Results 1 to 10 of 62

Hybrid View

  1. #1
    Player
    Klaleara's Avatar
    Join Date
    May 2020
    Posts
    104
    Character
    Sylveras Wolfedrake
    World
    Jenova
    Main Class
    Black Mage Lv 85
    Quote Originally Posted by Canadane View Post
    No, you took the phishing bait. I'm sorry I know you don't wanna place the blame on yourself but we've probably all gotten these tells multiple times by now. The website TLD is not identical to anything SE uses.
    Knowledge is power here, and understanding what happened is only going to help you and others not also fall for this.

    I'm sorry for what happened I feel for you, but understanding exactly what happened to you is important. Your edit makes...little sense. Your IP cannot be hacked per se. Getting your personal information and getting threats is almost unheard of from RMT they kust want to empty your gil and use your character to spam the same RMT message you got in the first place. But if they did have your account access they could also in turn log into your account management and see your personal information. This is likely how they sent you a message, if any.
    If you had used a security token on your account, it wouldn't have helped your initial character loss. You would have still had someone log into your character. But it may have stopped them from logging into your SE account management as the OTP would have changed and your personal information wouldn't have been accessible.

    Again, it sucks to have happen, but be wary of suspicious links. You can stop it from happening again.
    If they hit the scammers website from their computer, the scammers could have gotten their IP. Just, nothing they could really do with their IP lol.

    Secondly, pretty sure a security token on the account would have helped the initial character loss, as it's required to use the token to login to the game and get access to the character. A note, there are already plenty of ways to get around two-factor authentication, decent hackers get by it with fair ease. However, anyone with those skills aren't going to give 2 f's about someones final fantasy character.
    (2)

  2. #2
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,038
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by Klaleara View Post
    If they hit the scammers website from their computer, the scammers could have gotten their IP. Just, nothing they could really do with their IP lol.

    Secondly, pretty sure a security token on the account would have helped the initial character loss, as it's required to use the token to login to the game and get access to the character. A note, there are already plenty of ways to get around two-factor authentication, decent hackers get by it with fair ease. However, anyone with those skills aren't going to give 2 f's about someones final fantasy character.
    Nah, they capture the code with the fake login site then immediately enter it into the client. That's how they login.


    2fa won't help you if you give them the code lol.
    (4)

  3. #3
    Player
    Avatre's Avatar
    Join Date
    Jul 2017
    Posts
    2,852
    Character
    Avatre Drakone
    World
    Cactuar
    Main Class
    Dancer Lv 100
    Quote Originally Posted by Valkyrie_Lenneth View Post
    Nah, they capture the code with the fake login site then immediately enter it into the client. That's how they login.


    2fa won't help you if you give them the code lol.
    That's also assuming the site that you are "logging" into has the spot to enter 2fa. If they don't, then there would be no way to get into the account. As I haven't even looked at those phishing links, I don't even know if they have a field for that.
    (0)

  4. #4
    Player
    Klaleara's Avatar
    Join Date
    May 2020
    Posts
    104
    Character
    Sylveras Wolfedrake
    World
    Jenova
    Main Class
    Black Mage Lv 85
    Quote Originally Posted by Valkyrie_Lenneth View Post
    Nah, they capture the code with the fake login site then immediately enter it into the client. That's how they login.


    2fa won't help you if you give them the code lol.
    Depends on the 2fa you have? Most 2fa's is just a text to your phone, not an actual token. It seems that FF14 uses the token version though, which is meh imo.
    (0)

  5. #5
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,038
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by Klaleara View Post
    Depends on the 2fa you have? Most 2fa's is just a text to your phone, not an actual token. It seems that FF14 uses the token version though, which is meh imo.
    No I mean, you have to put in the code it gives you when you log in right?

    If you give them the code when you "log in" to the phishing site, then the 2fa is pointless because you gave them the code to get in.
    (10)

  6. #6
    Player
    Klaleara's Avatar
    Join Date
    May 2020
    Posts
    104
    Character
    Sylveras Wolfedrake
    World
    Jenova
    Main Class
    Black Mage Lv 85
    Quote Originally Posted by Valkyrie_Lenneth View Post
    No I mean, you have to put in the code it gives you when you log in right?

    If you give them the code when you "log in" to the phishing site, then the 2fa is pointless because you gave them the code to get in.
    A lot of (And my preferred method) of 2FA tokens are pushed. Meaning, you'll get a text, or a push to your 2FA app. Meaning, it can't get scammed like this due to the fact that the site would tell you to put in your 2FA, but you couldn't receive your 2FA token since you actually didn't attempt to sign in.

    The scammers would get your login info, but they wouldn't actually be able to get into your account, due to the fact that they didn't get your token.
    (0)

  7. #7
    Player
    Canadane's Avatar
    Join Date
    Jul 2011
    Location
    Limsa Lominsa
    Posts
    7,499
    Character
    King Canadane
    World
    Hyperion
    Main Class
    Sage Lv 100
    Quote Originally Posted by Klaleara View Post
    If they hit the scammers website from their computer, the scammers could have gotten their IP. Just, nothing they could really do with their IP lol.
    Exactly, that's not "Hacking an IP" that's just seeing it.


    Quote Originally Posted by Avatre View Post
    That's also assuming the site that you are "logging" into has the spot to enter 2fa. If they don't, then there would be no way to get into the account. As I haven't even looked at those phishing links, I don't even know if they have a field for that.
    They do, a friend with the token has been compromised one drunken night he wasn't too smart. He assumed the site just auto-logs in to a client with the credentials without human intervention, which would make sense considering the speed which would be required to use the information.
    (2)

    http://king.canadane.com