Xbox Live account hack

cobaltsky
Contributor
Contributor

Hi

This is in reference to the unauthorized charges made to Paypal accts. via Xbox Live/Windows Live.

My XBL acct. was hacked New Years day for 100. That money was spent on XBL points which were then used to buy Fifa rare card packs. I immediately contacted Paypal to dispute those charges. I have not heard from Paypal yet about this. I also called XBL to inform them my account had been hacked. I saw someone had added an alternate email to my acct. which I deleted. I then changed my password. My passwords are 16 characters, random, and very strong. I do NOT share passwords, I was not phished, and I am the only user on that XBL acct. Microsoft said they would suspend that acct. for 25-30 days for their investigation. They said they would email me with a 30 day pass to establish a temporary XBL acct. # days later, I noticed that XBL acct. was still active!! Someone had gone in AFTER my password change and added another bogus alternate email. I deleted that email, called MS, and asked why that XBL acct. was still active. The rep apologized and said he would suspend it right there and now which he did. He asked if I had received an email with my credit. I did not and he said he would send it.

Yesterday, Jan9th, I received an email that ANOTHER bogus alternate email was added to my Windows Live account. <XBL and Windows live are completely connected so the password is the same for both>. I treid to log in to remove that email, wondering how they had managed to do that AFTER my password change??!! I could NOT log in!!! I called XBL support, told them what happened. I told him that XBL/Windows Live Acct. needs to be DELETED. The rep said he would send out another email with credit and proceeded to tell me the email address it was coming to. Imagine my TOTAL shock when he read the bogus HACKER email address to me! I said why would you send it to the ALTERNATE email address when my primary email address was right THERE!!!?? It took several back and forths before I finally was able to convince him that alternate address was the HACKER!!! So I gave him another email address to use!

 

Where things are now. I am waiting for a call from MS. I still don't know how this will turn out.

 

BOTTOM LINE: XBL/Windows Live has been COMPLETELY compromised. The internet forums are filled with thousands of stories just like mine. Go to WWW.hackedonxbox.com   There you will find plenty of evidence to substantiate what I have written here. There seems to be total denial by MS that they have a MAJOR security breach. The press is starting to catch wind of this.

Here is a little story that illustrates the scope of this issue. A fellow that had his acct hacked went to his local Best Buy and told the clerk what happened, the clerk said it happened to him too and to five of his co-workers. 

 

So if you think I am blowing smoke or overstating the situation, rethink that belief. THIS IS WIDESPREAD AND WORLDWIDE! Be proactive, act now, contact anyone you need to to protect yourself and if you have been hacked ...post your story here. THIS NEEDS TO GET OUT!!!

 

 

****My advice is, if you have an XBL acct/Windows Live Acct., to DELETE it/them until MS fixes this.****

Login to Me Too
8 REPLIES 8

Bowtome
Contributor
Contributor

Exactly same happened to me. I saw it live as I have paypal on my iphone and it alerted me to transactions.

 

He had 2 emails on my acocunt , I have removed these, I have also stopped any payments to Microsoft. So he can login if he likes, but can't purchase anything. My bank also blocked paypal payments, I spotted it before the paypal money reached my account, so nothing came out. Paypal refunded the money 16 hours later.

 

We need to sue Microsoft.

Login to Me Too

cobaltsky
Contributor
Contributor

Yes Bowtome, and from what I am hearing, this has entered into the realm of class action lawsuit. I encourage you to post your story onhttp://www.hackedonxbox.com

 

This needs to get out so that the major media gets a hold of it. Right now it is running too much under the radar. More exposure will get action. MS still is not admitting they have a security breach which is putting everyone at risk. I still have not heard from MS...no email, no refund of the 4000 points stolen from me, no 100. refund, no nothing!!  

 

Login to Me Too

cobaltsky
Contributor
Contributor

Also be aware that the hackers added bogus alternate email addresses twice to my Live acct which I deleted each time. Even after changing my password, they still got in, added another bogus email, AND changed my password. I'm deleting the account. 

Login to Me Too

Bowtome
Contributor
Contributor

I will post there.

 

I removed the 2 email accounts and then changed password, they havent readded them yet.

 

I see one of them is playing on the xbox under my name, I have asked people with xboxes to send him a warning message I am coming for him : )

 

But since I removed email accounts and changed password he hasn't been able to play.

Login to Me Too

cobaltsky
Contributor
Contributor

Yes, these hacked XBL accounts are being auctioned off on sites like TRADETANG to sometimes unsuspecting users. 

 

Check out this great article and feel free to repost/tweet/share. More people need to see this:

 

http://www.manaobscura.com/2012/01/09/xbox-security-is-a-lie/

Login to Me Too

cobaltsky
Contributor
Contributor

This is the reponse from XBL I received:                <<<<sensitive info has been deleted>>>

 

Dear Xbox LIVE Customer,

Your report of unauthorized access to your Xbox LIVE account has been received by our fraud investigations team. To protect your privacy and account information, your Xbox LIVE account is temporarily locked and sign-in is disabled.  If you use this Windows Live ID for any other Microsoft services, they will also be locked during our investigation.  Your account cannot be accessed by anyone outside of our fraud investigations team and no charges can be made to your account during the investigation. 

Because we place great importance on the privacy of our customers’ information and the safety of their experience online we thoroughly investigate each and every reported case. We have highly skilled agents working on your case; however the investigation and resolution process takes two weeks on average depending on the nature of the case.  During this time we appreciate your continued patience.

To ensure you can continue to enjoy the services offered with Xbox LIVE we are providing you a free, 30-day Xbox LIVE membership code that you can use to create a new, temporary account or save and add to your own account once it becomes available again.

If we verify that fraudulent purchases were made on your Xbox LIVE account while your account was not under your control, the purchase amounts or Microsoft Points will be refunded.  Refunds will be processed within 10 business days after the conclusion of the investigation though it may take 1 to 2 billing cycles for them to appear on your credit card statement.  If multiple purchases were made, each purchase may appear separately on your statement.

Please continue to check your email for status updates regarding this case. Additionally, we may email you with additional questions to help complete our investigation.  If you have any concerns please contact us and be sure to include service request number XXXXXXXXXXXXXXXX.

 

Sincerely,

The Xbox LIVE Investigations Team

*********************************************************************************************************************************

 

Thankfully, I do not have any monthly subcriptions to online gaming sites like so many others so the 30 day wait will not affect me much but I feel sorry for all the gamers who are getting ripped off this way and cannot play on their accounts.

 

 

My question is this: since Microsoft security is paper thin, what will prevent a new acct. from being hacked again? Of course I will not link any payment methods to it and use only scratch cards for points and leave no point balance in this account. However, I find it very disturbing that this account is vulnerable and may be used by hackers for social engineering and phishing and who knows what else. I really believe that a key generator should be used by MS like World of Warcraft or SWOTL which could prevent this kind of thing. MS seems to be very much behind the curve here perhaps because they have been very arrogant in thinking their web security is the absolute best. They still are suggesting that we, the users, are at fault in some way. I find this continued attitude on their part to be not only self-serving but puts all their users at contiinued risk.

Login to Me Too

_Zazu
Contributor
Contributor

As an avid Xbox gamer myself I have been following these updates as they are posted on several popular gaming sites. A recent post on Kotaku.com points to brute force attempts in accessing accounts.

 

Cobaltsky, I am sorry to hear that you had to experience this issue first hand, you did however bring up very good tips on password strength that I would like to expand upon to help other Community members tighten their internet security. I as well create longer character passwords, using a mix of letters, numbers and special characters. You as well hit on some good key points on how you protect yourself, including awareness of phishing attempts and not sharing accounts. These are good measures to take with any online account.

 

While experiences may differ, employing a strong password can help protect you from unauthorized intrusions, I also recommend maintaining up to date anti-virus and spyware to better protect from trojan horses and key loggers.

 

You can find more tips on password security here; PayPal - Identity Protection Resources

Login to Me Too

cobaltsky
Contributor
Contributor

Thanks!

UPDATE: My windows live/XBL account has been restored. I'm now keeping my fingers crossed that I am not hacked again.

You also bring up a good point about Trojans etc. After I was hacked, I ran two scans right away to make sure the probelm did not originate on my system. <Microsoft security essentials and Malwarebytes Anti-Malware.) I find these 2 in conjunction to be excellent!  I don't believe it is possible to prevent every intrusion but being pro-active sure helps a great deal.

 

And I have used the resource you linked and it is excellent!

 

 https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/general/SafePasswords-outside&country=US&locale...

 

Thanks for the response.

Login to Me Too

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.