Friday, November 4, 2011

World of Warcraft - Account Investigation‏

A friend of mine forwarded this one to me and it is very clever. I'll add what he had to say about the email after he looked a little closer and even contacted Blizzard to verify.
-------
Just got this recently. A truly clever one. Looks VERY official... to the point of where I forwarded it to Blizzard just to verify. The only thing that is strange about this one is that it's from the "EU" division (Europe). All reference links are legitimate, but the one you are expected to use to take action is disguised.

While the link visibly says it takes you to "us.battle.net" if you right click the link and select "copy link location" then paste it in a document it says; **my email info removed**/dereferrer/?target=http%3A%2F%2Fus.battle.1ognin.net%2Flogin%2Fen%2Findex.htm%3Fref%3Dhttps%253A%252F%252Fus.battle.net%252Faccount%252Fmanagement%252Findex.xml%26app%3Dbam

Notice the portion I highlighted, one it's not the address visibly shown, and two it's faked to look like something official where 2Fus.battle is different and word "login" is spelled with a number 1 not a lower case L (Certain fonts make it hard to tell the difference. This example is easy because they didn't change the L in battle to match the 1 in Login.) Hyperlinks are useful tools but can be used to redirect you without your knowledge.
-------

And here is the email he received..


It is a very clever fake that almost any unsuspecting World of Warcraft user might fall for. By clicking on the link you would be sent to another fake page asking you to log in with your account details and the information you enter would be sent to the person responsible for this scam giving away your account info and costing you your account. (I can't show you the example of the page because it has already been taken down after being reported as fraud)

Maybe you're not a gamer and cannot possibly understand why someone would want to steal a World of Warcraft account. It's just a game right? To some, yes. To others its a LOT of time, effort, and money, put into a hobby and there are some people out there who want to take your time and effort from you, sell it, and profit from it.

You wouldn't sign something without reading it right? Don't ever click on hyperlink in your email or on facebook without first hovering over it and checking the bottom left corner of your screen to make sure you are actually going where you think you are. If the link destination does not show in the bottom of your screen simply do as my friend did and right click, copy link location, and paste in notepad. Because the next link you blindly click could be from an email appearing to be from your bank asking you to log in. How important are the contents of your back account to you? Worth taking a few seconds to look at a link i'd assume.

As always (although it doesn't pertain to this situation) if it looks too good to be true, it almost ALWAYS is. Have a great weekend!!

 - Thank you Mike for sending me this great example!