Xbox Live Fraud Probed By Microsoft 21
Several outlets are reporting on Microsoft's investigations into the possibility of hacking and fraud on the Xbox live service. After customer service complaints, rumours of hacked accounts, and allegations of mis-used credit card information, C|Net reports that the Microsoft has opened an investigation. At the very least, this will reassure frustrated customers. Kevin Finisterre has kept a log of his discussion with the 1-800-MY-XBOX folks and the service's ongoing problems. "Security researcher Kevin Finisterre was playing Halo on a recent night with several friends when some of their opponents threatened to steal their accounts, he said. 'Literally the next day my girl's account was locked out,' Finisterre wrote in an e-mail Tuesday. 'I received a message on my Xbox that said: "We are sorry we must log you out of Xbox Live because someone else is using your Gamertag."' The account was banned."
Rules of thumb (Score:5, Insightful)
Come soon WGA XBOX LIVE (Score:5, Funny)
Method? (Score:5, Interesting)
And since they're charming people, I have no qualms about posting their method here;
Now you may be wondering HOW do we get your information? its easy, you call 18004myxbox pretend to be that person make up a story about how your little brother put in the information on the account and it was all fake, blah blah blah you might get one little piece of information per call but then you keep calling and keep calling everytime getting a little bit more information every time. once you have enough information you can get the Pasword on the windows live ID Reset, they may tell you they cant but its bull shit. people at bungie CAN and WILL reset your password. believe me
So, sounds like a classic social engineering scheme, as opposed to 'hacking the system'. Even so, you have to wonder if phone reps really are giving out information, even if it is a small amount. Anyone tried getting information out of the phone reps yet?
Re:Method? (Score:4, Interesting)
I have a hard time believing whoever at tech support would be so unprofessional that they'd give you identifying information needed to reset something when you cannot produce it. For example in EverQuest the tech support seems to use the first credit card used on the account to determine password resets for hacked accounts. I've never heard of anyone ever able to convince them to give the first credit card number used on the said account no matter how often you call. If you don't know the CC number, they simply won't reset it for you. Maybe you can find out some other interesting info about the account, but they should never give you the info that'd reset the account just because you pester them long enough.
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
Keep doing it and eventually you'll get a customer service reps who just wants you to go away and will give you whatever you want.
Didn't you read the post? (Score:4, Informative)
Read the very post you responded to. The caller is askign exactly that, with the excuse that a brother or kid created the account with false info... in that context it sounds reasonable to ask what name they put on the account. I can easily see this tactic working.
Re:Method? (Score:5, Interesting)
Re: (Score:3, Informative)
Re: (Score:3, Insightful)
It's simple: find out who they are from the ISPs (all of them involved, ever), arrest them all, and charge them with everything you can. Surely they'll get off with a comparably light sentence, but hopefully they'll get sentenced strongly enough that this won't happen again.
Re: (Score:1)
After wandering around the links, I came across the following website; http://www.oinfam0uso.moonfruit.com/ [moonfruit.com]
FTFS:
THIS SITE HAS BEEN TAKEN OVER
T3am Hazard, OWNS Infamous
all they do is steal accounts + fuck with peoples shit
T3am Hazard Will now Be Helping Bungie + Microsoft Help find ALL THOSE WHO STEAL ACCOUNTS ALL NAMES WILL BE ADDED WITH IPS SOON. -Jokerz
Uh, Slashdotted?
Please Sony ... Nintendo ... (Score:2, Funny)
Same old story? (Score:3, Interesting)
I doubt this is much different from the trojans that target WoW accounts or the organised crime financed hackers that go for people's bank, paypal and ebay accounts.
Re: (Score:3)
So your grandma is more computer literate than a gamer? Hmmm...I don't think so. Not to mention that while a PC is more of an open system (even MS Windows is more open than the console), the console is definitely a little harder to break into as it doesn't allow the user to have administrative rights as easily, especially for downloadable content from a store like
Check the PCs (Score:3, Informative)
It is highly improbable that Microsoft's servers were compromised. Administering their own network is one of the few things they do relatively well.
Schwab
Re: (Score:1, Redundant)
Re: (Score:1)
Live website (Score:1)
I just hope I'll be able to download Symphony of the Night when I get home.