Removed my CC info and changed my password this morning. I got lucky and had no odd charges on my account.
Removed my CC info and changed my password this morning. I got lucky and had no odd charges on my account.
Karma
this thread has piqued my interest enough to change my pw to something a bit more off the cuff. i haven't had any issues with getting 'hacked' for fifa gear/points but it is disconcerting.
Susane Taylor is a moron. I filed a police report, then went to the bank and gave them a copy of the police report. Then I called Xbox Live, gave them the police report number and basically told them that they can ban my account or return possession of the account to me, I don't care either way since I lost all respect I had for them, but I'm getting my money back via the bank with or without their consent, and I was just giving them the heads up. I also told them that it's up to them whether or not they want to work with the police and the bank or not, but it'd be in their best interest to comply.
I got my money back after roughly a week, and I've seen no more charges on my account, so I'm happy.
This happened to me in September, about $300 worth in charges. Called MS, account was frozen for a couple months for an "investigation", called my bank, charges were disputed and reversed. In the end I got my account back and 3 months of XBL codes. Shitty, but I must (selfishly) admit I am relieved to see the scope of this go well beyond just me.
Changed my passwords (to good ones, not dumb ones), but if they didn't save me the first time around, not sure what they'll do when FIFA 13 drops.
Just wondering, can't you just add your CC info when you need to re-up/buy DLC and then take it right back off, so even if your account gets hacked they can't buy shit?
Might just be easier to hold on to some point cards to add when you want something if they are available in your area. After the PSN fiasco I wouldn't trust any console marketplace to permanently hold my CC info.
I don't believe so no. Up until recently once a credit card was added you were automatically listed in their auto-billing service to automatically renew your XBL Gold account and there was no way to turn it off without contacting Microsoft over the phone. There was a way to exploit it by setting your address to an IL one since they have laws against it, but it was a bit of a hassle just to turn off auto-billing. Even with that done there were still "services connected to the card" which prevented you from removing the card, again, without calling them. I believe the inability to remove the card due to services attached to it still exists.
Ah, I never had any issue turning off auto-renewal, didn't realize it was only because of where I lived lol
Just a curious thought i've been having. I purchased a 12 month xbl sub. a couple of years ago when they were doing a promo. I used a debit card which has since expired (expired sometime in the summer last year). Now i know about the auto-billing but what i wonder is even though they can't charge me for the next renewal, will they still put a charge up against your name or just revert you to silver status?
I will be renewing it regardless but if my situation was to change and things are different it would be nice to know.
Anyways, do you still have to turn off the auto-billing via a phone call or is there a non retarded way now?
Actually, if you google it, you'll see horror stories of microsft still charging expired cards. The credit card companies can't explain how they do it, but they can.
Supposedly you can do it without calling them now with the new dashboard update, but I removed my credit card before they made it available to everyone. As far as charging a non-existent credit card, they actually did that while I was on my honeymoon and they charged an account I had closed. I kept getting emails for a about four months before they finally removed my gold status. When I entered a new credit card it picked up a month before (so I only got 11 of the 12 I paid for, but I had gotten 4 free at this point) and my subscription carried on like normal. I know a few people who have gotten a few months free because of expired debit cards/closed accounts, but I certainly wouldn't advise doing it in case they've changed some policy about it.
They should have your expiration date for your CC from the info you gave them, how can they legally continue to charge it after?
For those that have been hacked, when microsoft "locks" your account for investigations what do they lock?
I called on monday morning, they said my accout would be locked for 15-20 bussiness days while they investigate. However, i'm still able to log into the account and play games online.
Do they only block the online purchases?
Didn't notice this thread before, but it happened to me on 12/24/2011. It only took them 3 days to 'investigate" my account, and I had the $200 back after about 7 days.
@jmcgarrell: I was also able to log in my account the entire time, which shocked me. I logged in and took the debit card off the account. Hasn't been an issue since.
I still question how many people are actually "hacked" and how many people just have a weak password/email or use the same generic email/password everywhere, I've had my account for 9 years now and nothing bad has happened to me.
I didn't have a weak password, nor do I use the same password everywhere. So no. I'm sure a lot do, but I'm not included.
http://farm8.staticflickr.com/7005/6...9a77b59a9f.jpg
http://www.insidegamingdaily.com/201...-for-xbl-hack/The ongoing hacking of Xbox LIVE accounts has been one of the more evergreen stories in the gaming interwebs for the past few months, ever since it was first discovered that people’s accounts were being hacked to purchase stuff for FIFA 12.
Now, it seems, Eurogamer and AnalogHype have both published their findings into how these hacks have occurred. Both sites seem to have been contacted by one Jason Coutee, who had his account hacked and decided to figure out the exact process that goes into hacking an account.
The first step is to gather gamertags from simply playing Xbox LIVE games, which can be done after a vigorous round of Battlefield 3 or something. Google is the next stop, where hackers will try to match the gamertag with the associated e-mail address—which can then be used to try and log in to Xbox.com.
Once there, hackers will try and test the e-mail addresses they’ve collected to see if they’re valid Windows Live IDs. Xbox.com allows up to eight password attempts before a captcha is presented to the user, and all the while this process can be smoothed out with password-generating scripts. Once the password is found, the hacker gets in to the account and changes the password, the ID, purchases points and games and junk with the user’s attached credit card info, and then sells the ill-gotten games through the internet.
Hackers and computer-savvy people know things like this. I’m going to go out on a limb and say that most (not all) Xbox gamers aren’t totally in the know about how website security measures work—or how they fail. I know that this was news to me—sure, I knew there were methods of hacking into people’s accounts, but I wasn’t aware of how totally easy it was.
As of now, Eurogamer, AnalogHype, and Jason Coutee have contacted Microsoft about the exploit’s ease of use, but haven’t gotten any reply.
“Everybody at Microsoft refused to acknowledge the issue and because of that, gamertags are still being hacked,” remarks the AnalogHype post, offering a potential solution: “Microsoft can easily fix this issue by sending an email to people when there are more than X amount of failed login attempts and by by storing session id’s.”
Our own computer-savvy intern, Landon “Boy Genius” Robinson, explains that he’s pretty familiar with this kind of tactic (or, as I will now call it, “hacktic,” because I’m clever). His suggestion would be for Microsoft to require a log-in name that’s unique and known only to the user who’s trying to log in—in short, NOT the e-mail address you’ve probably got attached to your LinkedIn page, your Facebook account, and all the rest.
These both seem like good measures that Microsoft could start to implement to try and block against what is likely to be the black hats’ current point of entry. Regardless, earlier this week I went ahead and removed my credit card info from my Xbox account—just in case.
It’s funny—I got a PlayStation 3 for the holidays and I’ve been griping about how annoying it is that I can’t do anything with my PSN account from the website. I can’t download demos, I can’t purchase games, and I can’t even add friends from the website. As it turns out, this is probably for my benefit, as the lack of web-based control is a safeguard against getting hacked. Or am I being naïve here too? Help me out, people.
http://www.eurogamer.net/articles/20...-live-accounts
http://www.analoghype.com/video-game...red-the-truth/