thread Things Aren’t Peaceful in Palestine European Politico-economics QA Mega-thread Canadian Politics Mega-thread
Fan Clubs
The IdrA Fan Club
Media & Entertainment
[Manga] One Piece [Req][Books] Good Fantasy/SciFi books Movie Discussion!
Sports
2024 - 2026 Football Thread Formula 1 Discussion Cricket [SPORT] Tokyo Olympics 2021 Thread General nutrition recommendations
World Cup 2022
Tech Support
[G] How to Block Livestream Ads
TL Community
The Automated Ban List
Blogs
Loot Boxes—Emotions, And Why…
TrAiDoS
Broowar part 2
qwaykee
Funny Nicknames
LUCKY_NOOB
Iranian anarchists: organize…
XenOsky
FS++
Kraekkling
ASL S21 English Commentary…
namkraft
StarCraft improvement
iopq
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1547 users

Account Thieves - They're pretty clever!

Blogs > HackBenjamin
Post a Reply
HackBenjamin
Profile Blog Joined January 2011
Canada1094 Posts
April 05 2011 12:35 GMT
#1
4/4/2011 6:11 AM
Subject: Too Many Attempts Warning No.53

Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your Computer

In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail Account

After you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your account

We now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: <omitted>

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at <omitted>

Sincerely,
The Battle.net Account Team
Online Privacy Policy




It's sad that people fall for this kind of shit, full of spelling mistakes, piss poor grammar, obviously fake links. What's even sadder is...

4/5/2011 2:42 AM
Subject: Too Many Attempts Warning No.42

Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps: etc etc etc



Hey wait a second...


4/4/2011 6:11 AM
Subject: Too Many Attempts Warning No.53

...

4/5/2011 2:42 AM
Subject: Too Many Attempts Warning No.42


ALMOST GOT ME SUCKERS



Just out of curiosity, how is it that these people/companies know that I have a battle.net account? It's not like my e-mail is displayed in my SC2 profile, my WoW characters, or anything like that. Having been the victim of a keylogger before, I use a separate e-mail account that is used for my Bnet account only, not for signing up for services, websites, forums, or anything else. It's completely insulated from the rest of my online life. I don't get it O_o

****
57 Corvette
Profile Blog Joined July 2010
Canada5941 Posts
Last Edited: 2011-04-05 12:50:58
April 05 2011 12:43 GMT
#2
I've seen some worse, but yeah these are getting pretty poor quality. You'd think with the amount of e-mails they send out they really want more accounts, and with a ton of spelling errors and stuff its not gonna fool many people.

[image loading]

And another one I got..

Hello (email),
Congratulations! Your world of Warcraft account (email) to receive compensation.This is Blizzard Entertainment's apology, We acknowledge a mistake, for you to lose the World of Warcraft account in order to recover our losses, We will give you 50000 gold coins free of charge and rare mounts (Dark Phoenix), I hope you can restart the game

Login here to authentication, 48 hours you will receive compensation

Description: test account and permanently disabled can not compensation



Edit: And I checked one of my e-mails...

[image loading]
Survival is winning, everything else is bullshit.
OmniEulogy
Profile Blog Joined July 2010
Canada6600 Posts
April 05 2011 12:46 GMT
#3
Time Travelers from the world of tomorrow are trying to take your account!

I'm not sure how they would know you had an sc2 account. Unless you use that same sn on a forums somewhere that also has the email you use for your account in the profile information.. it's a possibility they got it from that o.O
LiquidDota Staff
EscPlan9
Profile Blog Joined December 2006
United States2777 Posts
April 05 2011 12:52 GMT
#4
On April 05 2011 21:35 HackBenjamin wrote:
4/4/2011 6:11 AM
Subject: Too Many Attempts Warning No.53

Dear customer,

Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your Computer

In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail Account

After you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your account

We now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: <omitted>

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at <omitted>

Sincerely,
The Battle.net Account Team
Online Privacy Policy




It's sad that people fall for this kind of shit, full of spelling mistakes, piss poor grammar, obviously fake links. What's even sadder is...


The examples you pasted here were surprisingly well written. Yes, there will be inconsistencies and fake links. The inconsistencies in the subjects and dates is because they are merely doing mass mailing. The fake links because it would make no sense to link to the real site.

I find the incomprehensible ones more interesting.
Undefeated TL Tecmo Super Bowl League Champion
Danjoh
Profile Joined October 2010
Sweden405 Posts
April 05 2011 13:16 GMT
#5
I somehow managed to lose my WoW account, way past the time I stopped playing, and I have no idea how, except for brute force. =/

Never signed up with my bnet mail to any wow related sites, when I stopped playing, I changed my password. 3 months later I get a message that a old officer in my guild got hacked, so even tho I felt safe, I changed my password yet again, and I started having some computer issues, so I formated, and while having a clean install (updated all windows updates, installed FF+noscript) I changed my password yet another time, and had at this point stopped visiting WoW related sites.
My pass is 10 characters long, alphanumerical and no word...

4 weeks after that, I get hacked, tho, blizz support was very swift about it and restored my account and gear within 3 hours from the attack happening (or so they told me on the phone).
I saw they had added a 30 day gametime to my account, so I thought I could try it the following weekend, thursday (3 days after getting the hack resolved) I still had the gametime, but on saturday when I had finally downloaded and patched the client, the gametime was removed -_-.

I still don't get why they'd remove the gametime that was added =/
Deleted User 101379
Profile Blog Joined August 2010
4849 Posts
April 05 2011 13:22 GMT
#6
On April 05 2011 22:16 Danjoh wrote:
I somehow managed to lose my WoW account, way past the time I stopped playing, and I have no idea how, except for brute force. =/

Never signed up with my bnet mail to any wow related sites, when I stopped playing, I changed my password. 3 months later I get a message that a old officer in my guild got hacked, so even tho I felt safe, I changed my password yet again, and I started having some computer issues, so I formated, and while having a clean install (updated all windows updates, installed FF+noscript) I changed my password yet another time, and had at this point stopped visiting WoW related sites.
My pass is 10 characters long, alphanumerical and no word...

4 weeks after that, I get hacked, tho, blizz support was very swift about it and restored my account and gear within 3 hours from the attack happening (or so they told me on the phone).
I saw they had added a 30 day gametime to my account, so I thought I could try it the following weekend, thursday (3 days after getting the hack resolved) I still had the gametime, but on saturday when I had finally downloaded and patched the client, the gametime was removed -_-.

I still don't get why they'd remove the gametime that was added =/


I sometimes have the feeling that blizzard or one of it's employees is selling the info, though the passwords are probably encrypted so i guess they still have to phish for it or brute force it/get the password from a phished password with the same hash.
HackBenjamin
Profile Blog Joined January 2011
Canada1094 Posts
April 05 2011 13:24 GMT
#7


I sometimes have the feeling that blizzard or one of it's employees is selling the info, though the passwords are probably encrypted so i guess they still have to phish for it or brute force it/get the password from a phished password with the same hash.


Wouldn't surprise me if it was something along these lines. Blizz sells account emails, people get spam, click the wrong thing, and bam, account jacked. Now don't you wish you had an authenticator for $7.99?

._.
Aerox
Profile Blog Joined September 2004
Malaysia1213 Posts
April 05 2011 13:38 GMT
#8
I remember where it harvested our email addresses. It was during the time when some people (not sure if they're the same people) posted here and other community sites that there were hundreds of free SC2 beta keys available and we had to enter our email addresses at a very well-designed legit-looking site.
"Eyes in the sky."
Pika Chu
Profile Blog Joined August 2005
Romania2510 Posts
April 05 2011 13:48 GMT
#9
They don't know if you have an account. I have just enough friends who receive the same mails and don't own a SC2 account. Just as i'm receiving mail like that for WoW account, which i don't have .
They first ignore you. After they laugh at you. Next they will fight you. In the end you will win.
turdburgler
Profile Blog Joined January 2011
England6749 Posts
April 05 2011 14:17 GMT
#10
On April 05 2011 22:24 HackBenjamin wrote:
Show nested quote +


I sometimes have the feeling that blizzard or one of it's employees is selling the info, though the passwords are probably encrypted so i guess they still have to phish for it or brute force it/get the password from a phished password with the same hash.


Wouldn't surprise me if it was something along these lines. Blizz sells account emails, people get spam, click the wrong thing, and bam, account jacked. Now don't you wish you had an authenticator for $7.99?

._.


i doubt the company does that, if someone blew the whistle they would be sued for millions for data protection infringements. but i think its more than likely that staff who have access to the databases are selling information on, because loads of people i know get spam no matter if they change their emails or dont click anything phishy.
Equinox_kr
Profile Blog Joined December 2006
United States7395 Posts
April 05 2011 14:39 GMT
#11
You can take out all the guesswork of authenticity by just checking where it's mailed from. Obviously the mails will come from blizzard.com and not hotmail.com, which is where 99% of these fake e-mails come from.
^-^
BottleAbuser
Profile Blog Joined December 2007
Korea (South)1888 Posts
April 05 2011 15:18 GMT
#12
It's actually trivial to spoof the from: field. Just don't trust emails.
Compilers are like boyfriends, you miss a period and they go crazy on you.
jtm33
Profile Joined November 2010
19 Posts
April 05 2011 15:32 GMT
#13
I had a really clever one in my Gmail spam folder last month:

Greetings,

It has come to our attention that you are trying to sell your personal World of Warcraft account(s). As you may not be aware of, this conflicts with the EULA and Terms of Agreement. If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership.

You can confirm that you are the original owner of the account to this secure website with:
https://us.battle.net/account/support/login-support.xml

Login to your account, In accordance following template to verify your account.

* Account name
* Account password
* First and Surname
* Secret Question and Answer
Show * Please enter the correct information

If you ignore this mail your account can and will be closed permanently.

Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation.



Account Administration Team
Blizzard Entertainment
http://www.blizzard.com/support/
World of Warcraft , Blizzard Entertainment 2010

Please retain all history if you reply to this mail


And the account "login" page URL was a clickable link to a phishing site mimicking the battlenet login page. The from tags were spoofed to resemble Blizzard's. Also, the site returned a warning saying that it was a reported phishing site, but it wouldn't have when it was first made. Really easy to see how that could fool someone that didn't think about it. Of course it was obvious to me because my WoW sub had expired, it seemed an unlikely premise for Blizzard to send an email on, and the dodgy URL the link actually took me to.
Please log in or register to reply.
Live Events Refresh
Next event in 11h 27m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
SortOf 148
ProTech96
StarCraft: Brood War
Calm 5852
Sea 2865
Bisu 2544
Jaedong 1516
firebathero 619
EffOrt 383
Hyuk 371
Stork 345
Mini 320
actioN 299
[ Show more ]
Light 264
Rush 220
Snow 201
ZerO 181
Leta 174
Pusan 165
Soulkey 149
Killer 146
ggaemo 142
Sharp 96
hero 87
Hyun 69
NaDa 67
Aegong 64
Backho 54
JYJ 51
[sc1f]eonzerg 51
Free 50
ToSsGirL 46
scan(afreeca) 41
Shinee 41
sorry 40
JulyZerg 31
Barracks 28
Nal_rA 28
Bale 22
HiyA 20
GoRush 16
ajuk12(nOOB) 15
Icarus 15
Rock 10
Sacsri 9
IntoTheRainbow 9
SilentControl 5
Dota 2
Gorgc4724
qojqva178
Counter-Strike
olofmeister5634
markeloff71
edward52
Other Games
singsing2114
Liquid`RaSZi988
B2W.Neo614
Lowko284
XaKoH 284
crisheroes271
Mew2King45
ArmadaUGS45
ZerO(Twitch)7
Organizations
Counter-Strike
PGL32855
Other Games
BasetradeTV1118
StarCraft 2
WardiTV434
StarCraft: Brood War
lovetv 6
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• iopq 2
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Jankos2847
Other Games
• WagamamaTV176
Upcoming Events
CranKy Ducklings
11h 27m
WardiTV Team League
22h 27m
Replay Cast
1d 11h
CranKy Ducklings
1d 21h
WardiTV Team League
1d 22h
uThermal 2v2 Circuit
2 days
BSL
2 days
n0maD vs perroflaco
TerrOr vs ZZZero
MadiNho vs WolFix
DragOn vs LancerX
Sparkling Tuna Cup
2 days
WardiTV Team League
2 days
OSC
3 days
[ Show More ]
BSL
3 days
Sterling vs Azhi_Dahaki
Napoleon vs Mazur
Jimin vs Nesh
spx vs Strudel
Replay Cast
3 days
Replay Cast
3 days
Wardi Open
3 days
GSL
4 days
Replay Cast
5 days
Kung Fu Cup
5 days
Replay Cast
6 days
The PondCast
6 days
Liquipedia Results

Completed

CSL Elite League 2026
RSL Revival: Season 4
NationLESS Cup

Ongoing

BSL Season 22
ASL Season 21
CSL 2026 SPRING (S20)
StarCraft2 Community Team League 2026 Spring
Nations Cup 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals
ESL Pro League S23 Stage 1&2
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026

Upcoming

Escore Tournament S2: W2
IPSL Spring 2026
Escore Tournament S2: W3
Acropolis #4
BSL 22 Non-Korean Championship
CSLAN 4
Kung Fu Cup 2026 Grand Finals
HSC XXIX
uThermal 2v2 2026 Main Event
RSL Revival: Season 5
WardiTV TLMC #16
IEM Cologne Major 2026
Stake Ranked Episode 2
CS Asia Championships 2026
Asian Champions League 2026
IEM Atlanta 2026
PGL Astana 2026
BLAST Rivals Spring 2026
CCT Season 3 Global Finals
IEM Rio 2026
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.