1. July 1, 2021  

    Account compromised, Warmane doesnt care

    Hello guys,
    I just wanted to share my experience with you, how Warmane deals with compromised accounts. Yesterday my account got compromised, they didnt change my password. My character got moved without notifying me via email, they activated 2 factor security without notifying me. Now my character is naked and for sale in the Trading system.

    I wrote an email to the Warmane support, explaining this:

    "Hello dear Warmane support,
    My main account got hijacked (Kil******). They didnt change my password but they moved my main character (Wulfis) to some other account probably and they activated this mobile security code thingy on it. Can you please advise me what to do? I have made donations on that account, maybe it helps to retrieve the account over that payment information."

    This is what they replied, like they didnt even read the whole thing:

    "You can remove 2 Factor Authentication by email via the retrieve page. Select two-factor authentication removal within the drop-down menu,
    https://www.warmane.com/account/retrieve

    Your character is listed within the Trading system. You can cancel the sale via visiting,
    https://www.warmane.com/account/trade

    Select the realm your character is on via the left most drop down menu, change Buy to Sell in the right most drop down menu & then select Characters I'm Trading."




    Like wtf, I know that they dont care about lost items but they seem to not care at all. I highly recommend not donating to them, I really regret doing that.

  2. July 1, 2021  
    From what I understood, your email remains unchanged and you can restore it via the links provided.... So what's the issue here?

    If its not the case, try emailing again and clarify that the email has been changed.

  3. July 1, 2021  
    Ok the issue with the character not being on my account is solved, I didnt know that it gets removed from my character list if its for sale in the trading system.

    But the issue remains:

    How could they activate the mobile security without having access to my email account?

    Why didnt they change my password?

    Why the hell was my character naked with the gear in his inventory, at the time when he was for sale on the trading system?

  4. July 1, 2021  
    Looks like you neglected your account security and someone got the password. Be glad your email had different password. Enable in-game 2FA(no one will be able to log in game without access to your email)

    You have complete control to change passwords and 2FA, and everything. So what do you want staff to do? Secure your account so it doesn't happen again.

    It was naked on trade system because they selected option to sell without gear. Upon successful sale everything in your bags would have been deleted.

  5. July 1, 2021  
    I wanna find out how this 2FA could happen without me noticing it. Normally you would need access to the email and you would receive a notification. This did not happen, so why is this a problem on my side? This seems like a Warmane security problem.

  6. July 1, 2021  
    u got the account stolen witout u noticing lol
    they didnt do nthing that needed email u say urself that they used mobile auth
    y would u get notified? cause u didnt care for the account? u clerly knew 2fatuh existed but didnt use lol
    ur own fault the account got stolen n u trying to push blame on warmane like a bad parent blaming p0rnhub for letting their kid watch p0rn lol wah wah y didnt p0rnhub email me to see if my kid can watch p0rn roflol
    Edited: July 1, 2021

  7. July 1, 2021  
    It's almost as if account security is your own responsibility, as it states in the Terms of Service AND in a forum post here: http://forum.warmane.com/showthread.php?t=251692

  8. July 1, 2021  
    Jesus Christ, I already said it 2 times: How can these people, who compromised my account, even activate the 2FA without having access to my email account? Do you people even read the thread?

  9. July 1, 2021  
    Jesus Christ, I already said it 2 times: How can these people, who compromised my account, even activate the 2FA without having access to my email account? Do you people even read the thread?
    Because there's an option "Mobile authentificator" that doesn't require e-mail confirmation, but instead uses a code with about 30 second expiration timer on your phone to authenticate it. They downloaded the app on their phone, scanned the barcode while logged into your account and that's it. The 2FA is now on their phone. If you bothered securing your account, you'd know.
    And no, I didn't bother reading the whole thread because I can spot a QQ thread from your original post. It's everyone elses fault but yours, right?

  10. July 1, 2021  
    they used PHONE AUTH y would it need ur email
    u ever use any authenticator??? its ment to replace using email verification
    they had access to ur account cuz ur jesus didnt protect ur account in ur place n that let them turn 2fatuh on lol
    u not taking care of ur account is what cause all this stop trying to dig a way where its not ur fault

  11. July 1, 2021  
    Ok thanks dear Warmane community, you are wonderful people and always so helpful. You can go and enrich other threads with your outstanding analytic skills now. Or maybe dance in Goldshire with your lvl 1 nelf chars.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •