1. #1

    Strange security incindent notice mail from MMO-Champion

    I don't know, if it's right place to post it. I received following message this morning. And it's strange. No, not because it looks like fishing. It looks like 100% legitimate. Only problem with it - it came to a mail address that has NEVER been used to register MMO-Champion account. I'm not even sure, if I was registered on MMO-Champion back in 2010. How can you explain it?
    Attention MMO-Champion Users:
    MMO-Champion recently learned that in 2010, there was unauthorized access to a database containing information associated with your MMO-Champion user account, including your username, associated email address and hashed password. This information was posted to a website that tracks and notifies users of compromised database information on September 5th, 2018, which is when we discovered it. For your protection, if you have not changed your password since 2010, we have expired your password, and you will be prompted to create a new password the next time you attempt to log into your MMO-Champion account. We also recommend that you change your password at any other website where you use the same or a similar password.

    Thank you for your attention to this matter. You can contact us at https://www.mmo-champion.com/sendmessage.php with questions.

    Thank you,

    The MMO-Champion Team
    Copyright © 2018 Curse Media, All rights reserved.


    Our mailing address is:
    Curse Media
    305 Church St SW
    Huntsville, AL 35801-4924

    I don't care about Wow 11.0, if it's not solo-MMO. No half-measures - just perfect xpack.

  2. #2
    The Forgettable Forgettable's Avatar
    10+ Year Old Account
    Join Date
    May 2010
    Location
    Calgary, Canada
    Posts
    5,180
    I also received this, but on my registered email. It's legit. They did some system changes today requiring passwords to be changed yearly now due to this new information. Just check out MMO-C and if you're logged in and haven't changed your password in the last year, it will ask you to.

  3. #3
    Quote Originally Posted by Forgettable View Post
    I also received this, but on my registered email. It's legit. They did some system changes today requiring passwords to be changed yearly now due to this new information. Just check out MMO-C and if you're logged in and haven't changed your password in the last year, it will ask you to.
    Problem is - it came to "wrong" email. Not to "trash" email, I used back then (I'm not sure, if it was prior to 2010) to register MMO-Champion account, that is abandoned now due to what happened back in WOD. It came to email, that has NEVER been used not only to register MMO-Champion account - it has never been used for anything, except my BNet account. So. My question is - how did they get it? Is this email compromised? Did Blizzard give them this account, i.e. compromised my BNet email via revealing it to 3rd parties without my permission?

    I don't care about Wow 11.0, if it's not solo-MMO. No half-measures - just perfect xpack.

  4. #4
    The Forgettable Forgettable's Avatar
    10+ Year Old Account
    Join Date
    May 2010
    Location
    Calgary, Canada
    Posts
    5,180
    Quote Originally Posted by WowIsDead64 View Post
    Problem is - it came to "wrong" email. Not to "trash" email, I used back then (I'm not sure, if it was prior to 2010) to register MMO-Champion account, that is abandoned now due to what happened back in WOD. It came to email, that has NEVER been used not only to register MMO-Champion account - it has never been used for anything, except my BNet account. So. My question is - how did they get it? Is this email compromised? Did Blizzard give them this account, i.e. compromised my BNet email via revealing it to 3rd parties without my permission?
    8 years is a long time. It was probably used, and you just forgot. Happens to me all the time.

  5. #5
    Quote Originally Posted by Forgettable View Post
    8 years is a long time. It was probably used, and you just forgot. Happens to me all the time.
    May be. I can't determine it now, cuz email was replaced by dummy one, when I abandoned my old account, as I didn't want to have any way to recover it. So, only thing, that interests me - was my BNet account compromised or not. Cuz if it was and it is published now, I may have some problems. Yeah, I have physical authenticator, but not compromised email - is third line of security and probably the most important one.

    That's why I don't trust cloud services. They promise you, that you can 100% trust them, as they would never give your private data to 3rd parties, but problem is - hackers won't ask them.
    Last edited by WowIsDead64; 2018-10-11 at 04:27 AM.

    I don't care about Wow 11.0, if it's not solo-MMO. No half-measures - just perfect xpack.

  6. #6
    Fluffy Kitten Nerph-'s Avatar
    15+ Year Old Account
    Join Date
    Sep 2008
    Location
    Belgium
    Posts
    8,829
    Have you signed up for any contest on MMO-Champion that asked you to login using your battle.net account? I'm no site admin or anything so I don't know if that email address gets saved (and in this case used) but it's the only thing I can think off if you are 100% sure you never signed up to MMO-Champion with that email address.
    Last edited by Nerph-; 2018-10-11 at 04:45 AM. Reason: added bold for clarity

  7. #7
    didn't think much of it considering I've changed my passwords plenty of times since fuckin 2010.

  8. #8
    Quote Originally Posted by WowIsDead64 View Post
    I don't know, if it's right place to post it. I received following message this morning. And it's strange. No, not because it looks like fishing. It looks like 100% legitimate. Only problem with it - it came to a mail address that has NEVER been used to register MMO-Champion account. I'm not even sure, if I was registered on MMO-Champion back in 2010. How can you explain it?
    You had to have used that email at some point during 2010 for the site.

    Quote Originally Posted by Nerph- View Post
    Have you signed up for any contest on MMO-Champion that asked you to login using your battle.net account? I'm no site admin or anything so I don't know if that email address gets saved (and in this case used) but it's the only thing I can think off if you are 100% sure you never signed up to MMO-Champion with that email address.
    We don't get your battle.net email when you sign in that way.

  9. #9
    Reforged Gone Wrong The Stormbringer's Avatar
    10+ Year Old Account
    Premium
    Join Date
    Jul 2010
    Location
    ...location, location!
    Posts
    15,417
    Quote Originally Posted by Sky High View Post
    didn't think much of it considering I've changed my passwords plenty of times since fuckin 2010.
    Same. I changed mine earlier this year I believe, so I'm good.

  10. #10
    Quote Originally Posted by chaud View Post
    You had to have used that email at some point during 2010 for the site.
    Can you tell, at what moment during 2010 this leak happened? May be my account wasn't affected.

    - - - Updated - - -

    Quote Originally Posted by The Stormbringer View Post
    Same. I changed mine earlier this year I believe, so I'm good.
    I don't care about MMO-Champion account, as this old account is abandoned anyway. Problem is - notification came to my BNet account and I thought, I've never used it to register anywhere, except BNet. And despite of fact, that I'm unsubbed now and don't even know, if I will resub some day, I still care about my BNet account due to amount of money, invested into it. RPGs are for greed people, yeah.
    Last edited by WowIsDead64; 2018-10-11 at 03:40 PM.

    I don't care about Wow 11.0, if it's not solo-MMO. No half-measures - just perfect xpack.

  11. #11
    Quote Originally Posted by WowIsDead64 View Post
    Can you tell, at what moment during 2010 this leak happened? May be my account wasn't affected.

    - - - Updated - - -


    I don't care about MMO-Champion account, as this old account is abandoned anyway. Problem is - notification came to my BNet account and I thought, I've never used it to register anywhere, except BNet.
    I don't have any details to share beyond what was in the email unfortunately. Feel free to use the contact form and I'll take a look to let you know what username the email was associated with.

  12. #12
    Fluffy Kitten Nerph-'s Avatar
    15+ Year Old Account
    Join Date
    Sep 2008
    Location
    Belgium
    Posts
    8,829
    Quote Originally Posted by chaud View Post
    We don't get your battle.net email when you sign in that way.
    Ah okay, it was merely a thought. Thanks for the clarification!

  13. #13
    Quote Originally Posted by chaud View Post

    im having the same issue Chaud but cant seem to get a reply anywhere, is there anyone one you could poilitely poke for me please.

    Thank you.

  14. #14
    Quote Originally Posted by Rolopolo View Post
    im having the same issue Chaud but cant seem to get a reply anywhere, is there anyone one you could poilitely poke for me please.

    Thank you.
    I've answered all emails received up to the time of this post. There isn't anyone else, I'm support, development, and content.

  15. #15
    Deleted
    Quote Originally Posted by WowIsDead64 View Post
    Can you tell, at what moment during 2010 this leak happened? May be my account wasn't affected.

    - - - Updated - - -


    I don't care about MMO-Champion account, as this old account is abandoned anyway. Problem is - notification came to my BNet account and I thought, I've never used it to register anywhere, except BNet. And despite of fact, that I'm unsubbed now and don't even know, if I will resub some day, I still care about my BNet account due to amount of money, invested into it. RPGs are for greed people, yeah.
    World of Warcraft leaked peoples email addresses to anyone you friended in the game. So any of them could have stolen your email and signed up to various sites.

  16. #16
    Quote Originally Posted by Jeffyman View Post
    World of Warcraft leaked peoples email addresses to anyone you friended in the game. So any of them could have stolen your email and signed up to various sites.
    No, I was smart enough to never use RealID. As I remember, I enabled parent control to disable it immediately. And then, when such opportunity was implemented, I disabled RealID in account options. But who knows. As I've already said, may be I had been using this mail during some short period of time, but I'm not sure, when it happened.

    I don't care about Wow 11.0, if it's not solo-MMO. No half-measures - just perfect xpack.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •