Page 1 of 2 1 2 LastLast
Results 1 to 10 of 16

Hybrid View

  1. #1
    Player
    Rehayem's Avatar
    Join Date
    Aug 2019
    Posts
    754
    Character
    Yasu Naoya
    World
    Malboro
    Main Class
    Gunbreaker Lv 100

    Beware: new phishing attempts

    I thought of making this post because scammers and hackers are trying now a different way to steal your account with the typical giveaway or raffle of sorts.

    All names will be blacked out in accordance with Terms of Service. This is for educational purposes only.

    First and foremost, they will send you a tell, however this time it will be linked to somewhere else, now a safe website we know: in my case, it was official Twitch website.

    While looking at this, you might be compelled to agree this looks legit.


    Looking further into their "About" page, it shows an actual forum link.

    Before you even attempt to click this, this is an obfuscated link to make it look legit. The moment you hover over the link, you will see the real one. Going to the actual forum link leads to nowhere.


    Analyzing it with VirusTotal shows exactly how it behaves, marked by multiple antiviruses as malware. This "website" redirects to a fake forum copy with those strange links that tend to end in .com-h.nl or something similar.

    This is not a safe forum website. This is a phishing link meant to steal your account since it also bypasses 2fa


    Remember kids, if it looks too good to be true, it probably is. Never click those links. They will use safe websites to lure in people, stuff like Twitch, Youtube, even Carrd websites.

    Thanks for coming to my TED talk. Stay safe out there.
    (17)
    Last edited by Rehayem; 01-09-2025 at 02:46 PM. Reason: updated images

  2. #2
    Player
    Jeeqbit's Avatar
    Join Date
    Mar 2016
    Posts
    7,403
    Character
    Oscarlet Oirellain
    World
    Jenova
    Main Class
    Warrior Lv 100
    It's an interesting change of tactic, but the victims are usually not active members of this forum.

    They are mostly new and casual players that would have never visited the forums before. People who visit the forums regularly normally know all about this already.

    It's purposefully aimed at people who think there is something to see on the forums but who have never actually visited them before.
    (1)

  3. #3
    Player
    Rehayem's Avatar
    Join Date
    Aug 2019
    Posts
    754
    Character
    Yasu Naoya
    World
    Malboro
    Main Class
    Gunbreaker Lv 100
    Quote Originally Posted by Jeeqbit View Post
    It's an interesting change of tactic, but the victims are usually not active members of this forum.

    They are mostly new and casual players that would have never visited the forums before. People who visit the forums regularly normally know all about this already.

    It's purposefully aimed at people who think there is something to see on the forums but who have never actually visited them before.
    That is true, however it doesn't stop having this post eventually end up in the search engine in case anybody is ever confused or unsure. Spreading the word about this new phishing attempt can also help curb potential attempts of theft.
    (1)

  4. #4
    Player
    hydralus's Avatar
    Join Date
    Jun 2016
    Posts
    1,073
    Character
    Keiho Fukiku
    World
    Balmung
    Main Class
    Warrior Lv 50
    They put a warning about these phishing attempts every time you log in.
    (6)

  5. #5
    Player
    Rehayem's Avatar
    Join Date
    Aug 2019
    Posts
    754
    Character
    Yasu Naoya
    World
    Malboro
    Main Class
    Gunbreaker Lv 100
    Quote Originally Posted by hydralus View Post
    They put a warning about these phishing attempts every time you log in.
    Yes, but the previous tells were linking directly to the fake forums. These new attempts are meant to lure you into a trusted website (like Twitch) to fool unsuspected people who may not be that tech savvy or understand it's all a facade.
    (0)

  6. #6
    Player
    hydralus's Avatar
    Join Date
    Jun 2016
    Posts
    1,073
    Character
    Keiho Fukiku
    World
    Balmung
    Main Class
    Warrior Lv 50
    Quote Originally Posted by Rehayem View Post
    Yes, but the previous tells were linking directly to the fake forums. These new attempts are meant to lure you into a trusted website (like Twitch) to fool unsuspected people who may not be that tech savvy or understand it's all a facade.
    The in-game warning says, "If you receive a Tell containing a URL to a website from a random player, please check the contents carefully since there is a high possibility that it is a phishing site." Which covers every case. Going even further than that, they link to a lodestone post that gives several examples, including the one OP is talking about. All of the information is there every time you log in if people bother to read.
    (2)

  7. #7
    Player
    Rueby's Avatar
    Join Date
    Feb 2022
    Location
    Zenos' Pockets
    Posts
    836
    Character
    Vera Nova
    World
    Spriggan
    Main Class
    Gunbreaker Lv 90
    Honestly...
    'if it sounds too good to be true' it very much is.

    Thanks for this tho
    (0)
    Eyestrain thread - https://forum.square-enix.com/ffxiv/threads/501914-Dawntrail-Graphics-Update-Eye-Strain

  8. #8
    Player
    FudoMyoo's Avatar
    Join Date
    Nov 2014
    Posts
    325
    Character
    Fudo Myoo
    World
    Tonberry
    Main Class
    Paladin Lv 100
    I received a link in the FC warning about a phishing scam related to voting for FF14 as GOTY.

    Without reading it carefully, I copied the link to my browser and stupidly logged into my SE account as a loyal fan. Five minutes later, my internet went down, and I assumed it was an ISP issue. As I prepared for bed, a friend texted my wife, saying I had logged in and abruptly left the FC. Using mobile tethering, I regained control of my account, but I still lost 100 million gil.

    Lesson learnt. lol
    (0)

  9. #9
    Player
    Regis_Paran's Avatar
    Join Date
    Jun 2022
    Posts
    104
    Character
    Asane Paran
    World
    Shiva
    Main Class
    Bard Lv 100
    Quote Originally Posted by FudoMyoo View Post
    I received a link in the FC warning about a phishing scam related to voting for FF14 as GOTY.

    Why would they include an actual fraudulent link in the warning?...
    (0)

  10. #10
    Player
    WinglessSeraphim's Avatar
    Join Date
    Aug 2021
    Posts
    184
    Character
    Apterous Angel
    World
    Sagittarius
    Main Class
    Paladin Lv 100
    Quote Originally Posted by Regis_Paran View Post
    Why would they include an actual fraudulent link in the warning?...
    My guess is to weed out the idiots.
    (0)

Page 1 of 2 1 2 LastLast

Tags for this Thread