« Calling all space engineers | Main | N^2 »

Sep 08, 2005

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c022953ef00d8345915b669e2

Listed below are links to weblogs that reference Virtual World Phishing:

» MMORPG Phishing Scams from Privacy and Security Law Blog
As an update to our previous post on the keylogger worm that attempts to steal account data from players of Massively Multiplayer Online Role Playing Games, an interesting report at Terra Nova about a phishing scam designed to steal the... [Read More]

» loan online from equity loan
Loans Home Equity Loans - Home Mortgage Student Loans [Read More]

» This Prairie Home is a bit of a rambler - USA Today from Seattle Post
1 hour ago By Claudia Puig, USA TODAY. Those who have listened avidly to Garrison Keillors radio shows are most [Read More]

» American Auto Guardian Utilizes StoneEagle's SEcureCard Solution to Automate their Claims Payment Process from with Paying Claims
URI: http://www.prweb.com/dingpr.php/U3F1YS1TaW5nLVRoaXItRW1wdC1JbnNlLVplcm8= [Read More]

» From TweakXP comes FireTune from new freeware
of various performance tweaks rolled into one little freeware applet, making it easier than digging [Read More]

» Barr to refile Plan B contraceptive application from and older from
Barr which had sought to sell the drug to women 16 and older. [Read More]

Comments

1.

Ebay? IGE, more likely.

2.

This isn't new by any means. Usually scams like these will direct users to a website that appears to be run by the MMORPG company in question and presented with a login screen. Accounts who are collected then are cleaned out of any liquid assets.

Variations on this theme include "You have been selected for our new beta!" and "You've been given a free account! Click here to set up."

Our always amusing Internet Relations Manager has at times made a game out of warning our users of these:

http://www.camelotherald.com/more/228.shtml
http://www.camelotherald.com/more/359.shtml
http://www.camelotherald.com/more/681.shtml
http://www.camelotherald.com/more/692.shtml
http://www.camelotherald.com/more/786.shtml
http://www.camelotherald.com/more/815.shtml
http://www.camelotherald.com/more/1740.shtml
http://www.camelotherald.com/more/1747.shtml
http://www.camelotherald.com/more/1882.shtml

3.

Hm, links should really auto-HTML themselves. :)

4.

"To secure your account and quickly restore full access, we require you to login in you account .This process is mandatory, and if not completed within the nearest time your account may be subject for suspension or will be banned"

I love how these scamming nerds can go out of their way to punctuate and spell correctly for the first few paragraphs, and then you inevitably see lapses such as the paragraph I just quoted. There's about 5 serious errors in it, and even though EVE's team is from Iceland (which results in the occasional typo in its game), the scammers are losing a fair portion of their targeted fishies by not investing 60 more seconds of their time in some proofreading.

5.

No surprise that phishers are looking for other lucrative markets, but thanks for posting the info so that these scams don't take people off-guard. Worth an update to the recent post we did on our blog about worms and other malware that attempt to steal such account info -- thanks!!

7.

Since I don't have an EVE account, I felt safe clicking on the link. Doesn't work; you get a 404

8.

On a completely unrelated note (I wish I could submit stuff to TN): Ex -WoW devs form a new company and are looking for talent.

9.

This type of phishing email showed up rather frequently in Everquest as well. Like DaoC, the Community Rep would generally post a sample and remind everyone that this sort of email would never be sent out.

10.

This is nothing new. I remember various phishing techniques (in-game, on the forums, and email) being used in the early Runescape beta. This would have been about four years ago.

11.

In Diablo 2, phishers tell noobs to check their stats by whispering their account name and passord to a third-party member (someone with a registered name of like "BlizzTech" or "BlizzStats"). While this is common, it is interesting the lengths to which some phishers will go. It seems as if the one who wanted your account is very devious. I expect means of phishing will only get more subtle.

12.

Man, you think that's bad? The other day, someone attempted the first scam in a VW on me. It was unreal. I guess it goes to show how valuable in-game items are to some people!

13.

"Expect more attempts in other MMORPGs in time."

In fact, this has been going on for year(s) already and is not really new. But yes, it is increasingly becomming problematic. In south korea, http://www.zdnet.com.au/news/security/0,2000061744,20277029,00.htm>over 50% of the cybercrimes involve games and the selling game money to launder the ill gotten money.

And why would we be surprised? With all the impressive quotes about the total value going on in what's called the secondary market of MMORPG's, something like this could only be expected.

14.

Runescape is plagued with these scammers. Every time there is a game update people will start saying something like "the new update blocks your password when you typre it. Look! ******" And with fansites like Rune Tips people are always sending out e-mails to players with spoofed e-mail adresses from "jagex.com". Also some people have been puting keyloggers in image files and putting them in there signatures on fansite forums.

The comments to this entry are closed.