Another hacked account

jotmon

Well-known member
At this point i:m starting to believe this must be and iinside job and they know what's happening but have no Power/tools to stop It and that's the reason why they don't talk about It. It's not a coincidence that all the targeted accounts had quite some points and other stuff available. Someone that have/had access to their database must be at work. It's too fast, too precise and too widespreed to be a random hacker.
doubtful.

I've heard of instances of players logging in to their own accounts and ending up in someone else's character list with access to the others person's DDO store account.

Seems to me there's an obscure issue of securing player logins accounts to their character data and banking info that no one from SSG wants to talk about.
 

Solarpower

Well-known member
even as simple as just setting up Authy / Google Authenticator / whatever other 3rd party Autheticator app the user wishes to use.
Why do you think it's "simple" ?
The existence of ready-made authenticators is one thing. The main thing is how to connect them to the game ! But it may not be that simple.

SSG can't even make a simple server selection without having to restart the game. And here you are, talking about connecting a third-party app to the game... 🙄
 

Grumgrim

Member
I was probably on codemasters priginally but had to create a new usename when the accounts were transfered to US servers.

well it looks like i got the expected response from SSG about my account being accessed and drained: "Unfortunately, we’re not able to recover any coins or items that were lost. Please remember that keeping your account secure is the player’s responsibility"
so now have a compromised username and a system that allows brute forcing of passwords and no help from SSG, currently thinking I will continue to play for now but no more points, vip, or patron supports or big packs. Happy to spend money not happy to have SSG let others steal it

With the amount that I have heard happening its either easy or a member of SSG staff is doing it. Interesting thing is you have no idea if they have access to your account and have already checked to see if you have enough points or stuff available or a way to add more points. if you diddnt they could just log off and try next time double point and ottos are available
 

Grumgrim

Member
So got a response from Lead GM Woebot with a generic your fault this is how to do a secure password without addressing any of my concerns, I tried to respond but got "Your message wasn't delivered because the recipient's email provider rejected it"

So Ill start by post my response here, I previously asked for thier procedure for complaints and resolutions but that was missed/ignored

"
So you are 100% sure someone logged into my account using my username and password?
They didn't happen into by mistake as I have seen numerous reports off? And have even ended up doing myself at one point. ( Although I would never steal unlike others it seems)
Your system is not secure. I can do no more than I have to secure my account you will not allow me to even change my username.
There is nothing I can do with the tools you provide to stop someone re Accessing my account either by brute force or luck (considering how many people this is happening too I suspect people have found a way of increasing the chance of it happening)

Years of support buying every patron coffer, ultimate pack and VIP not to mention additional points means nothing when your system fails me?
I do not intend to let this go at the very least there should be something done to stop this happening.
Allow us to have separate password for the store, bind boxes to account. Something.

If nothing can be done I will look into what the next steps are.
Do you have any further escalation to this or is the end of your problem solving/complaint procedure?

Regards"
 
  • Like
Reactions: DBZ

Jummby

Well-known member
So got a response from Lead GM Woebot with a generic your fault this is how to do a secure password without addressing any of my concerns, I tried to respond but got "Your message wasn't delivered because the recipient's email provider rejected it"

So Ill start by post my response here, I previously asked for thier procedure for complaints and resolutions but that was missed/ignored

"
So you are 100% sure someone logged into my account using my username and password?
They didn't happen into by mistake as I have seen numerous reports off? And have even ended up doing myself at one point. ( Although I would never steal unlike others it seems)
Your system is not secure. I can do no more than I have to secure my account you will not allow me to even change my username.
There is nothing I can do with the tools you provide to stop someone re Accessing my account either by brute force or luck (considering how many people this is happening too I suspect people have found a way of increasing the chance of it happening)

Years of support buying every patron coffer, ultimate pack and VIP not to mention additional points means nothing when your system fails me?
I do not intend to let this go at the very least there should be something done to stop this happening.
Allow us to have separate password for the store, bind boxes to account. Something.

If nothing can be done I will look into what the next steps are.
Do you have any further escalation to this or is the end of your problem solving/complaint procedure?

Regards"
They are in full deny until you die legal mode, if what you say is true.
 

Grumgrim

Member
Further update - response from them

"Thank you for following up and for taking the time to outline your concerns in detail. I understand how upsetting this situation is, especially given the time and money you’ve invested into your account over the years. To clarify, after review, there is no indication that Standing Stone Games’ systems were breached or compromised in this case. All investigated incidents of account compromise have been the result of account credentials being exposed outside of our systems. This typically occurs through phishing attempts, reused passwords on third-party websites, malware or keyloggers on a local machine, or logging into non-official sites that request account details. While we understand the frustration around not being able to change a username, access to an account still requires the correct password. Without that password, a login cannot occur. For that reason, protecting and isolating your password remains the most effective way to secure your account. To help prevent this from happening again, we strongly recommend the following: • Use a completely unique password that is never used anywhere else (not forums, Discord, other games, or email accounts). • Create a password specifically for your SSG account and do not store it in browsers or password managers tied to shared devices. • Avoid logging into any website other than official SSG properties (the game client, MyAccount page, and forums). • Run regular malware and antivirus scans on your system to rule out keyloggers. • Change your password periodically, even if you believe it has not been exposed. Unfortunately, once points or items have been spent or removed as a result of an account compromise, we’re unable to restore or reimburse them. This decision is based on policy and is consistent across all similar cases. We understand that this is not the outcome you were hoping for, but please know your feedback regarding account security options has been documented and shared with the appropriate teams for consideration. If you have additional questions or need assistance with securing your account going forward, we’re happy to help. Thank you for your time and understanding"

so generic copy and paste ignoring my actual questions

my response

"This does not answer the question. I asked if they logged into the account or they ended up in my account which is an issue I have seen myself and is widely reported. It happens when logging in or logging out a character and you end up in someone else's account. This is a fault with your system not a breach of my username/password. If they logged in you should have logs and should be able to tell me if it was a result of knowing the password or brute forcing it with multiple incorrect attempts. Depending on the issue tells me if I can continue to spend money with you or if your security is too poor to continue. Please read and respond. I have repeatedly asked for your complaints and resolution procedure and that question has also been ignored. Please can you answer that"

This is my last attempt at nice, next step legal/regulatory bodies.
I was upset, now I am angry, repeatadly ignoring the questions is terrible, currently preparing posts for every social media outlet I can think of. If nothing else everyone who plays the game needs to know these vulnerabilities and that ssg cannot be trusted to have points loaded, items on your character or have certain payment options saved as they are not secure or safe
 
Top