I just logged into my OSRS account, I haven't touched it in about a week.
Last time I played, I didn't have any membership left, and was in Lumbridge.
I just logged in to find I have 10 days of membership and I was in Clan Wars.
Super confused, suspecting I had somehow been hacked, I checked my bank. Sure enough, my bank pin was disabled and all my money is gone (a few million) as well as items including:
Amulet of Torture
Bandos Chestplate
Bandos Tassets
Abyssal whip
Primordial boots
Berserker ring (i) (I didn't even know it was tradable)
Robinhood hat
Smoke Battlestaff
All rune arrows
What I don't understand is that I have both 2FA and a bank pin set. How is it possible that they made it into my account without setting off any notifications that something was up? How did they log in without the 2FA? Why wasn't I notified that my bank pin was being removed?
Now I'm not even sure if its safe to play the account again. How can I ensure this can be prevented from happening again? How did this happen in the first place?
I don't share the account with anyone. I've never done any weird risky things like IRL trading or buying money or anything. I've only played from my one laptop and phone.
Thank you for reading. Please let me know if anyone has any answers.
23-Feb-2023 06:33:46