I posted this on reddit but people have suggested I put it up here so here's the gist of it:
Hello,I hope there's some kind of action to this...it's very concerning.
I was wondering if anyone else had been hacked and what their next steps were. Here is the timeline for what I know so far.
- Logged in in the morning and did a few roulettes
- Around 11am PDT I got disconnected from FFXIV and had internet issues
- Contacted my ISP to try and figure out what happened, they can't figure it out so we did a factory reset of my router
- Logged in (using my 2fa on my iPhone) and just went about my business and queued for MSQ
- Around 1pm PDT my FC discord is asking why I left the FC. I was clueless about this so when I exited I couldn't open up my FC window so I got reinvited
- I chalked that up to maybe packets caused me to leave the FC some how
- Log in today (still using my 2fa on my iPhone) and remembered our airships first mission is complete, I go to workshop, grab ceruleum tanks and send it on it's way. At this time I noticed that the 4mil in the FC bank was gone. I checked the history and low and behold it was my name showing up at 11:09 saying I withdrew 4mil
- I glanced at my gil to see if it was sitting at 33mil (I had approximately 29mil yesterday with ss on the 18th to prove it) and noticed I only had 700k
- Did some digging on my computer and found that I had name resolution issues around 10:55am specifically to WPAD and forums.square-enix.com
So after all this, I decided to submit an ingame ticket and now I'm waiting for a response.
I can try and provide further proof but I'm not really sure how this happened and how I'm supposed to go from there.
Did someone really sniff my public IP and find a way into my PC and log in/control my account without my 2fa? Is there anything else I should be looking for? If people need screenshots or anything, let me know. I'll be as helpful as possible.
Totally something I didn't want to deal with prior to ShB launch...
Edit: /u/Bensen555 let me know that Square Enix has a login history. Well, here it is: https://media.discordapp.net/attachm...817&height=918
Looks like a login from Austria...now to hope SE does something about this.