Forums

Account Hacked - Wiped for 1b

Quick find code: 408-409-666-66283862

Lil_Chadito
Aug Member 2023

Lil_Chadito

Posts: 8 Bronze Posts by user Forum Profile RuneMetrics Profile
Welp, I got hacked over 1b in my account last night. I use Runelite, but I had an instance the other day where the Runelite client mentioned there was too many log in attempts (Red flag already). So after not being able to get in through the traditional method of runelite, I downloaded the jagex launcher, and logged in via the Runelite client option and got in just fine. The only thing that I think may have caused the hack, is due to me not making a jagex account prior to using the launcher. It still doesn't explain getting through the bank pin though. 2fa google authenticator as well. Plus an authenticator on my email as well. Couldn't imagine it being a keylogger, but you never know. I think it's the jagex launcher tbh.

20-Jul-2023 19:59:35

Tenebri
Jan Member 2015

Tenebri

Posts: 39,414 Sapphire Posts by user Forum Profile RuneMetrics Profile
if they got your bank pin, then they got the bank pin somehow, most likely through phishing attempt. it wont be a key logger as you dont type your bank pin in.

why do you think its the jagex launcher? especially by the sounds of it they already hacking your account before you even downloaded it.


also this is rs3 section, not osrs
200m all RS3 on 7/3/19
1.2Billion overall Slayer xp / Ultimate slayer title

OSRS 2277/2277 Untrim slayer cape
Hail Satan, He loves for who you are.

20-Jul-2023 21:32:14 - Last edited on 20-Jul-2023 21:34:28 by Tenebri

Lil_Chadito
Aug Member 2023

Lil_Chadito

Posts: 8 Bronze Posts by user Forum Profile RuneMetrics Profile
I think it may be the launcher due to not having a jagex account set up prior to logging in through the launcher. The only thing I can think of, not too sure how I would have a phishing issue since I never go through my emails or suspicious links either. Sucks to have so many hours of grinding just taken away overnight.

20-Jul-2023 22:29:20

Malua
May Member 2006

Malua

Posts: 43,113 Sapphire Posts by user Forum Profile RuneMetrics Profile
Check the 'Linked Accounts' tab in account management.
If you see any accounts linked in there, unlink them (including your own). Click on 'Manage Steam' to check for a linked Steam account.
It sounds to me like the hijacker has set up a backdoor login method via a linked account as this method does not trip Authenticator or your Bank PIN.

If only your own third party account is linked, review the security of your account on its other website as it is insecure.
Forum Community Helper -
Information about Moderators and Community Helpers

21-Jul-2023 01:01:14

Lil_Chadito
Aug Member 2023

Lil_Chadito

Posts: 8 Bronze Posts by user Forum Profile RuneMetrics Profile
I checked in there and I have no accounts linked whatsoever. All it says under there is Link with Google, Link with Apple, etc. I also clicked on 'Manage Steam' and sure enough osrs is not in my steam library nor is it linked. I'm assuming if they were linked, it would state the account information on that page too. So you're saying that using Runelite through the jagex launcher could cause issues? I'm just stuck here...

21-Jul-2023 04:16:16

Malua
May Member 2006

Malua

Posts: 43,113 Sapphire Posts by user Forum Profile RuneMetrics Profile
Original message details are unavailable.
So you're saying that using Runelite through the jagex launcher could cause issues?
No, we haven't said that.
It sounds like you had a problem before you started using the Launcher.

The next thing to check would be your device as you may have some malware that came via your old Runelite.

When you have a Jagex Account you get emailed and alerted about every login.
There is an 'end all sessions' button you can use on your Jagex Account if you get an alert about an unknown login.

The hijacker getting past a Bank PIN and Authenticator without removing them or knowing what numbers to enter is significant.
My first thought was that you had a linked account but you have checked and found nothing.
Unless your hijacker knows your Bank PIN and has physical access to your Auth code generator, the only other possibility is malware on your computer.
Forum Community Helper -
Information about Moderators and Community Helpers

21-Jul-2023 04:57:10

2_Tron

2_Tron

Posts: 23,025 Opal Posts by user Forum Profile RuneMetrics Profile
Original message details are unavailable.
Welp, I got hacked over 1b in my account last night. I use Runelite, but
I had an instance the other day where the Runelite client mentioned there was too many log in attempts (Red flag already). So after not being able to get in through the
traditional method of runelite
, I downloaded the jagex launcher, and logged in via the Runelite client option and got in just fine. The only thing that I think may have caused the hack, is due to me not making a jagex account prior to using the launcher. It still doesn't explain getting through the bank pin though. 2fa google authenticator as well. Plus an authenticator on my email as well. Couldn't imagine it being a keylogger, but you never know. I think it's the jagex launcher tbh.
This was the moment you got hacked/hijacked throwing you off guard unable to re-establish your connection with Jagex's Servers, making your 'traditional method' of playing work.

- remove all 3rd party software
- remove all 3rd party add-ons
- remove all 3rd party plugins
- scan your computer multiple times, see if there aren't left any 3rd party links
- scan your computer register for any malicious keys and remove them permanent in safe mode

I can't say it enough times but do use '
Jagex's Original RuneScape Game Clients
' to play RuneScape or OldSchool RuneScape to prevent from ending in situations like yours.
All that 'cheating/advantage' didn't pay you off but stabbed you in the back.

*edit 'see' removed 'behind'*

21-Jul-2023 07:49:10 - Last edited on 21-Jul-2023 11:57:32 by 2_Tron

Mrs Ana

Mrs Ana

Posts: 9,010 Rune Posts by user Forum Profile RuneMetrics Profile
Original message details are unavailable.
I checked in there and I have no accounts linked whatsoever. All it says under there is Link with Google, Link with Apple, etc. I also clicked on 'Manage Steam' and sure enough osrs is not in my steam library nor is it linked. I'm assuming if they were linked, it would state the account information on that page too. So you're saying that using Runelite through the jagex launcher could cause issues? I'm just stuck here...
In prior times, people were being hijacked because they were downloading pirated copies of RuneLite, which in turn allowed those hijackers to install malware on your computer to steal all of your personal information. Jagex then added a direct link to the official RuneLite website, which you may see below on the Old School RuneScape official website (
https://oldschool.runescape.com/
):



Now, it's fully integrated in the Jagex Launcher , which makes is more secure. I'd definitely scan your computer first and then migrate to a Jagex Account for the best security settings possible.

The Security tips Support article may also be of use to you.

21-Jul-2023 15:02:33

Lil_Chadito
Aug Member 2023

Lil_Chadito

Posts: 8 Bronze Posts by user Forum Profile RuneMetrics Profile
But if I'm not mistaken, isn't Runelite supported by Jagex? You can launch Runelite through the launcher no? I also did a full scan, and I took my computer into a tech shop to have it scanned; alas, no malware or viruses were found. So how do you explain that?

Regarding 3rd party software, again, if it's approved through Jagex, and I only use the default plugins, why is there still a possibility of this happening? If the Jagex launcher is the only thing I should be using, why does it even give me an option to use Runelite in the first place?

Again, this seems to be an ongoing issue with the Jagex launcher and I still believe this is 100% the reason why I got hacked in the first place. I did everything by the book, and yet this still happened 2 days after I download the launcher. What a bittersweet way to stop playing the game. So many hours to go down the drain because the security measures are a joke.

21-Jul-2023 19:16:51

Quick find code: 408-409-666-66283862 Back to Top