Forums

Account hacked even with 2FA a

Quick find code: 408-409-444-66291647

MrSapperism

MrSapperism

Posts: 1 Bronze Posts by user Forum Profile RuneMetrics Profile
Hey everyone, I know this subreddit probably gets lots of posts just like this so apologies in advance.

I was just made aware that my account was hacked at least a few days ago. I logged in to find my character in a PVP area skulled, the most valuable items stolen and with an active membership.

I made the effort to change the password immediately (it was not changed by the hacker?). What puzzles me is that I had a pretty solid password and 2 factor authentication. However, I was not made aware that anyone had attempted anything.

I don't care too much that they took whatever valuables I had but I am puzzled as to how someone managed to break in and take my things even though I also had a bank pin enabled. I haven't played the game in maybe 2 years . I tried to see if I could report this incident to Jagex but their website isn't particularly helpful at all - rather its very confusing and seems anti consumer.

I guess what I'm trying to say is check your account every so often if you don't play for a while like myself and if anyone knows how this could have happened - i'd love to hear it so as to avoid it in the future. I did also try to gather details such as previous logins and banking receipts given they paid for a membership but to no avail.

In response to all this. I had upgraded my account to the new Jagex platform and made the new security changes such as new authenticator, password, pins etc. Due to my being away from Runescape for about 2 years or so, I wasn't aware of any of this.

Thanks for reading everyone.

10-Dec-2023 10:16:29

Malua
May Member 2006

Malua

Posts: 43,113 Sapphire Posts by user Forum Profile RuneMetrics Profile
Hi there
MrSapperism


You have now taken the necessary steps to secure your account when you upgraded it into a Jagex Account.
The Jagex Account was introduced at the start of 2023 so, if you hadn't logged in in a a couple of years, you would have missed its introduction.

I suspect the hijacker had set up a backdoor access pathway into your account. This backdoor access bypassed your existing security (password, Authenticator, bank PIN etc.), however upgrading into a Jagex Account has removed the hijackers backdoor access so your account is secure now.

How did the hijacker set up a backdoor login access?
They would have tricked you into giving them this backdoor access some time in the past two years. It would have been very cleverly set up so you weren't aware that you were being tricked.
Forum Community Helper -
Information about Moderators and Community Helpers

10-Dec-2023 13:03:22

Uhb Ygv 852

Uhb Ygv 852

Posts: 1 Bronze Posts by user Forum Profile RuneMetrics Profile
I was also hacked with 2FA and i am 100% certain there was no breach from my side in any way
i contacted support and they claimed that my 2FA code was used butt that is literally impossible
im almost certain there is a breach in security that jagex has not found

background: its not a jagex account, i was logged in literally the minute before i was hacked, i only had my devices logged allowed to use my e-mail, my code wasnt changed.

i was not phished
i do not have malware

16-Dec-2023 03:27:43

Malua
May Member 2006

Malua

Posts: 43,113 Sapphire Posts by user Forum Profile RuneMetrics Profile
Hi there
Uhb Ygv 852


If you were logged in immediately before it happened, were you forced out of the game by the hijacker?
If you were forced out of the game, it means your device has malware and your hijacker used that access to force you out.

Do you have your Authenticator set to ask for a code at every login or every 30 days?
It actually doesn't matter in a 'forced out of the game' hijack as the hijacker is entering the game on a continuation of your login so a new 2FA code is not required.

If you had logged out of the game already and didn't discover the hijack until you logged in later, I would suspect a different access method.
In this case, you should check the 'Linked Accounts' tab in account management and unlink any accounts you see linked (including your own). Click on 'Manage Steam' to check for a linked Steam account.

You really should consider upgrading your account to a Jagex Account. The security protocol is much stronger.
Article: Upgrade your RuneScape character to Jagex account
Forum Community Helper -
Information about Moderators and Community Helpers

16-Dec-2023 07:26:49

Quick find code: 408-409-444-66291647 Back to Top