NCSoft not secure? L2 account robbed and now my credit card compromised?!

General Discussion Started Last reply 20 posts
Hello community,
I am a legit player for 5 years, i do not share my information with anyone and my computer is clean from any viruses. also i do not use the same username and password for any other site, it was unique to ncsoft only.

So before you thread bash and go off topic, i wanted to see how many other people has similar issues i have had because it is to prove that NCSoft's own servers are not secure.

June 15, 2010 my L2 INACTIVE account was stripped, a few weeks after 60000 Aion Accounts stripped article here
http://www.symantec.com/connect/blogs/44-million-stolen-gaming-credentials-uncovered
My master account, email, security questions, game password all changed 1 week before june 15 when i tried to come back into game. Also i have taken a break for over a year and i have a brand new computer that L2 was never installed so for sure i didnt have a virus in my computer for any trojan to compromise my info. NCsoft returned majority of my gear and adena.

12/20/2010 while i was in store mode, My master account, email, security questions, game password all changed, account stripped again. Ncsoft gives common gear to "reintergrate" back into game and nothing more(isnt that nice? punish the victim some more). Ncsoft gives me a generic canned answer of using the same username and password at fansites, which isnt true because I used only one username and password unique to ncsoft site only.

I have refused to pay any further subscriptions to ncsoft for they seriously have a security hole in their servers.

1/30/11 the credit card that was listed on Ncsoft account, had several attempted charges to another MMORPG, a $1400 charge to malaysia, and a web conferencing company before my credit card company shut down the card.

This credit card i have had for many years, never had any issue till now. Granted its a few weeks after the L2 incident, but I find it rather oddly coincidental that this happened. especially when this has happened to Korea's NCsoft of private information being leaked out a couple of years ago.

As the security team at he credit card company still researchs this issue, i would like to hear if anyone else has similar issues like this.

Please dont thread bash!

Thank you!
This won't be here for long...
This won't be here for long...

hahaha
Nope the server is not secure....specially not when its possible to log into certain accounts with 3-6 different variations of the real password if your password ends with a number.
Nope the server is not secure....specially not when its possible to log into certain accounts with 3-6 different variations of the real password if your password ends with a number.

o.o saywhat
o.o saywhat

It's a bug that has existed for several years and NCSoft is "aware" of it, but no fix has so far been made.
yeah i find it utterly halarious that ncsoft is aware of a critical security flaw, yet doesn't inform ANYONE or prevents people from using a number at the end of their passwords.

Tested it, tried it, it's true....

sometimes more then 6 different passwords will work in place...

I use a alphanumerical password that actually the maximum number of character long and it ends with letters, not numbers specifically for this reason..

IF anyone is able to **** into my account, there is only way they could have done it, and that's either via a MASSIVE ncsoft leak/****/security flaw that makes having a password completely useless, Which also makes me nervous about these forums, because even though Vbulletin is **** good, it's not exactly ideal to use the same password for it. The other way is via keylogger, which i know for a fact considering the specific machines i use and being in the business of paying attention to these things shouldn't be an issue on my side.
I am glad some people are aware of the issues with NCSoft. It is sad that NCsoft refuses to fix the issue. Even as of now, they claim to put a new security feature on my account when the email is changed they will send a email to both new and old email to notify you of the change. So what does that do when that email comes in after their phone support team goes home for the day or the fact that the ticket support will take nearly 48 hours.. wont stop theft either.

NCSoft, you wont get another dime from me because even if i continue to play, and yet there is no security to anyone's account nor give back what was stolen.. whats the point if it gets stolen again after you put in another few months? Thats highly discouraging to put in the work just to have it stolen from you and there is absolutely no recourse!

Surprisingly no GM has answered this and thank you for not bashing this thread. The world needs to know that no matter how much of a loyal customer you are, they dont care and sit back to count their money.
lol yes, some1 just tryed to **** me, somehow , i was about o change my pw also , after i saw this threat, sicne my pw ends with number also xa0xa0 , now lets see


but wait ,any pro hacker can just come here and steal my acc or flypsi acc for example?
You are both non factor dwarves, I wouldnt get worked up over this.

Now if you both were gladis or something...
lol yes, some1 just tryed to **** me, somehow , i was about o change my pw also , after i saw this threat, sicne my pw ends with number also xa0xa0 , now lets see


but wait ,any pro hacker can just come here and steal my acc or flypsi acc for example?

Was that like...an attempt at a stab at me? I don't really see why you had to put my name into something...again. fanboi much?
Maybe he wants to be a factorable fanboi?
perhaps NC should employ HBGary Federal to do their security... giggidy...
The last time I played Lineage 2 was a year ago, the last time I added paid time to my account was January 4th 2010.

I tried to reactivate to play again, try out the new Hi^5 expansion. To my surprise, my account details have been changed, someone changed my password, email address attached to the account. All that without me EVER receiving an email informing me that the password or email address was being changed. The account was never shared with anyone. To be honest it's not even that big a deal of an account, a 78 level arcana lord with dark crystal robes and an Arcana Mace, hardly a coveted must have character/gear but clearly NCSoft security leaves a lot to be desired. I know some smart***** will say I shared my account info, tough luck etc. I didn't. And yeah positive there is no virus involved, due to my work the network I am in is probably safer than most countries military computer networks.
All that without me EVER receiving an email informing me that the password or email address was being changed.

That is also something that worries me, have happened to me to and I did not get any email saying the password or email to the account was changed.

Usally on things like this on recive an email saying " are you sure you want to change email adress? or are you sure you wanna change password? "
i think to change your Email... a validation email should be sent to that account to make sure... if not that account.. then the backup email account..

at which point.. you can then change the email and password.. BUT ONLY if you've validated......
Validate the validation!
hmm this is a bit of a worry. I recently had my Ncsoft account messed with also, but my lineage 2 characters were untouched, Seems they only wanted Aion :/ Had happened while my account had been inactive also
I was wrong... it is still here.