Xbox Live 'FIFA hack' concerns continue to escalate
It's been several months since we started following the "FIFA hack," a rather blunt scam that saw Xbox Live accounts drained so thieves could purchase in-game FIFA 12 'Ultimate Team' cards for use and sale. We have been tracking the FIFA issue and following up on other tips that weren't necessarily rooted in the FIFA hack, but related in that users saw exploitation of payment methods tied to their account. A recent Shacknews editorial detailed accounts compromised by the FIFA exploit.
"I was sitting on my couch watching ESPN on my daughter's Live account when the Xbox Live friends notification popped up and said that I had just signed in to XBL. I took a quick look at my status and to my surprise I was online playing Worms Armageddon. I logged in to my Xbox Live account to find out what was going on," hacked user Michael Adcock told us. "All of the Microsoft points that were stored in my XBL account had been spent on Prince of Persia: The Forgotten Sands and an in-game item for FIFA 12. Whoever spent my MS points had then tried to purchase 6,000 more. Lucky I was able to log in and change my Windows Live ID, bank account and email passwords before any more damage could be done."
Adcock's incident occurred on December 27 and his account is currently locked while Microsoft investigates.
Justin Heard is another victim, with $241 spent using the PayPal account tied to his Windows Live ID. "It seems the access point was through Microsoft's website, as Rift CE was purchased for Games for Windows and that can't be done on the Xbox 360," Heard said. He explained that the hackers purchased several point bundles and then a Family Gold package, which he believes was to transfer the points from his account to the new account.
Heard's account is also locked while Microsoft investigates.
"I can state we've not been made aware of anything like that either from users or PayPal to my knowledge -- a partner we work with closely," Xbox Live Director of Policy and Enforcement Stephen Toulouse told Shacknews. Heard had previously told site VGW that when he contacted PayPal, a representative told him the online banker had received 19 calls within the past hour about the issue. Toulouse dismissed that claim. "I just checked with a counterpart at PayPal who said they have no idea what that source is talking about."
"I got an email from Microsoft saying I had purchased 10,000 points. I immediately tried to get on my Xbox, and found that I couldn't sign in," another victim, Zackh Mackey, tells us. "I checked my credit information online, and sure enough, there were charges tied to the points. I called customer support and they locked my account for a month to investigate. This happened back in early November."
It took about 28 days before Mackey's account was investigated. He tells us his account was tied to Gmail and he used a credit card.
"Two months of [Xbox Live] Gold was credited by email and the money has been refunded to my credit card. No problems since, knock on wood."
The people we've spoken to don't feel they were victims of phishing or a social engineering scam to obtain their passwords. In some cases their Windows Live IDs were tied to email addresses they hadn't used in years.
"Enough people I know in the industry with good password discipline have been victims of some kind of hacking attack that I'm taking every precaution with my own account," expressed Ben Kuchera of Ars Technica, one of the first sites to report on the FIFA hack. "The easiest way to limit your exposure is to remove your credit cards and just use point cards for purchases and to pay for your account. It's slightly inconvenient, but I feel much safer."
We've been in contact with Microsoft regarding our Windows Live ID concerns, having asked directly if the system has been compromised and, for clarity, how the hack occurs.
"Windows Live ID was not compromised. The FIFA '12 and other similar incidents are cases of social engineering or phishing, which are industry wide problems. Microsoft constantly audits its systems and reviews its processes in an effort to help protect customers from such issues," a Microsoft spokesperson told us. "To help avoid becoming a victim of phishing, people can use the guidance found at the Microsoft Hotmail: Serious About Safety site. They can also visit the Windows Live Hotmail Help Center, if they believe their account was compromised."
At this point we feel comfortable in expressing that we can't explain exactly what's going on, but we are concerned. Changing your Windows Live ID and password would be prudent, as would disassociating any credit card or PayPal and relying on point cards instead.
Posted:
Source: http://www.joystiq.com/2012/01/04/xbox-live-fifa-hack-concerns-continue-to-escalate-microsoft-s/#comments
Related Articles
Comments
Mixmaster_ReichPosted:
The same thing happened to me except I don't own FIFA lol. All I did was file a dispute in my paypal and I was returned all 124$ of my money.
NuBiXxPosted:
I hope the people who got there account hacked get all there money back.
I wonder If it's any of the morons on this site giving out there info left and right to strangers just to get there Gears stats lvl glitched.
I wonder If it's any of the morons on this site giving out there info left and right to strangers just to get there Gears stats lvl glitched.
iToXiCPosted:
M60 I Feel bad for these people who don't give out their info to phishing sites and still get hacked
Thanks!
I got hacked and I'm no stupid kid, but it happened on 911 and they bought $270.00 of MSP and managed to spend it all on FUT before I could get it back.
Microsoft took TWO MONTHS to return my account too. At very least, I got my money back and the two months of xbox live I missed out on.
TeravainenPosted:
I Feel bad for these people who don't give out their info to phishing sites and still get hacked
MPAAPosted:
Hasn't anyone noticed that this doesn't happen to those who:
1: Has a VERY obsecure LiveID (not guessable)
2: Has a VERY strong or unpredictable password
3: NEVER inputs his gamertag, liveid and/or password into phishing sites or any other sites outside of xbox.
1: Has a VERY obsecure LiveID (not guessable)
2: Has a VERY strong or unpredictable password
3: NEVER inputs his gamertag, liveid and/or password into phishing sites or any other sites outside of xbox.
JrdPosted:
this happened to my friend, he got 200 euro worth of MSP taken off his account and all was spent on FIFA 12, when he doesn't even own the game. He just called microsoft and they refunded it all and gave him 12 months live for the inconvenience :L
KorruptPosted:
ZerkosSuperS5W i got hacked and they spent 25,000 msp and spent over 600 pounds on more still dont have that :(HERP A DERP, let's give my pass out to get free players trolol
I'm sure he didn't just tell them his password... Moron.
ZerkosPosted:
SuperS5W i got hacked and they spent 25,000 msp and spent over 600 pounds on more still dont have that :(HERP A DERP, let's give my pass out to get free players trolol
Latest Downloads
- 01. SnowRunner: SaveGame (all trucks are open) [32.1](1)
- 02. [PS4/EU] Hatsune Miku: Project DIVA Future Tone 100% Trophy Save(2)
- 03. Silent Hill 2 Remake: SaveGame (Motel Jacks, NG+)(0)
- 04. Phasmophobia: SaveGame (XX-2000, $594,965,799, 3 apocalypse skulls + bonus)(2)
- 05. Satisfactory: SaveGame (Observation deck)(1)
- 06. [EU] Sniper Elite 5 - Best Of The Best (CUSA16075)(5)
- 07. Voices Of The Void: SaveGame (All improvements for work + 7 days passed) [0.8.0](1)
- 08. Silent Hill 2 Remake: SaveGame (NG+, ending "Maria")(1)
- 09. Five Nights at Freddy's- Security Breach Save(9)
- 10. Commandos 2 - HD Remaster: SaveGame (All missions are open)(0)
- 11. Black Myth: Wukong - SaveGame (100%, NG++)(3)
- 12. Mindjack save xbox(0)
- 13. mindjack ps3 save(0)
- 14. Lies of P: SaveGame (game completed 6 times, hero level 124)(1)
- 15. Shadow of the Ninja - Reborn: SaveGame(0)
Latest Tutorials
- 01. PS3 HEN - Audio via a USB headset.(296)
- 02. Stumble Guys | Social Butterfly Achievement(196)
- 03. Last Days of Lazarus Achievement Walkthrough (Xbox/PS)(1,458)
- 04. EDENGATE: The Edge of Life - 100% Trophy/Achievement Guide(1,821)
- 05. Sherlock Holmes Chapter One | Walkthrough | No Commentary(1,461)
- 06. Morbid: The Seven Acolytes | Full Game Walkthrough(2,429)
- 07. Adam Wolfe | Full Game Walkthrough | No Commentary(1,571)
- 08. ALFRED HITCHCOCK: VERTIGO - 100% Walkthrough(1,880)
- 09. SHERLOCK HOLMES THE AWAKENED | Walkthrough | No Commentary(1,330)
- 10. Space Roguelike Adventure | Guide - Cheat Code!(1,527)
- 11. DETECTIVE Stella Porta Case | Trophy & Achievement Guide(1,191)
- 12. Tunic 100% Platinum Walkthrough | Trophy & Achievement Guide(1,818)
- 13. Outbreak: The Nightmare Chronicles Achievement Walkthrough(1,456)
- 14. Full Void 100% - Trophy & Achievement Guide(1,439)
- 15. Outbreak: Lost Hope #Xbox Achievement Walkthrough(2,276)
"Xbox Live 'FIFA hack' concerns continue to escalate" :: Login/Create an Account :: 22 comments