I've just been scammed. The guy that logged into my account stole from me about 2m gp, a staff of armadyl, a dragon pickaxe, a ring of fortune and around 100 runite ore. I'm not a particularly valuable account, so he must have considered everything else in my bank as junk. The scam that he used isn't any of these listed. Here's what he did.
First, he used a smurf account to announce a "100m giveaway". He posted a video onto YouTube (search hip061, the video is still there as of the moment of posting this) announcing his "giveaway", along with a link to a RS Forum post.
Here's where things get confusing. If you follow the link, a genuine looking RS forum will open, down to the web link indicating on your browser that you're on a "services.runescape.com/m=forum" website. If you try to log into your profile, you'll be taken to a genuine looking RS website login screen, again the web link seems to indicate an actual RS forum services link.
Here's the part that where I should had suspected something was up. The login paged requested your username/email and password, as per normal, but then also requested your bank PIN and your Authenticator password. I should had suspected that something was wrong the moment these two were brought up, but I was blinded by what apparently were easy riches, so no dice. I should also note that my server connection to both Google and RuneScape went down after this for about half an hour.
I've logged into my account now to find those items I mentioned gone. I've already changed my password, bank pin and reset my authenticator, but the damage is done now. Safe to say that I'm not trusting "giveaways" ever again.
25-Jul-2018 19:32:44