Forums

Hacked, Jagex leaking info? Thread is locked

Quick find code: 408-409-143-66256948

Smokiemouse

Smokiemouse

Posts: 12 Bronze Posts by user Forum Profile RuneMetrics Profile
Hello,

First I'll describle my experience. I recently broke my cell phone by forgetting it in my pants before washing. Yes that is already painfull but the story doesn't end here. With my new phone in hand, I desactived my authentificator for 1 day to set a new one on my new phone and BOOM, account hacked the same day. Everything gone in my bank.

Now, how is this possible ? This is beyond odd. How did the hacker know my authentificator just got disabled and that today was the only day he could hack it ? How did he have my password ?? Before you ask, no I don't use 3th party program, never shared my password and my email adress is double securised.
All I can think of is :
- Jagex is leaking personal data or that one of their employee is the hacker.

Now I try to get my items back but I only get silly answers like ''you must secure your account'' or ''we can't refund lost items in OSRS''. In only 1 day, the hacker got the info my account wasn't protected anymore by my authentificator and got his hands on my password.

Did you have a similar experience ? Could some1 explains to me how this is possible ?
This is way too weird to be a simple coincidence.

05-Jul-2022 22:19:58

Corder
Oct Member 2017

Corder

Posts: 27,893 Sapphire Posts by user Forum Profile RuneMetrics Profile
The hijacker probably knew the Login and Password for days, weeks maybe even months.
Try to think back in time, and check old messages with people who also play Runescape, as well as your email for any hints as to who might know your login and password.

Did your account have a bank PIN prior to the hijacking?

There hasn't been any database breach or similar hijackings reported recently.
If there was a hijacker inside of Jagex, we would see a greater volume of reports of probably rich and "special" accounts getting ruined.

There are tips on security here. It also goes over social engineering, phishing etc. https://support.runescape.com/hc/en-gb/sections/4476448948497-Getting-secure
Life is like a camera: Just focus on what's important, capture the good times, develop from the negatives, and if things don't work out, take another shot !

06-Jul-2022 00:08:29

Smokiemouse

Smokiemouse

Posts: 12 Bronze Posts by user Forum Profile RuneMetrics Profile
This is exactly my point. It's so weird that the hacker knows my username and password. I only use those on rs. No old posts either, I can guarantee that since I'm a solo player.
And no, I never thought I would need a bank PIN because I had an authenticator.

Did you say reported recently? So that means there has already been a database breach? This is an old account so that would explains everything. Now the question of how they knew I disabled my authenticator remains. And if Jagex is at fault, what are my rights ?

06-Jul-2022 01:57:26

Corder
Oct Member 2017

Corder

Posts: 27,893 Sapphire Posts by user Forum Profile RuneMetrics Profile
I'm not aware of any database breach. But a Jmod was fired a few years back for messing with a number of player accounts. It was all over the news then. That's not really relevant here though but for the record that is what happened and has been all reversed :P

If I were to guess. What gave the hijacker your login and password could be.
a phishing website scam
a phishing email scam
reused credentials on private servers
reused credentials in other websites that has had a breach
shared the account at one point
kept the login information documented somewhere accessible by someone else

Btw - having a bank PIN acts as a second bank authentication in the event that 2FA gets bypassed. That's not to say 2FA as PIN isn't great, but it has its disadvantages over regular PIN.
Life is like a camera: Just focus on what's important, capture the good times, develop from the negatives, and if things don't work out, take another shot !

06-Jul-2022 12:23:18 - Last edited on 06-Jul-2022 12:25:18 by Corder

The contents of this message have been hidden

07-Jul-2022 18:54:06

Kathy
May
fmod Member
2011

Kathy

Forum Moderator Posts: 20,217 Opal Posts by user Forum Profile RuneMetrics Profile
Hi
C44
,

Sorry to hear about your issue!

It seems you have already received some advice on your current thread here . Please focus on your efforts on your already existing thread as it helps keep the help you've received in one place.

Best,
• Kathy •


Forum Help Sticky
|
Sailor Neptune
|
Forum Community Helper

07-Jul-2022 21:04:56

Ladyolake
Jan Member 2008

Ladyolake

Posts: 7,111 Rune Posts by user Forum Profile RuneMetrics Profile
Most players never expierence a hijacking.

If it were Jagex lax.. then there would be thousands of people on here and every social media you can find bitchin.

As it is, its about same as any other week.

I wish you luck.
The richest person is not who has the most. It is who Needs the least.

08-Jul-2022 14:12:41

The contents of this message have been hidden

08-Jul-2022 18:05:43

97
Nov Member 2017

97

Posts: 15,834 Opal Posts by user Forum Profile RuneMetrics Profile
Often things like facebook or other corporates get data breaches, you may have used a similar email and password elsewhere. Hackers have gotten very smart and that's why I always preach using password specific accounts, never reuse an email or password for your accounts as you risk a data breach.

A Bank pin is essential in 2022, it may be a hassle but it at least gives you a buffer period if you were to get an unwanted guest on your account.

To assume Jagex is a fault is simply not the answer. I would suggest looking on the web to see if you had emails or passwords that are commonly used that have been breached on 3rd party sites.

I would check to see if your account has been linked with a hackers email or login. Check to see if you have been linked to a 3rd party login.

You can check by logging in on the website > My Account > Linked Accounts. Jagex provides 5 options to link and login . Make sure none of these options have been linked if you have not done so.

Best of luck ! :) :)
20 Year RS Veteran|OSRS Player
@RSN_97
Support Centre | Forum Help

08-Jul-2022 18:42:48 - Last edited on 09-Jul-2022 01:25:44 by 97

Quick find code: 408-409-143-66256948 Back to Top