Forums

Jagex Account hacking.

Quick find code: 278-279-360-66291777

GOSS_ReapZ
Dec Member 2021

GOSS_ReapZ

Posts: 4 Bronze Posts by user Forum Profile RuneMetrics Profile
Hello, I logged in today and noticed that all my items were missing. However that isnt the main topic of this thread. I did some digging to see if i can determine how this could have happened as I enable 2fa on all of my accounts. email/rs anything that uses it. I dont share my pc or any passwords & have never had any issues with losing an account.

My main focus here is on the 2fa system and the new jagex accounts. I just today created my jagex account when i logged back into my account after months. Noticing when i did this it never asked me for my 2fa code to actually link the account. It automatically allowed me to link the account without entering my previous password/2fa code/anything else. It seems it automatically links it based on the email that is connected to the account. My question for everyone is this.

Is allowing you to bypass all security measures on the runescape account and automatically linking it to a jagex account really a safe way to do this? It seems to me that there should be more verification that the person creating the new jagex account really is the same as the person with the runescape account. Yes they have to have access to the email to do this but why allow us to put 2fa on rs accounts if you just ignore it when creating the new jagex accounts & linking the characters?

Just some thoughts & frustrations i had after my experience logging in today & finding i have to start my maxed account over from 200k gold :)

13-Dec-2023 01:38:57

Mrs Ana

Mrs Ana

Posts: 8,998 Rune Posts by user Forum Profile RuneMetrics Profile
Hey, GOSS_ReapZ.

When upgrading to a Jagex Account , you are required to log in to your account first. While doing this, if you have 2-Step Verification enabled, it'd be prompted at this stage. Once you have authenticated this step, I don't believe that there is a need to authenticate the account again prior to upgrading to a Jagex Account. Remember that Jagex wants to make it as easy as possible to upgrade so that other players are encouraged to do so.

( Eventually, the plan is to make it mandatory for every single player out there. Right now, you aren't forced to upgrade yet, but if you wish to use the Jagex Launcher, it can only be used with a Jagex Account. Other than that, you are required to download the standalone clients to play .)

Once you get to that stage, you are required to select an email address and password. The email address does NOT have to be the same email address that you use for that specific account, if the account was created after November 2010. Accounts created prior to November 2010 required a username and password. I'd select a new Google Mail account for the Jagex Account. You'll then get a verification code sent to that NEW email for the Jagex Account. After you enter it, you will then be able to import other characters/accounts if you so desire.

The Jagex Account system requires you to have 2-Step Verification enabled at all times. You can have the Authenticator app; codes via email; or both. You'll also have the option to have Backup Codes. Those are highly recommended just in case you lose access to both your authentication methods mentioned above. Jagex Accounts cannot be manually recovered for security reasons.

In any case, all the information about Jagex Accounts may be found below:

https://help.jagex.com/hc/en-gb/categories/4403516390801-Jagex-Accounts

13-Dec-2023 15:43:45 - Last edited on 13-Dec-2023 15:48:09 by Mrs Ana

Quick find code: 278-279-360-66291777 Back to Top