It's not convincing enough if you've had to enter the OTP on the official pages. They aren't even on the same page as the username and password after all.Oh yeah received one of those scam messages.
They basically send you to a mirror of the forums pretty well done btw, with fake GMs saying hey I want to participate in this raffle!
My luck I was logged on the forums already, so I was able to avoid this.
So moral of the story if some random dude invite you to some lottery stuff or whatever that requires you to log in at something. Avoid it at all costs.
Like the mirror is the same as the forum UI, it show as you didn't log in yet to the forums and had that upper button in the top right telling you to log in, I didn't click it because I just had logged in the official forums, then I paid attention to the URL and I was like oh a f* scammer. I was really distracted, could had prevented by just not entering the link at all at least wasnt scammed, but still had to run Anti Virus, Spybot check registry alterations and so on. Changed my password and setup my one pass app finally...
What Avatre means is that the scam pages put the login/password and OTP fields on the same page; the web real login flow has the login/password (which is validated) and then put the OTP entry on a second page after that login, and only do so if you have a security token registered to the account.Like the mirror is the same as the forum UI, it show as you didn't log in yet to the forums and had that upper button in the top right telling you to log in, I didn't click it because I just had logged in the official forums, then I paid attention to the URL and I was like oh a f* scammer. I was really distracted, could had prevented by just not entering the link at all at least wasnt scammed, but still had to run Anti Virus, Spybot check registry alterations and so on. Changed my password and setup my one pass app finally...
Since the scam pages can't do that first part of the login and present the OTP conditionally, they do it all on one page; when the user/password/OTP is entered, they can automatically log you in on game (thus booting you as a 'dead connection', like when you get disconnected and try to immediately reconnect) via what's basically a highway robbery bot. Since you can log back in quickly (and the OTP will expire so they can't get back into your account a second time without phishing the OTP from you again) they have to work very quickly to strip you of what resources they can in a seemingly wholly-automated manner. (As in, your gil can potentially be gone in under 20 seconds, sometimes even less.)
As a side note, this is an excellent reason to use password managers. Yes, you probably know your FFXIV login/password by heart from entering it in the launcher, but if you hit 'fill from password manager' when you go to the forum login page... on the real site, it'll fill the username/password. On a phishing site... well, the password manager just sees that it's a domain you don't have a password saved for, and will go "Nope, don't have a password for here." Which can be enough to make you look at the address bar more closely and see that oh, you aren't on the real site.
I aim to make my posts engaging and entertaining, even when you might not agree with me. And failing that, I'll just be very, VERY wordy.Originally Posted by Packetdancer
The healer main's struggle for pants is both real, and unending. Be strong, sister. #GiveUsMorePants2k20 #HealersNotRevealers #RandomOtherSleepDeprivedHashtagsHere
|
![]() |
![]() |
![]() |
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.