Page 3 of 4 FirstFirst 1 2 3 4 LastLast
Results 21 to 30 of 32
  1. #21
    Player
    Avatre's Avatar
    Join Date
    Jul 2017
    Posts
    2,852
    Character
    Avatre Drakone
    World
    Cactuar
    Main Class
    Dancer Lv 100
    Quote Originally Posted by Vidu View Post
    ...that sounds a lot like you've fallen for one of those scams that have been going on for a while now (and have gotten so bad that they posted an official warning on the Lodestone). For those scams, they'll get you to put in your one-time-password aswell as your normal one, so they can log in to your account. If this is indeed what happend, its still on you - not SEs fault that you rendered your secury token useless by giving away the information.
    99.9999999999999999999999% chance(screw it, it's 100% chance) that this is what happened.

    No official website for FF will EVER have anything between the .com and / It will ALWAYS be something like the two below.

    Official Lodestone(the na at the start could be eu, or whatever regional abbreviation is used for your region):

    https://na.finalfantasyxiv.com/lodestone

    Official forums:

    https://forum.square-enix.com/ffxiv


    Note how there is nothing between the .com and /

    Memorise that there is nothing between them...and if you see something with something in there...DO NOT CLICK! The person who sends you those tells is also a victim, who the culprit is hijacking their account to spread it while they steal the gil.


    Edit: Also, for anyone not aware, if you hover your mouse over a link in an email, or on a webpage, it shows the web address in the bottom left of the screen. Make sure it actually goes to where it says it goes, otherwise...don't click it(you can test it with the two I put in this post if you want)
    (3)
    Last edited by Avatre; 02-12-2021 at 02:28 AM.

  2. #22
    Player
    Takamorisan's Avatar
    Join Date
    Sep 2013
    Posts
    240
    Character
    Takamori Maruyama
    World
    Behemoth
    Main Class
    Marauder Lv 90
    Oh yeah received one of those scam messages.
    They basically send you to a mirror of the forums pretty well done btw, with fake GMs saying hey I want to participate in this raffle!
    My luck I was logged on the forums already, so I was able to avoid this.

    So moral of the story if some random dude invite you to some lottery stuff or whatever that requires you to log in at something. Avoid it at all costs.
    (0)

  3. #23
    Player
    Avatre's Avatar
    Join Date
    Jul 2017
    Posts
    2,852
    Character
    Avatre Drakone
    World
    Cactuar
    Main Class
    Dancer Lv 100
    Quote Originally Posted by Takamorisan View Post
    Oh yeah received one of those scam messages.
    They basically send you to a mirror of the forums pretty well done btw, with fake GMs saying hey I want to participate in this raffle!
    My luck I was logged on the forums already, so I was able to avoid this.

    So moral of the story if some random dude invite you to some lottery stuff or whatever that requires you to log in at something. Avoid it at all costs.
    It's not convincing enough if you've had to enter the OTP on the official pages. They aren't even on the same page as the username and password after all.
    (1)

  4. #24
    Player
    Takamorisan's Avatar
    Join Date
    Sep 2013
    Posts
    240
    Character
    Takamori Maruyama
    World
    Behemoth
    Main Class
    Marauder Lv 90
    Quote Originally Posted by Avatre View Post
    It's not convincing enough if you've had to enter the OTP on the official pages. They aren't even on the same page as the username and password after all.
    Like the mirror is the same as the forum UI, it show as you didn't log in yet to the forums and had that upper button in the top right telling you to log in, I didn't click it because I just had logged in the official forums, then I paid attention to the URL and I was like oh a f* scammer. I was really distracted, could had prevented by just not entering the link at all at least wasnt scammed, but still had to run Anti Virus, Spybot check registry alterations and so on. Changed my password and setup my one pass app finally...
    (0)

  5. #25
    Player
    Coletergeist's Avatar
    Join Date
    Apr 2020
    Posts
    500
    Character
    Cin Aamon
    World
    Diabolos
    Main Class
    Reaper Lv 95
    Quote Originally Posted by ElHeggunte View Post
    I know from personal experience. A few months ago some mysterious person seemingly joined my FC of his own accord and instantaneously took millions of gil from the FC chest the moment a member deposited it (happened within less than a second, according to the logs). They appeared to be a gil seller or bot; they were a level 1 paladin, nothing else even unlocked and had the same exact name and character across multiple servers. A cursory search of their name online also produced a similar event with someone else on a different world with the gil being taken in exactly the same way.
    This is why I have 'member' and 'veteran member' as ranks in my FC; new 'members' dont have access to gil for this very reason. Veteran members are members I trust and have been in the FC for at least a month or so. I cant and wont trust new members I dont know ever. Period.

    and I'm sorry you had to deal with that, too *^*. That must've sucked so freakin' bad.
    (4)

  6. #26
    Player
    Packetdancer's Avatar
    Join Date
    Oct 2019
    Location
    Gridania
    Posts
    1,948
    Character
    Khit Amariyo
    World
    Leviathan
    Main Class
    Sage Lv 100
    Quote Originally Posted by Takamorisan View Post
    Like the mirror is the same as the forum UI, it show as you didn't log in yet to the forums and had that upper button in the top right telling you to log in, I didn't click it because I just had logged in the official forums, then I paid attention to the URL and I was like oh a f* scammer. I was really distracted, could had prevented by just not entering the link at all at least wasnt scammed, but still had to run Anti Virus, Spybot check registry alterations and so on. Changed my password and setup my one pass app finally...
    What Avatre means is that the scam pages put the login/password and OTP fields on the same page; the web real login flow has the login/password (which is validated) and then put the OTP entry on a second page after that login, and only do so if you have a security token registered to the account.

    Since the scam pages can't do that first part of the login and present the OTP conditionally, they do it all on one page; when the user/password/OTP is entered, they can automatically log you in on game (thus booting you as a 'dead connection', like when you get disconnected and try to immediately reconnect) via what's basically a highway robbery bot. Since you can log back in quickly (and the OTP will expire so they can't get back into your account a second time without phishing the OTP from you again) they have to work very quickly to strip you of what resources they can in a seemingly wholly-automated manner. (As in, your gil can potentially be gone in under 20 seconds, sometimes even less.)

    As a side note, this is an excellent reason to use password managers. Yes, you probably know your FFXIV login/password by heart from entering it in the launcher, but if you hit 'fill from password manager' when you go to the forum login page... on the real site, it'll fill the username/password. On a phishing site... well, the password manager just sees that it's a domain you don't have a password saved for, and will go "Nope, don't have a password for here." Which can be enough to make you look at the address bar more closely and see that oh, you aren't on the real site.
    (6)
    Quote Originally Posted by Packetdancer
    The healer main's struggle for pants is both real, and unending. Be strong, sister. #GiveUsMorePants2k20 #HealersNotRevealers #RandomOtherSleepDeprivedHashtagsHere
    I aim to make my posts engaging and entertaining, even when you might not agree with me. And failing that, I'll just be very, VERY wordy.

  7. #27
    Player
    Valkyrie_Lenneth's Avatar
    Join Date
    Mar 2011
    Location
    Limsa Lominsa
    Posts
    8,038
    Character
    Lynne Asteria
    World
    Jenova
    Main Class
    Viper Lv 100
    Quote Originally Posted by Coletergeist View Post
    This is why I have 'member' and 'veteran member' as ranks in my FC; new 'members' dont have access to gil for this very reason. Veteran members are members I trust and have been in the FC for at least a month or so. I cant and wont trust new members I dont know ever. Period.

    and I'm sorry you had to deal with that, too *^*. That must've sucked so freakin' bad.
    Wow, you give players access to gil after a month? Even in my fc of people we've known for years. Pretty much all of us have met irl. Only 3 of us have access to gil, and only 2 of us have certain housing access.


    2 of them are married, and only 1 and me have the access lol.
    (4)

  8. #28
    Player
    ElHeggunte's Avatar
    Join Date
    Aug 2013
    Location
    The Nation of Domination
    Posts
    1,466
    Character
    Naiyah Nanaya
    World
    Diabolos
    Main Class
    Monk Lv 100
    Quote Originally Posted by SilverSp View Post
    i didnt spend it on anything my account was compromised and yes my account always had a security token it was a data breach when i logged in i was in a different world with no gil left in my account
    Okay then. I still don't understand why you made this thread. We can't do anything besides tell you to wait on SE to do their thing and to not get phished again in the future. SE has always taken a long time to do the rollback process and complaining about it on the forums won't make it go any faster.

    Quote Originally Posted by Coletergeist View Post
    This is why I have 'member' and 'veteran member' as ranks in my FC; new 'members' dont have access to gil for this very reason. Veteran members are members I trust and have been in the FC for at least a month or so. I cant and wont trust new members I dont know ever. Period.

    and I'm sorry you had to deal with that, too *^*. That must've sucked so freakin' bad.
    Yes, lesson learned. I immediately adjusted the default rank to have practically zero permissions and demoted anyone who hadn't logged on in a while just to cover the chance of compromised accounts. I had never bothered to tighten permissions after I inherited leadership because I trust everyone in the FC just like the original leader and we never kept gil in the chest to begin with. By this point there were only three of us anyway, including the person who had their gil stolen (they had only been back a week too, but that's an entire story unto itself). I just never imagined that a gil seller would get into the FC and manage to take gil from the chest a literal second after it was deposited.
    (3)
    With this character's death, the thread of prophecy remains intact.

  9. #29
    Player
    VelKallor's Avatar
    Join Date
    Jan 2021
    Location
    Limsa Lominsa
    Posts
    2,590
    Character
    Vel Kallor
    World
    Kujata
    Main Class
    Red Mage Lv 100
    I asked a GM if they could restore a deleted character ( yes yes I know I was a doofus and should have just left it there ), amazingly they did it.

    Ive had a few tickets and have been delighted with their responses and help.

    Cant be happier TBH.
    (1)

  10. #30
    Player
    Kes13a's Avatar
    Join Date
    May 2020
    Location
    Gridania
    Posts
    2,842
    Character
    Etherea Stormaire
    World
    Zalera
    Main Class
    White Mage Lv 100
    considering how many people fall to the scammers, even though SE has posted NOT to...

    this is not a data issue, this is you voluntarily making a mistake. yeah, I imagine they have to investigate it fully. I am sure they are also making sure your account wasnt used for anything illegal since someone else now has all your information.

    sorry you arent getting satisfaction, here or by CS, but really, who in their right mind clicks on or goes to a link from a rando player and enters information? was it the need to go for the millions of gil? as we all hear, if something seems to good to be true.. it often is. next I am sure we'll hear your bank account is empty because you were trying to help some african prince/diplomat/business person get their millions out of the country....
    (4)

Page 3 of 4 FirstFirst 1 2 3 4 LastLast