Email saying someone has reset my password.

blueflame8

Ascalonian Squire

Join Date: Mar 2009

I just got an email from [email protected] saying
'Someone at 218.8.233.220 has reset your Guild Wars Game Account password for account [email protected].
If you did not make this change, please contact support immediately at [email protected].'
I can't try logging in because the game is installed on my other computer.
So where do I go about getting help for this? I typed in [email protected] and got a invalid url. Can anyone link the website before.
Also does this mean someone has tried hacking into my account?

Yasmine

Yasmine

Wilds Pathfinder

Join Date: Nov 2007

The Lost Souls Of Jugdement [KJCD]

[email protected] is an email address, so just email them. Yes, i'm afraid you have been hacked.

gone

Guest

Join Date: Jan 2007

inetnum: 218.7.0.0[Who Is IP][trace][Reverse IP Search] - 218.10.255.255[Who Is IP][trace][Reverse IP Search]
netname: UNICOM-HL
country: CN
descr: China Unicom Heilongjiang province network
descr: China Unicom
admin-c: CH1302-AP
tech-c: LZ31-AP
status: ALLOCATED PORTABLE
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-HL
mnt-routes: MAINT-CNCGROUP-RR
changed: [Who Is Domain][trace][Reverse DNS Search] 20031110
changed: [Who Is Domain][trace][Reverse DNS Search] 20040927
changed: [Who Is Domain][trace][Reverse DNS Search] 20050511
changed: [Who Is Domain][trace][Reverse DNS Search] 20060124
changed: [Who Is Domain][trace][Reverse DNS Search] 20090508
source: APNIC

route: 218.8.0.0[Who Is IP][trace][Reverse IP Search]/15
descr: CNC Group CHINA169 Heilongjiang Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: [Who Is Domain][trace][Reverse DNS Search] 20060118
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: [Who Is Domain][trace][Reverse DNS Search]
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: [Who Is Domain][trace][Reverse DNS Search] 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: Liu Zhiyong
nic-hdl: LZ31-AP
e-mail: [Who Is Domain][trace][Reverse DNS Search]
address: Data Communication Bureau of HLJ
phone: +86-451-542931
country: CN
changed: [Who Is Domain][trace][Reverse DNS Search] 20030801
mnt-by: MAINT-CNCGROUP-HL
source: APNIC

most likely a proxy/zombie, but ya never know. (see link in post below)

JimmyNeutron

Krytan Explorer

Join Date: Sep 2007

Yeap. Log on NOW!!! before they empty your entire account!!! Probably too late now since it only takes seconds to transfer the most valuable stuff out to someone else.

gone

Guest

Join Date: Jan 2007

http://www.ip-adress.com/whois/218.8.233.220

more detailed than copy/pasta.

Bob Slydell

Forge Runner

Join Date: Jan 2007

IPwhois result

http://ws.arin.net/whois/?queryinput=218.8.233.220

EDIT: damn someone beat me to it, lol

Braxton619

Braxton619

Desert Nomad

Join Date: Jul 2008

A/W

Details of the Hacker:

OrgName: Asia Pacific Network Information Centre
OrgID: APNIC
Address: PO Box 2131
City: Milton
StateProv: QLD
PostalCode: 4064
Country: AU

ReferralServer: whois://whois.apnic.net

NetRange: 218.0.0.0 - 218.255.255.255
CIDR: 218.0.0.0/8
NetName: APNIC4
NetHandle: NET-218-0-0-0-1
Parent:
NetType: Allocated to APNIC
NameServer: NS1.APNIC.NET
NameServer: NS3.APNIC.NET
NameServer: NS4.APNIC.NET
NameServer: NS-SEC.RIPE.NET
NameServer: TINNIE.ARIN.NET
Comment: This IP address range is not registered in the ARIN database.
Comment: For details, refer to the APNIC Whois Database via
Comment: WHOIS.APNIC.NET or http://wq.apnic.net/apnic-bin/whois.pl
Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
Comment: for the Asia Pacific region. APNIC does not operate networks
Comment: using this IP address range and is not able to investigate
Comment: spam or abuse reports relating to these addresses. For more
Comment: help, refer to http://www.apnic.net/apnic-info/whoi...e-and-spamming
RegDate: 2000-12-07
Updated: 2009-10-08

OrgTechHandle: AWC12-ARIN
OrgTechName: APNIC Whois Contact
OrgTechPhone: +61 7 3858 3188
OrgTechEmail: [email protected]

# ARIN WHOIS database, last updated 2009-12-12 20:00
# Enter ? for additional hints on searching ARIN's WHOIS database.

Where he lives:


SaiyanAvatar

Pre-Searing Cadet

Join Date: Apr 2009

FIGS

Blueflame, same IP address got my account as well. I have no idea what's going on or what's missing yet.

I've contacted NCsoft but have not yet heard back.

How is your situation going so far?

Bob Slydell

Forge Runner

Join Date: Jan 2007

http://i47.tinypic.com/2s0zcao.jpg
http://i46.tinypic.com/20tnnuu.jpg

Asia Pacific Network. Sounds like a data center.

Im afraid they used a proxy server. Maybe support can still help you though.

Siirius Black

Siirius Black

Krytan Explorer

Join Date: Aug 2007

The Dragon's Lair

La Legion Del Dragon

E/

Dont you suppose to make password changes from NCSOFT? if they did the change there...then the security breach or problem is at NCSOFT...

gone

Guest

Join Date: Jan 2007

My gut tells me Liu Zhiyong lives here (see link)
http://maps.google.com/maps?source=s...000000&split=1

gone

Guest

Join Date: Jan 2007

I'd like to add that in NO WAY are MY POSTS approved by this site, Anet or NCsoft. just a post from some random guy on the interwebs.

JimmyNeutron

Krytan Explorer

Join Date: Sep 2007

I created a bogus account on NCSoft and yeap...you can reset your password WITHOUT having to know your existing password NOR does NCSoft sends a confirmation email to your register email address BEFORE they reset your password.

My opinion....NCSoft is to blame!!! due to lack of security implementations.

VOICE UR ANGER AGAINST NCSOFT!!! Remember....vote w/ your wallet.

Curious...all those that got their account hack, did you register on ANY fansites using your GW's login info (your email address)?
Thanks!

Xaniane

Xaniane

Ascalonian Squire

Join Date: Oct 2008

Kindred Spirits (KiN)

E/

Blue! I had the exact same thing happened to me about a month ago.
Same email saying someone at so and so address has reset your password if this is not you contact support immediately.
I tried the url that they provided and it was invalid or it was in chinese.
So I went to the guildwars website and then went to NCsoft link in there and changed my password.
All I can say is thank god nothing has been touched.
But I'm still peeved, Not Happy Jan!....

Bob Slydell

Forge Runner

Join Date: Jan 2007

There still is no way to tell if its really a guy in china or if its a proxy from someone in America, there is just no way to tell still. But since other people had the same address linked to their password changing, leads me to believe that its a gold selling site/business's IP address. ArenaNet should take action and just simply deny that IP address any service to Guild Wars. It'll stop them for a while and cause them to have to take the time and change their IP with the ISP. They might still be able to change passwords in NC, but when they try to access GW it'll fail.

gone

Guest

Join Date: Jan 2007

I've been getting e-mails like this lately(for like.....months). the hilarious thing is, I've never went near, signed up for, or ever had anything to do with Blizzard. ever.
the actual message is the best.

Quote:
Dear Blizzard Customer,
We have received a notice that there was made by the owner
of the Right to belong that your account with problems .
This is a very serious matter. You must login our website,else I will block your account.
This is a time sensitive issue and must be resolved promptly.
Please reply to this email with information about how you will deal with this situation.
I have disabled your account on the basis of fraudulent.
now you can login removedlink submit your evidence.
Otherwise, we will be deemed to give up your right to appeal.

Blizzard, we will need your full cooperation.

I thank you for your time and hope to hear from you soon.
if you want unlocked,please contact us within 15 days at our website:
Code:
Security of Blizzard Account
Sunday, December 13, 2009 4:02 PM
From [email protected] Sun Dec 13 21:02:00 2009
X-Apparently-To: 		 via 216.252.110.186; Sun, 13 Dec 2009 13:02:35 -0800
Return-Path: 		<[email protected]>
X-YMailISG: 		zHSsHnkWLDtWo8ax_fR8k4UhvvjYG9TS7_OKvqB8ehDaFs329TT4Pax4GiobsuQyflMwXzH_2mwx_C2xntXunB0jx9o6.ES0ytqE7QeZSGDp0ZCst.4lsNZvL.8TS0ak97Fwf2YLHNU8FpDtggi1Vld5dz3R_yqiFhxhoXaogPFDAhtRdFRhZ8EfXNy8K317mAh3uSyAC3XcZ3nZ3uk1kgNqArjvV0LajZjo.MaPZvXb9NakMGCYZ7bhEsCY7uvE6IVC5vlF9hCA5eP4Lx9xeXXeDL4eLFlx.kgnQ9hHa5PatuUeKCHD9CP7bA1DlCb3v2GqO19Lq8vC85If.A.uvLgok142NX4zru7vGGW.e2UUWbuco09JDct5zaIKa5P5A1qlsnNAQrVOig74MbsLXOM.xua.EMPn_FFCOiD.uUptJlyTfN8gfePQvu0fsXJUVt37rK4XqxgFOTrV
X-Originating-IP: 		[65.55.111.110]
Authentication-Results: 		mta1048.mail.sk1.yahoo.com from=blizzard.com; domainkeys=neutral (no sig); from=blizzard.com; dkim=neutral (no sig)
Received: 		from 127.0.0.1 (EHLO blu0-omc2-s35.blu0.hotmail.com) (65.55.111.110) by mta1048.mail.sk1.yahoo.com with SMTP; Sun, 13 Dec 2009 13:02:34 -0800
Received: 		from BLU0-SMTP35 ([65.55.111.71]) by blu0-omc2-s35.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Sun, 13 Dec 2009 13:02:06 -0800
X-Originating-IP: 		[60.19.171.235]
X-Originating-Email: 		[[email protected]]
Message-ID: 		<[email protected]>
Return-Path: 		[email protected]
Received: 		from fmy ([60.19.171.235]) by BLU0-SMTP35.blu0.hotmail.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.3959); Sun, 13 Dec 2009 13:02:02 -0800
From: 		
"[email protected]" <[email protected]>  
Add sender to Contacts
To: 		<>
Subject: 		Security of Blizzard Account
Date: 		Mon, 14 Dec 2009 05:02:00 +0800
MIME-Version: 		1.0
Content-Type: 		text/html; charset="utf-8"
Content-Transfer-Encoding: 		base64
X-Priority: 		3
X-MSMail-Priority: 		Normal
X-Mailer: 		Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: 		Produced By Microsoft MimeOLE V6.00.2900.5512
X-OriginalArrivalTime: 		13 Dec 2009 21:02:03.0261 (UTC) FILETIME=[85296AD0:01CA7C37]
Content-Length: 		1737
Compact Headers

Dear Blizzard Customer,
We have received a notice that there was made by the owner
of the Right to belong that your account with problems .
This is a very serious matter. You must login our website,else I will block your account.
This is a time sensitive issue and must be resolved promptly.
Please reply to this email with information about how you will deal with this situation.
I have disabled your account on the basis of fraudulent.
now you can login http://www.worldofwarcraft.com submit your evidence.
Otherwise, we will be deemed to give up your right to appeal.

Blizzard, we will need your full cooperation.

I thank you for your time and hope to hear from you soon.
if you want unlocked,please contact us within 15 days at our website:
http://www.worldofwarcraft.com

Sincerely,
Blizzard Billing Department
http://www.Blizzard.com
I can assure you, the "wor1dofwarcraft" almost had me clicking. lulz.
/edit2
whoops forgot
http://www.ip-adress.com/whois/60.19.171.235

nbajammer

nbajammer

Krytan Explorer

Join Date: Jun 2005

Iowa

Blade And Rose [BaR]

Mo/

Anyone would be crazy to take that e-mail seriously with so many English grammatical errors.

Lifestyle

Academy Page

Join Date: May 2009

R/Mo

These tracerts, whois's, google maps, and bad e-mails made my day

SaiyanAvatar

Pre-Searing Cadet

Join Date: Apr 2009

FIGS

UPDATE: I got back in, thankfully the person left my customized weapons and armor alone...EL Tonic, lots of gold and ectos gone though...oh well, so much for ever getting a tormented item or filling my hall...I'll never have gold again because I originally got it from kegging...so it goes, but it could be worse...

gone

Guest

Join Date: Jan 2007

I just have to wonder..will these D-bags ever give up?
this time it's "worldofwarrcrarft" and claiming my nonexistent PW on a nonexistent account was changed.
Quote:
Greetings!
This is an automated notification regarding the recent change(s) made to your World of Warcraft account.
Your password has recently been modified through the Password Recovery website.
If you made this password change, please disregard this notification.
However, if you did NOT make changes to your password we recommend you Login verify your password:
linkremoved

If you are unable to successfully verify your password, please contact Billing & Account Services at *removed*.
Account security is solely the responsibility of the account holder.
Please be advised that in the event of a compromised account, Blizzard representatives typically must lock the account.
In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.


Regards,

The World of Warcraft Support Team
Blizzard Entertainment
Code:
World of Warcraft - Password Recovery
Wednesday, December 16, 2009 1:41 PM
From [email protected] Wed Dec 16 18:41:54 2009
X-Apparently-To: 		 via 216.252.110.187; Wed, 16 Dec 2009 10:35:42 -0800
Return-Path: 		<[email protected]>
X-YahooFilteredBulk: 		65.55.111.109
X-YMailISG: 		aE3xNuoWLDsgx1ShU3tMDeUAfgu3sKVWzuwFJlGNZOQpPui5jjco1iqSvTvhkePJpJr9ofq1KZWBSLPuaP1wngBqEgnOm2gFjnnH1.TjL7h436bvomGQTUgv81PMZUT1pM2q6jglZstmPYMd8PFzvTAp9PAHN.37Xsy4o7bsG8g8fgW3SalSMJHYdc_c3jgUNutCB3NGhb_hxCMUUca41KAw8bwVaOq1qWRT.O9GoGFeCIP1e_srvpvsshX2g3Biu8Ql7tYSe_ADKeWat6qHHkho1Yz47Z1YQfKJxD2nnW425QXKdKpbqPuGLK9T.wHLDoobHX0IajdCdn6EP7tyDExIsmMgytdBG4suRnC5BZ4GXeTP_A2V14tuE9fbmO9q3eFFRL8-
X-Originating-IP: 		[65.55.111.109]
Authentication-Results: 		mta1013.mail.mud.yahoo.com from=blizzard.com; domainkeys=neutral (no sig)
Received: 		from 127.0.0.1 (EHLO blu0-omc2-s34.blu0.hotmail.com) (65.55.111.109) by mta1013.mail.mud.yahoo.com with SMTP; Wed, 16 Dec 2009 10:35:42 -0800
Received: 		from BLU0-SMTP80 ([65.55.111.71]) by blu0-omc2-s34.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Wed, 16 Dec 2009 10:35:20 -0800
X-Originating-IP: 		[222.69.160.215]
X-Originating-Email: 		[[email protected]]
Message-ID: 		<[email protected]>
Return-Path: 		[email protected]
Received: 		from ygvgfaci ([222.69.160.215]) by BLU0-SMTP80.blu0.hotmail.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.3959); Wed, 16 Dec 2009 10:35:19 -0800
Reply-To: 		<[email protected]>
From: 		
"[email protected]" <[email protected]>  
Add sender to Contacts
To: 		<>
Subject: 		World of Warcraft - Password Recovery
Date: 		Thu, 17 Dec 2009 02:41:54 +0800
MIME-Version: 		1.0
Content-Type: 		multipart/alternative; boundary="----=_NextPart_000_0E46_0180E6D4.12A4DA40"
X-Priority: 		3
X-MSMail-Priority: 		Normal
X-Mailer: 		Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: 		Produced By Microsoft MimeOLE V6.00.2900.5512
X-OriginalArrivalTime: 		16 Dec 2009 18:35:19.0812 (UTC) FILETIME=[8522F440:01CA7E7E]
Content-Length: 		3403
I'm Almost ready to do stupid things "for the LuLz"
/edit-whoops -it looks to me like they are operating out of apartments/hotel rooms lol.
http://www.ip-adress.com/whois/222.69.160.215

gone

Guest

Join Date: Jan 2007

Yep. here we go. this time it's "worldofwarcraft-wowaccountmanagement" now that one ALMOST looks legit. looks like they are even getting grammar correct, now it's just a punctuation thing.
Quote:
Greetings!
This is an automated notification regarding the recentchange(s)
made to your World of Warcraft account. Your password has recentlybeen modified through the Password Recovery website.
*** If you made thispassword change, please disregard this notification.
However, if you did NOTmake changes to your password we recommend you Login verify your password:
removedlink
Account security issolely the responsibility of the account holder.
Please be advised that inthe event of a compromised account, Blizzard representatives typically must lockthe account.
In these cases the Account Administration team will requirefaxed receipt of ID materials before releasing the account for play.
Regards,
The World of Warcraft Support Team BlizzardEntertainment
Code:
World of Warcraft Account Management
Friday, December 18, 2009 6:04 PM
From wowaccountadmin Fri Dec 18 23:04:48 2009
X-Apparently-To: 		 via 216.252.110.186; Fri, 18 Dec 2009 15:02:02 -0800
Return-Path: 		<[email protected]>
X-YahooFilteredBulk: 		65.55.111.97
X-YMailISG: 		QwADviMWLDvKvB9aYsV3nB4QEUTERxMM9Oluj0EMu31k6nmEQhhInUULJls8mrVRGyZWlXCxV_viz8E5ODqS7WjL.TeSOyVI8RrMdvtstrQZHqHp9lX0VPaqbaUzsPsTgTnUrQROtFxtDj3K8TuyWvnpSNnaw0IgHXQ7E8_haMQm1VWDx_9j8.FTM3_ex.W8_LsMVg0dMIe5WFpz7HN6qCk4HCf0vepJVBXN2zvOjIzZJmkZ1KV1Y6MG4qfOJEkWcVxf2tUeuJspyYDSFg_8qVsi0BcPYPng9jlWBzkKO6NNHaB0h0075F5HMQks5t5FuUC6SbJMkdcr9dApaZjFsW..lgx2QeiaAdCJbjmtgiwuhMsBndS3mxOlqZIzOmhyqKExDkKFLE3j6wm1GdaoNzeS1fgQ9qmDBgmoH_Y-
X-Originating-IP: 		[65.55.111.97]
Authentication-Results: 		mta1059.mail.sk1.yahoo.com from=blizzard.com; domainkeys=neutral (no sig); from=blizzard.com; dkim=neutral (no sig)
Received: 		from 127.0.0.1 (EHLO blu0-omc2-s22.blu0.hotmail.com) (65.55.111.97) by mta1059.mail.sk1.yahoo.com with SMTP; Fri, 18 Dec 2009 15:02:01 -0800
Received: 		from BLU0-SMTP8 ([65.55.111.72]) by blu0-omc2-s22.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Fri, 18 Dec 2009 15:01:55 -0800
X-Originating-IP: 		[222.242.194.93]
X-Originating-Email: 		[[email protected]]
Message-ID: 		<[email protected]>
Return-Path: 		[email protected]
Received: 		from ijbwsutb ([222.242.194.93]) by BLU0-SMTP8.blu0.hotmail.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.3959); Fri, 18 Dec 2009 15:01:54 -0800
Reply-To: 		<[email protected]>
From: 		
"wowaccountadmin" <[email protected]>  
Add sender to Contacts
To: 		<>
Subject: 		World of Warcraft Account Management
Date: 		Sat, 19 Dec 2009 07:04:48 +0800
MIME-Version: 		1.0
Content-Type: 		text/plain; charset="utf-8"
Content-Transfer-Encoding: 		base64
X-Priority: 		3
X-MSMail-Priority: 		Normal
X-Mailer: 		Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: 		Produced By Microsoft MimeOLE V6.00.2900.5512
X-OriginalArrivalTime: 		18 Dec 2009 23:01:54.0344 (UTC) FILETIME=[17725A80:01CA8036]
Content-Length: 		1101
http://www.ip-adress.com/whois/222.242.194.93

Pimpmyplatypus

Ascalonian Squire

Join Date: Jun 2006

W/Rt

what, like this:

Greetings!
This is an automated notification regarding the recent change(s)
made to your World of Warcraft account. Your password has recently been modified through the Password Recovery website.
*** If you made this password change, please disregard this notification. However, if you did NOT make changes to your password
we recommend you Login verify your password:
-at worldofwaocraft link -
If you are unable to successfully verify your password .
using the automated system, please contact Billing & Account Services at 1-800-59-BLIZZARD (1-800-592-5499) Mon-Fri, 8am-8pm Pacific Time or at [email protected]. Account security is solely the responsibility of the account holder. Please be advised that in the event of a compromised account, Blizzard representatives typically must lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.
Regards,
The World of Warcraft Support Team Blizzard Entertainment


From the lovely people at wowaccountadmin ([email protected])

i've been getting them for months