It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
avatar
phaolo: So many hacked accounts.. how is it possible?
Wait, they haven't used cracked Witcher3 games, right? XD
avatar
HertogJan: 1. PC with malware.
2. "GOG Galaxy" downloaded from another site than GOG.com. Someone recently posted a link to a page on malwarebytes.org warning for fake clients with malware.
3. Same combination of password, e-mail and username as on other sites/forums. Either 1 or more of those got hacked or the people behind it abuse account info.
The fake client is a generic malware / trojan which is used for many software products. I think it is 3 or 1 (but have not seen a specific malware for GOG).
avatar
phaolo: I don't remember and I can't find it again, sorry.
avatar
apehater: i can't remember too, that a known forum user account was hacked. that only new accounts are hacked is suspicious and reminds me of the "witcher removed from account" threads one month ago.
It has not been just new accounts, its been new and old accounts, but most of them are relatively inactive accounts. A lot of them seem to be users who have "come back" for TW3 only to discover their account has been hacked. The most likely scenario seems to be the "same password used on multiple sites" issue, combined with a compromise of a different unrelated site that exposed those passwords.
avatar
Ciris: Hi!

First off, I'd like to apologise to all who have experienced account hacking on our site over the past couple of days. We're hard at work to make this less of an issue and less likely to happen - but I understand how frustrating it must be to lose access to your games.

Having said that, there's a new measure that will help us pick up on hacked accounts more easily.

If your account e-mail changes, you will get an automated message.

It that looks like this and has the new e-mail address, the old one, the IP currently in use (together with estimated location), and the OS and browser of the current user.

If you get such a message and it wasn't you who changed the email address, contact us.

Use the link at the end of the message ("contact our support team") to let us know it happened. You'll be redirected to our contact form - here's an example of how to fill that in.

We do our best to get back to hacked account emails as soon as possible, and to change the e-mail addresses as quickly as we can and restore the fully functional accounts to their rightful users.

IMPORTANT:

1) When contacting us regarding a hacked account, you must replace the e-mail address with one you have access to - otherwise, our reply will end up at the hacker's e-mail address, which you have no control over or access to.

2) Please do not send multiple requests to support - if you do, your request is pushed to the back of the queue again. If you feel the need to add more details to your support request without getting bumped back, you can do so by replying to the automated support reply you will get with your Ticket ID.

3) As soon as you get access to your account back, please change your password. It may be a simple thing, but please don't forget. It will mean the hacker once more lost access to your account for sure.
This is a great start, but the bigger problem is you guys seem to reset the password back to its original when restoring an account. If the real account owner is not sitting on their E-mail waiting for the password, the hijacker can just get right back in. You need to institute a system of resetting the password to something random instead of re-using the old password. You also need to get serious about two-factor authentication. No major site these days doesn't at least offer that as an option.
Post edited June 18, 2015 by cogadh
high rated
avatar
Ciris: 3) As soon as you get access to your account back, please change your password. It may be a simple thing, but please don't forget. It will mean the hacker once more lost access to your account for sure.
This is just dumb. You should be setting a new password and sending that to the true owner.
avatar
Ciris: 3) As soon as you get access to your account back, please change your password. It may be a simple thing, but please don't forget. It will mean the hacker once more lost access to your account for sure.
avatar
madth3: This is just dumb. You should be setting a new password and sending that to the true owner.
Sending plaintext passwords is also not good.They should provide a reset link.
avatar
apehater: did this happen to a known forum user or only to new gog accounts?
avatar
HertogJan: Highest rep I've seen on those posting on the forum about it, was 8. I might have missed some of the threads though.
The other day, it happened to someone registered in 2012 who never posted on the forum. So not a known user, and not a new account either.
high rated
avatar
DanielRuf: Sending plaintext passwords is also not good.They should provide a reset link.
I know but it's better than the current thing and it can be started right away.

If they wait to implement reset links, this won't be changed until christmas. :/
avatar
HertogJan: Highest rep I've seen on those posting on the forum about it, was 8. I might have missed some of the threads though.
avatar
Potzato: The other day, it happened to someone registered in 2012 who never posted on the forum. So not a known user, and not a new account either.
Btw, why do these "hackers" even change the email?
The smartest evil thing would be to leave all untouched and then download everything..

Ugh wait.. maybe they're doing it, but tried the swap only with easy accounts.. +_+
high rated
avatar
phaolo: Btw, why do these "hackers" even change the email?
They're selling the accounts. There has been a user or two who said the got the account from a "friend".

If they only wanted the games, they could get them easier, probably.
avatar
Potzato: The other day, it happened to someone registered in 2012 who never posted on the forum. So not a known user, and not a new account either.
avatar
phaolo: Btw, why do these "hackers" even change the email?
The smartest evil thing would be to leave all untouched and then download everything..

Ugh wait.. maybe they're doing it, but tried the swap only with easy accounts.. +_+
Because you can change the email with just a password, but you can't change the password without the email, so they change the email to one the hijacker controls, then they change the password and lock the real account owner out.
Hmm, I'm logged in (obviously, as i can post) but at the top of the site I'm invited to sign in or sign up. There is no account bar.

Very strange
avatar
Huff: Hmm, I'm logged in (obviously, as i can post) but at the top of the site I'm invited to sign in or sign up. There is no account bar.

Very strange
Same here. It wasn't like that earlier today. Something odd going on.
avatar
Huff: Hmm, I'm logged in (obviously, as i can post) but at the top of the site I'm invited to sign in or sign up. There is no account bar.

Very strange
Did you reload and sign in again? I see the bar at the top.
high rated
avatar
Huff: Hmm, I'm logged in (obviously, as i can post) but at the top of the site I'm invited to sign in or sign up. There is no account bar.

Very strange
Old bug, it has been spotted at least twice in the past. (And, supposedly, fixed)
avatar
Huff: Hmm, I'm logged in (obviously, as i can post) but at the top of the site I'm invited to sign in or sign up. There is no account bar.

Very strange
avatar
madth3: Old bug, it has been spotted at least twice in the past. (And, supposedly, fixed)
Didn't realize this was a known bug, not seen it in all the time Ive been here !
high rated
avatar
Huff: Didn't realize this was a known bug, not seen it in all the time Ive been here !
It doesn't happen all the time and not to all the users. As I said, it was supposed to be fixed.
:-)

Oh, and just because it has been seen before doesn't mean you should just shrug it. You can sent support a ticket about it.
Post edited June 18, 2015 by madth3