I am not the type of person who enjoys drawing attention to herself or making a fuss. I have never snapped at a customer service representative, I have never written a negative review and I have certainly never launched a one-woman attack on a company. The “customer service” I have been on the receiving end of over the last few days, however, has changed all of that. When I have a large quantity of money stolen from me, money that is meant to be paying for food for my 1yr old disabled son, I can’t just sit back and twiddle my thumbs in hopes that someone, somewhere, will eventually get off of their arse and help me; especially when that ‘someone’ is Microsoft.
So what exactly has happened to make the ‘momma bear’ in me rage?
On January 2nd 2012 I received a few emails in a quick succession that completely ruined my day. Someone had logged into my Xbox Live account, purchased 10,000 Microsoft Points and a “Gold Family Pack” for a grand total of $214.97 + Taxes. They had purchased the Family Gold Pack so they could then transfer the MS Points to a dummy account that they had created. I immediately attempted to log into my Xbox Live account and, when that proved unsuccessful, I got straight onto the phone with the ‘Phone Support Team’.




I was informed that my problem would be forwarded immediately to their ‘Fraud Department’ and that they will have to lock my Xbox Live account for 30 days pending the outcome of an investigation. I inquired as to how they would contact me if they needed further information and/or wished to let me know that their investigation was complete. They requested a contact number and a new email, which I happily supplied.
After getting off of the phone with Microsoft I contacted PayPal regarding the three unauthorized transactions and also my bank. While both were unable to do anything at the time they logged my complaint and also promised to investigate the fraudulent activity on their end. Not exactly the results I would have hoped for, but with a little tightening of purse strings I could just get through the month without that money.
On January 3rd I received a generic email from Xbox to reiterate that my account is blocked and that the Windows Live ID will also be unusable elsewhere online. In addition to this they gave me a 30-day gold key as compensation for the lengthy investigation time and suggested that I create a temporary account while my main one is blocked. Apparently someone forgot that when you create a new Xbox Live account you get 30 days gold for free anyway. Communication clearly isn’t Microsoft’s strong point and even then that’s a bit of an understatement.

I’d like to point out here that while I was given a 30 day ‘gold’ code this could take 42 days to rectify and even then there are 10 business days on top of that and it may take two billing cycles for it to appear back in my account. So that is near enough over two months away, if not three.
But wait, it gets worse.
I awoke this morning to find a further $124.98 + Tax stolen from me. I know what you’re thinking right now, “She should’ve unlinked her PayPal account from her Xbox account, the silly woman!” I completely agree with you; yes I should’ve done exactly that, but when Microsoft insisted twice that my account was completely blocked I naturally assumed that meant my account was completely blocked. Silly me! What they really meant was that they did not block the account whatsoever and the hacker/thief/opportunist decided to purchase yet another 10,000 Microsoft Points and transfer them to another dummy account. I was so surprised at receiving those emails that I burst out laughing just as soon as I had unlinked my PayPal account from my Xbox account.
Surely this couldn’t be happening again?



So back onto the phone with Microsoft I went. The person I spoke to certainly got a bit of an earful this time around. After explaining the complete story to the Phone Support Team Member, including the part where I was told twice that my account had been made inaccessible by all, they came out with a complete gem which just proved how full of bullshit they really are.
“The fraud department was unable to block your account.”
“So why did no one contact me about this? You have my telephone number, you have my email address. You used my email address to tell me that you HAD blocked my account. Just what is going on?”
“They were unable to block your account, I don’t know. Have you tried changing the password online?”
“Yes, but whoever is doing this has changed my password and my security question. I am completely unable to access the account myself. That does not answer my question though. Why have I been told, twice, that my account was blocked, that an investigation had begun, when clearly none of that was true? Why is it you’re allowing someone to successfully steal money from me a second time when you were aware of the issue days ago? What the fuck is going on? I want my money, I need my money. Tell me what you are doing to help me.”
“You need to keep trying to log into your account.”
At this point I chose a few choice words that were only used out of pure frustration and hung up the phone. I came online, ranted on Twitter and received a response from the official @XboxSupport Twitter account.








I direct messaged them.





They were about as helpful as everyone else I have been in contact with regarding my stolen money. In total (including tax) I have had $366.06 stolen from me. At this point in time I just feel like I am being lead around in circles here. I have spoken to numerous people from Microsoft and the only information I am given is that they will pass it on to the next person.
From this, I have learnt that..
- No one can tell me how this happened in the first place.
- No one can tell me why my account was not blocked when I was told it had been.
- No one can tell me why this was allowed to happen a second time.
- No one can tell me this will not happen again in the future.
- No one can tell me when I will get my money back.
- No one can tell me exactly what is happening with my ‘investigation’.
- No one can explain the inconsistencies between the amount of points purchased and the amount of points that were logged as being transferred.
- Everyone seems to be completely dumbfounded by the whole situation despite knowing that this is not a new occurrence; that many gamers are waking up to these emails every day.
- Everyone who is currently reading this should go and change their passwords right now.
Just how much louder do I need to shout before I can get some answers?
——————–
Update Jan 5th 2012 @ 5.11pm:
I just turned on my Xbox so I could create a temporary account and play some video games. What’s this? My account logs in straight away like normal? That means.. Oh no, surely they’ve still not blocked the account?!
Yeah, that’s right. It has been over 72hrs since I first reported this whole thing to Microsoft and my account is still active. I cannot log in via Xbox.com, which confuses me because surely if my password had been changed than I wouldn’t be able to log in via my console?
Oh, and who is this?

Wait a minute.. I recognise that name!

Oh shit.
I fire off a friendly message. (Sorry, I didn’t even think to photograph my messages to him!)
“Hi, who is this? When did you add me?”

“Oh right! What seller did you buy it from on there?
”

“Ahh, okay! What’s the name of the middleman? Does he have a website or is he on Xbox too?”

Alright, now we’re getting somewhere. I play it cool, keeping it friendly and upbeat.
“I just wanted to see if I knew him lol! What’s his username on there?”

Bingo!
I am about to see how far this lead gets me. I’ve decided not to reveal the email address just yet in case this person is an innocent party.
Wish me luck – I will update again as soon as I can!
Update Jan 5th 2012 11.50pm:
A few things to update on here. Firstly, I have spoken to Microsoft again and the rep I chatted to was appalled that no one else had actually managed to get my account blocked since the moment I first reported the issue on Monday. He said he is going to (wait for it) “pass my case onto the Tier 3 team” who will phone me once my account has been blocked and the investigation began. I don’t have much hope of it getting blocked. I’m beginning to get used to the idea of never being able to use my account again.
Secondly, I did some detective work and have figured out the hacker/thief’s game plan. It’s pretty simple really.
Step One: Obtain username/password of account currently in use (I cannot work out how he obtains this information)
Step Two: Purchase Family ‘Gold’ Pack for the hacked account (this means he can now transfer points between the accounts he lists on the family pack)
Step Three: Purchase 10,000 MS Points (4000/6000)
Step Four: Create multiple (number unknown) brand new Xbox accounts (typically American accounts)
Step Five: Transfer all purchased points to these accounts (divide among multiple accounts or send full amount straight to a single one)
Step Six: Sell the account that has these points on to people, charging a smaller amount than Microsoft would charge for the points alone
Step Seven: Rinse, repeat, profitprofitprofit!
He also does Step One-Four but instead of transferring out the points he’ll purchase games with them and sell accounts with these games on.
Finally, his listings all state that you must use the MS points “as quickly as possible” and that if they disappear, it’s not his fault as there was a stated ‘warranty’ in his auction site listing. If the points have gone you will have to purchase more from him, end of story. The same goes for the games; you must recover the purchased GamerTag, transfer the licenses for the games as quickly as possible or you may miss out.
I have so far gotten his online auction site account name, his ‘business’ email address and a contact number for a Polish chat-system called ‘Gadu-Gadu’, which looks quite similar to show Skype works. I have not reached out to contact him yet and I ask that people who are reading this do not attempt to do so either.
And finally, before I wrap it up for the night, a few people have criticized me for not making my account safe enough and basically lumping the blame solely on me. I believe this is a pretty unfair judgement to make. I want it to go on record that I have not become the victim of a phishing scam. I am extremely conscious of online identify theft and I know exactly what to look for when it comes to non-legitimate websites. On top of that I have never logged into Xbox.com or Paypal.com through any web address other than Xbox.com and Paypal.com. My Windows Live ID is a unique email address I used just for my Xbox, same goes for the password. The password and security question answers were also unique to the account only and a random assortment of 16 letters/numbers that have no relation to one another or even to myself. I do not have easy-to-guess passwords such as ‘password’ or an important date. I also have daily virus/malware/spyware scans run on both of my computers daily between middasy-1pm. I do not know how safer I could’ve made my account honestly. A unique email, a unique (and difficult to guess) password, unique security answers AND daily scans on my computer. Suggestions on how safer I could’ve made my account would be appreciated.
I realise now that I made a huge mistake in keeping my bank account linked to my Xbox account, but raise your hands if you too have done the same with some form of online account. World of Warcraft, GameFly, LoveFilm, Playstation – The list goes on. I think it’s fair to say that many people would look at Microsoft as a reliable company and absolutely trust them with their bank details. What makes them any different than Blizzard or Sony? If this level of trust makes me a fool, than so be it, brand me as one. Just know that you are branding a hell of a lot of people with that marker and we are not the ones to blame here.
——————–
Update Jan 6th 2012 @ 12.50pm:
My account has finally been blocked! I will do a more in-depth update soon.
——————–
Update Jan 6th 2012 @ 3.35pm:
Today has certainly been a busy one for me. I never thought my story would get so much attention online; and it is because of YOU GUYS that my issue has now been resolved.
So what exactly has happened today?
Aside from my story exploding at gaming websites across the net, I had a phone call from Jonathan Michael a few hours ago who is employed by Microsoft as part of the ‘Customer Advocacy & Exception Management Team’. He was extremely keen to reach a resolution today and it was clear that Microsoft were doing some serious damage control by bending over backwards to help me.
I was immediately told a refund would be issued to me (which I have now received and is sitting in my PayPal account). I then approached the topic of my Xbox Live account. All of my information on it had been changed by the hacker; the password, the security questions, anything that would relate this account to me had been changed. Jonathan informed me that to get around this he wants me to create a new Windows Live ID and that he is going to transfer my Xbox Live account from my compromised Windows Live ID to this brand new one.
Err, you guys can do that? (And by ‘that’ I mean transfer my account easily without verification, read on below..)
I have never heard of this happening before. Ever. If anyone who is reading this has had this done for them please get in touch with me. Is this something that they are pulling out because they want me out of their hair? I’m leaning towards ‘yes’ on that one.
Why?
Because I know that if you are unable to be verified as the account holder, you will no longer have access to that account. I have spoken to gamers today who told me that they could no longer user their accounts because of this verification process. So how the hell did I get by that one? Special treatment ahoy!
I do not want to sit here and say I am unhappy with the results. I’m not, I have access to my money again and I no longer have to worry about feeding my boy. What has frustrated me is how I have been treated throughout all of this.
At first I was given the run around, then I was lied to, then I was passed on from person to person and the ONLY reason why I am sitting here with a completed grocery list next to me is because I made a big ol’ fuss. I set out to get your attention, to get people talking, to force Microsoft to ignore me no more. I succeeded, but what about the numerous (read: 250+) people who have sent me emails telling me their stories?
What about Pete who had his account hacked in November?
Did you know that Todd has been waiting patiently since October?
Poor Scott has been fighting Microsoft since September?
I could go on, but I believe you’ve got the point.
I have spoken to so many people today, I have been interviewed, invited onto podcasts, read so many frustrating stories; and I have learned things about the internet, about big companies and about people that I will never forget.
So, what now? My story is over. I have no reason to update this blog anymore, right? Well, not exactly. I want to continue this fight. I want to hear from everyone who has ever encountered terrible customer service from Microsoft in regards to their hacked Xbox Live accounts.
Talk to me. Spread the word. I want to help you.
——————–
Update Jan 6th 2012 @ 5.29pm:
I spotted this via Eurogamer.net.

While I find it amusing that I have created an out-of-the-ordinary case for Microsoft, I am quite peeved that they are still insisting the abuse of my account was my fault. Fuck you Microsoft. I love your gaming console, I love your game selection, I love being an Ambassador for you, but you really are infuriating.
——————–
Update Jan 7th 2012 @ 5.27pm:
Microsoft DID refund me 100% yesterday.. Until they took $81.08 from my bank account today. The weird part of this is the original description and the trans. type, they do not match the 5 other transactions over the last few days. Also my PayPal account is not showing an deductions. However the ‘uncategorized’ labeling tells me it is a completed deduction from my account and not something that is pending. I am baffled at this because my PayPal account has been unlinked from my Xbox account, my PayPal email address and password have also been changed and I removed my bank from my PayPal account! My bank account log-in details too have been changed. This charge makes absolutely no sense to anyone, especially since PayPal has been mentioned but NO activity has happened on my PayPal account.
Just what the bloody hell is going on?!
@Stept has a theory which would (kinda) explain things..

So I am currently right back to where I start with this story; no account and out of some money.

I also wanted to mention that I still do not have access to my Xbox account. Apparently people are assuming that I do have it back, I do not.
Back to the phone I go..
Update Jan 7th 2012 @ 7.13pm:
I managed to get through to someone helpful at Microsoft (I’m as shocked as you are) after the point-of-contact CSR told me that they would have to pass me onto someone else (chuckle). He asked me a lot of security questions relating to my account which, when answered, where not do so correctly. We went around in circles for a while until he accepted that I could just not prove that the account was mine. We hmm-ed and ahh-ed for a while before I offered a possible solution; I had the unique case ID that was associated to my account on Monday.
I gave it to him and he started to help. (Hooray!)
The first thing he had me do was recover my Xbox Live account directly on my console, he sent a “reset your password to this account” link to an email address I gave him. I did briefly wonder just how unsafe this was in reality, he couldn’t actually PROVE this account was mine outside of a case ID number. I got the email and reset the password. After logging into my account I noticed all of the security questions were in the another language (I’m kicking myself for not taking a screenshot) and I changed everything to what it should be.
Back to the Xbox I went and recovered my account using my old Windows Live ID and the new password. I internally squee’d with delight when I saw the progress bar appear. Once completed I was guided to the section on the dashboard where I could transfer my account to the new Windows Live ID that I had created yesterday. This was when the CSR informed me that Jonathan, the gentleman who called me yesterday early afternoon, would’ve been unable to do this for me and he was confused as to why Jonathan had promised me that he would do it himself. He did ask me why Jonathan had contacted me because “he doesn’t usually get involved with stuff like this”. He laughed when I told him what had happened.
He told me to go back to my new Windows Live ID, update it with my information and to then call back so they could check out this new charge on my account. @Stepto has a theory:
I should just put 1800-4MY-XBOX on my speed dial. (I am also phoning PayPal and my bank regarding all of this, naturally, but this tale is about the bad customer service received from Microsoft.)
Update Jan 8th 2012 @ 10.72am:
I can happily say that my story has finally reached it’s happy ending and I cannot see a sequel on the horizon.
After my post last night I got straight on the phone with my bank, PayPal and Microsoft. PayPal immediately told me they were going to refund the costs, but couldn’t explain why the transaction was not appear in my PayPal account. I received an email from them this morning which brought me great joy:

The date was different to the ones shown on my bank statement, but as @Stepto said, it could’ve been a lag in a system somewhere.
I also received two emails from Microsoft this morning. One with a code for a 3 month Gold account, which, while not compensation, makes me happy enough. I also received a notification that the point balance on my account had be restored also. While a little compensation would’ve been appreciated (I’ve heard of people receiving 1 month of free gold for example), I am happy with the knowledge that I got such a quick response and that, because of my story, Microsoft will be looking into how they deal with fraudulent reports from gamers.


As I said above the other day, while my story is over, I still want to continue fighting for you guys. I also have a few other findings that I am going to post on a separate blog post, to keep this one focused solely to my tale. Keep sending me those stories, I am planning a lot of things for this website and I hope that over the next few weeks those plans will begin to take shape.
Spread the word and happy gaming to you all!
——————–
Have you been a victim of Xbox’s Security blunder? Drop me an email stories@hackedonxbox.com, I would love to hear from you and how Microsoft dealt with your case.

Hi, this is a comment.To delete a comment, just log in and view the post's comments. There you will have the option to edit or delete them.
My genuine question to every web savy victim here is this, (not asking for your actual passwords) what kind of passwords are you guys using? I’m very curious as to whether the general public is aware on how to construct a strong password (examples would be great, but please don’t use real passwords you that you may actually use)
Nonsensical letters, numbers and symbols. The only weak spot is that it was shared with that of the EA account as I was only using that for Battlefield 3. That is why at first I thought it was EA, but some have stated they have been hacked and they did not have an EA account. However some of them did say they had Netflix accounts, so maybe the API used to link the logins is weak and can be compromised.
There are still tons of videos online on how to steal a Live account, most of them are not valid now but it shows that it was possible. You steal the Live account and you get everything that comes with it.
my sort of paswords are long and patterned on the keyboard (and not simple patterns) my standard password (when i can apply it or others of the same length) tends to be between 18 and 24 characters long. never had a hacking problem in my life but find that i am getting increasingly paraniod due to the rising amount of complaints.
I was hacked in Sept and they still have no resolved my issue. Lost all my points, access to purchased games, etc. Awful, they keep saying "30 more days needed".
I was currently hacked and I have the hackers email that he tried to use to change my account info but I have luckly gotten all of my account back and fixed up with new passwords and secuirty questions. Now to get this fixed with paypal and my bank and microsfot >.<
Hacked as well…same story as everyone else. Apparently it's all our fault too. We all put our Live ID's and passwords on a list somewhere so they could be grabbed by whoever wanted to use our accounts. Thanks M$!
Sent an email to you detailing my story. Bascially happened at the end of November, waited a few weeks, missed a phone call, that missed call reset the clock for the investigation, even though it was returned within 15 minutes. Talked afew times to different CSR's on the phone, and on the chat program. Get different answers everytime. Also tired of talking to what sounds like bored, I dont' care teenagers. But as of yesterday..have to wait 3-6 weeks from Mid December. Communication is the biggest problem they have right now. Maybe they also need to be looking into data leaks on EA's side or maybe even Facebook? Since they allowed integration of the console's dashoboard onto facebook._
Well submitted for a phone call that stats I should hear from it in 5 minutes, its been 3 hours….no fun.
SO I, like the many others, has been hacked. Luckly it was through paypal and has not been taking out of my bank account yet, so I was told by my bank to freeze my account and close it and open up a new one. We will see how this goes.
my account was also hacked very recently actually the same day as this lady. he stole 30 dollers from me but not 300. now im scared. he could be buying more soon :0
A few days ago i turned on my xbox only to see that i couldn't access xbox live ( first time in over three years)
Earlier that day i read an article on a french gaming website that the xbox live had been eventually breached by hackers and many customers lost their accounts.
I immediately went online to verify the article i had previously read. Comments suggested that if you could not access xbox live you should try and log in on xbox.com which i did and succeeded. But i still couldn't access xbl on my xbox.
I rushed on my email account and eventually succeeded in changing the password after several attempts because i was continously being signed out ( maybe the hacker?).I eventually accessed xbl.
After enquiring on the net apparently hackers breached EA servers aswell and eventually stole account details particularly gamers playing Battlefield 3 and Fifa 12 games that i own. That may not be the case for everyone as people got hacked while not owning any EA game.
I haven't lost any Microsoft Points -phew- but i am a victim of hacking and that is unacceptable from microsoft because it may occur again the same goes for EA.
We pay ENOUGH MONEY to access xbl the least they could do is secure our account details!!! FAK !!!
Credit to you Susan.
MS certainly has/had a breach somewhere. A few months back out of nowhere, I see an email from live that somebody bought some live points through the zune portal and added a new mobile number to my account. I log into my xbox account and see the guy draining the points I did have on my account right before my eyes. Right away I changed my password and contacted MS to see what happened. They blamed it on phishing, but I already know that is impossible.
I got my issue resolved pretty fast, mainly in part because I caught the guy right away or he could have certainly charged way more points to my account.
I really don't know why the live portal doesn't give you more in depth security details about your account. Such as current/past logins from IP addresses and even what xbox consoles are linked to an account. They should give a person the ability to lock things down much more then they do. They clearly have a big security hole somewhere and need to plug it. Of course they will never live up to the fact they do have a breach.
I'm sorry to hear that xbox support failed you. When this happened to me the support person told me to contact my bank and do a chargeback for the amount. The bank got my money back within a few days and sent me a new card. Your bank should have done the same but it sounds like they have failed you as well. You should always cancel your card when this happens, especially if someone with your account credentials can see the number (they CAN on live.com!).
My own experience with xbox support was great, but a similar experience with Sony really sucked. I told them my account had been compromised and they were like "That sucks, change your password" (not exact words).
I'm aware of a seller on Trade-Tang who is selling account log-ins and passwords as mentioned in this article. I'm reluctant to post a link here as I'm not exactly sure what to do. I have an old work mate who's purchased points from the seller in the past
Way to go, keep up the good fight!
No points were spent as the whole thing just stank of hackers, especially when he started emailing out user names and passwords. We'd like to report him / her, they have a lot of positive feedback on the site and it is very worrying…
Wow.. you are an ass. FYI.. hosting service can be purchased for $10/month and comes with a free domain. Even people without lots of moola need to have some entertainment money, and xbox is a cheap alternative to paying for a babysitter, dinner and a movie. That amount of money would hurt my household as well. Show some class, not your lack of it.
You are a beacon of hope in the confusing non-sense that is customer service. Thank you for sharing your story.
mine got hacked back in october.they didn't completely lock it down until 3 weeks in.2 days before mw3 came out.every day i would log in with my new gamertag and see the hacker log in under my gamertag and play fifa 12.xbox told me they weren't sure why it hadn't been locked down.they thought maybe they were trying to catch the person in the act.i was the one who actually tracked the guy down.he was stupid enough to link his xbox to my call of duty elite profile,which gave me his real gamertag.of course he was from the uk.i don't even use paypal,so i'm not sure how he hacked my account.
It's sad that in this day and age Microsoft's account system is so broken. Worse when they're so nonchalant about it. How do they expect to stay in business if these constant hacks happen to people?
same happened to me…
2000 points cleared off my account, and 15 cheevos for fifa12 (a game i've never played.)
in the middle of the process.. 30 day investigation and temp account.
I've been shouting the ineptitude of Microsoft to everyone who will listen, this is a big hole in security and allowing this to happen is their failure. no matter how the hackers are getting the info the damage they can cause and the way it is handled is shocking. Social engineering is not an excuse, it is a simple way for them to either cover the truth or say we just don't know.
Do NOT feed the troll
My account was hacked and they charged $75 on October 1st 2011. I immediately called my bank and cancelled my card. I then contacted Microsoft who cancelled my account and said it will be under investigation. "While under investigation, it will be unplayable for up to 22 business days." No problem. My bank payed me back in full a week later. This was looking to be an easy fix.
60+ Business days later, Jan 9th, 2011 and my account is still "under investigation". Only thing support can tell me is that the investigation team is still looking into the account. They have no direct communication with the investigation team (I'm thinking they are the CIA?!?!).
2 words: Microsoft Sucks!
Thank you for sharing your story. At least I'm not the only one getting screwed by Microsoft.
Correction, Jan 9th, 2012..Happy New Year! lol
Im still waiting 130 days later for a 50 dollar refund
They refunded 75 the day after but I’ve fought and fought
Over the last one.they said they sent it but it could
Take up to two billing cycles to show up……and they have gave me
3 months and 400 points to pacify me.not working
Sorry to hear about your situation,
I think Microsoft has good security, but they are always going to be vulnerable becuase they are always going to be a huge hacker target. It sucks that MS makes it so hard to delete credit card information. I am glad you are raising awareness… with all that said. One thing you wrote threw me for a loop.
"I am not the type of person who enjoys drawing attention to herself"
but aren't you rockin' pink hair. That seems like someone who does enjoy drawing attention to themselves.
Just my two cents – if you use a debit card online (which it looks like you are via paypal in one of those screen shots) you REALLY need to rethink that.
With credit cards you're only liable for $50 of fraudulent charges, period. Even if I stole your card, went out and bought ten cars and a yacht, you would only have to pay $50, and only if your credit card company decided to act like bastards. If you report the card stolen you generally don't even have to pay that.
With debit cards there's the possibility of you being liable for ALL the fraudulent charges, meaning that if someone clears out your entire bank account, you might be just screwed. Granted you'd have to not notice the missing money for 60 days, but the way some people manage their finances, that's not out of the ordinary.
I know this is kind of a separate issue and the onus should really fall on Microsoft in your case, but I just wanted to point out that this is another way you're opening yourself up to losing more money.
Read this page on the FTC site for more info: http://www.ftc.gov/bcp/edu/pubs/consumer/credit/c…
It's only expensive if you buy new games (not from places like Gamestop) also, completely unthinkable someone could be financially low after the holiday season right? Get a life.
Instead of blaming Microsft. You should put part of the blame on yourself. For not taking the security measures to make sure your computer is free of any viruses/spyware. Seriously this whole mess wouldn’t even happen if you kept your computer free of spyware/trojans. A simple virus/malware scan would of probably prevented this. Doesn’t take a genius.
Oh it doesn't, what about those that own Macs and iOS devices ONLY other than their XBOX. So what you are saying is that these folks wrote one of the first known viruses for Mac just to steal my Live account and do this with it? Holy shiz, it's a frickin' conspiracy.
I have a two month old account (longer if you count GFWL) and all I have that seems to be the cause is an EA account or the iOS apps as that is all I have ever logged into.
It doesn't take a genius to think about what you are saying before you type it.
This is so untrue, it isn't even funny. For one, I use a Mac. For two, I've never been to xboxlive on my computer prior to being hacked. For three, I'm a web developer for a living. I can sniff out phishing website and emails from a mile away.
I do however agree that this could be the situation for others.
I wasn't mad at Microsoft for allowing my account to get hacked because that can be out of their control, I was pissed that it has taken 60+ business days just to get my account back!
Just wanted to say, this comment really ticks me off. So somehow it's the users fault if a virus is contracted that their preferred method of AV software didn't pick up? So following that line of thinking, what is someone supposed to do? Get every piece of AV software under the sun and HOPE you don't get something that was written to bypass current AV definiton files?
You really need to think this through before you put into writing……
Caught a hacker within a few mins of it happening. I have WP7 on my phone, so saw the login to messenger from a system not my home or work PC. After fighting with them playing a password reset merry go round, I was able to lock them out of my account and remain in control of my account. I think they gave up when they saw I didn't keep any bank info linked to my account and keep my standing points balance at a minimum.
I dont believe this is a server hacking issue more a social hacking issue. After reading a few sites and getting a bit of an understanding as to how these people seem to work it seems to me that they could be contacting Microsoft customer support to get the data they require.
It would only take a little investigation into a persons gamertag, email, details by some of the sites you can browse be it social networking or sites that link gamertags along with personal details. If you happen upon a poor customer service rep, which from the sounds of reading this is quite common, it seems it would be possible to get the rep to divulge, eventually, the information you require to gain access to the account.
My advice would be to remove any personal data you have linking you to your gamertag.
I would believe that may be happening. People make mistakes, even well meaning CSR's. In my instance, I still think the breach occurred from one of two places…EA or Facebook. The reason is the live ID I used, I haven't had access to the email address for a few years now. The only places I have used it were on EA logins to link my Gamertag to an EA account and when Facebook integration was launched earlier in 2011. The only time I used that particular combo was when logging into Facebook on my xbox and the initial setup over Xbox..
In all honesty, I think it is likely that either our account information was stolen by someone on the inside or one of the weak APIs used by EA accounts and/or Netflix accounts was breached. This is Live accounts, they are basically MSN/HOTMAIL accounts with a bunch of extra crap piled on top. Gmail, Steam, etc. are much more secure as you can be prompted to be notified by email or text when an account is accessed. That implementation seems like a no-brainer when I am paying $60 annually for a service.
Nice work. It took 83 days to get my account back from being locked because it was hacked. I luckily got the account locked immediately and the people only charged $120. I basically stalked Major Nelson on twitter. He finally noticed when a friend suggested I dump Xbox all together and switch to PSN. He forwarded me to a "Community Specialist" who got my account back to me within the day.
Not a fun experience.
Hi ho, hacked in October, still waiting for $50 odd dollars or so. Called, went through their hoops, and they said I would receive the refund in about 20 days.
You are very optimistic by saying "happy ending", I'd be foaming at the mouth still, even after resolution. Just wondering, I heard of an outage in ms servers not long ago, after the whole psn outage (http://www.kotaku.com.au/2011/10/fifa-loving-hackers-strike-xbox-live-accounts/), maybe it all starts here?.
Btw, you were asking about the whole switching live accounts between two live ID's? Well something along these lines happened to me, though it WAS all my fault. I can't remember what stupid thing I did with my email address, but I went and locked myself out, couldn't remember the password reset etc etc. So when I went to go change the email address, live customer support told me I couldn't. I answered a billion and one questions, my account was on hold for like 4 or 5 days, after countless phone calls to live support, tier 27 support told me the least they could do for me is refund me any points I may have purchased, but I needed to create a new gamertag. I specifically asked them if there was any way that I could save that tag. The straight answer was, no. Either way, I haven't touch my xbox in a few months, after reading this, I'm pretty much done with Live.
Sorry you had to go through this, take care of yourself and that baby boy!
I had my XBL account hacked in November last year and several hundred dollars worth of charges by the hacker to my attached Paypal account – which I never approved to be permanently connected. I had previously bought points via Paypal on my XBL account via the Microsoft website and never opted to permanently link the accounts!!! I called Microsoft, and they refused to do anything – their only response was for me to call my bank. Fortunately I was able to login to my XBL account on the web and was able to change my security details. I immediately logged into my PayPal account and disabled the link to XBL, changed my Paypal account password, cancelled the charges from Microsoft and filed a fraud report with PayPal. I was then able to recover my account back to my 360.
I resent that Microsoft refused to take any responsibility for the problem and refused to help in anyway. They treated me like I was the criminal every time I phoned them. From a technology point of view, it would be very easy for Microsoft to track who was accessing my account and block their console serial number and/or console mac address.
I am also very annoyed that I am paying a premium price for a service that is offered for free by other vendors, and is not accompanied by any premium service or support, let alone any real duty of care!!!
Heres the part that frustrates me abou this whole mess. I realize, that this is a gaming platform and in light of everything, it's a hobby. But I am so frustrated with Microsofts response to any of this. There are literally HUNDREDS of people, if not more, effected by this. I am glad this worked out for Susan. But for those of us who had money taken, do we not have children to feed to? The only way there seems to be any resolution in what most of use would consider a timely manner, is to start screaming on the internet. Only then, does Microsoft take any kind of action.
Again, I am glad this worked out for Susan, but really, how is she any different from the rest of us? Besides being an Ambassador for Xbox and putting this on a blog?
Not trying to bash you Susan, I'm just frustrated with Stephen Toulouse and Microsoft using you and others who have had stories published on the web as poster children for how they are working the issue in a timely manner.
I am also a victim of the current breach. Getting this resolved was QUITE a pain and caused me to remove my cc/bank info from XBL. I now only use game cards to renew my membership. That being said, the title for your website “Microsoft: A Company with No Brains, Heart, or Soul” is pretty over the top and detracts from the message you are trying to get across. Microsoft tries hard to put out a good product and service and have all the same problems many large companies do communicating internally. Try and remember we are talking about a company that has 10k+ employees in their entertainment division alone (many who I know as a Redmond, WA resident.) I can guarantee you the people who work for XBox/XBL are very passionate about their product and work hard dedicating their “brains, hearts and souls” to make it something people will enjoy.
I can guarantee you that the people that work for Live account support (not XBOX support) do not work in the United States and instead work overseas along with most of the Windows Support Team. How do you hold someone legally liable that lives in another country if they were to sell off your information?
I’m not entirely sure about that. The person who I worked on the phone with was clearly based (by accent and language usage) in the US. That being said, I’m not sure she was more/less useful than someone based overseas.
I am talking about Live support, not Xbox Live support. Live account support is located overseas, think Hotmail problems.
I woke up one morning to find a beautiful email saying that i had bought 6000 MS points at @ in the morning…needless to say the told me they would block my account and get back to me within 7 business days. 3 weeks later i called and they told me whoops! the person before didnt get enough info from you to start (I guess that the whole thing about being done was a complete lie) well one month later and they never sent me the promised "free one month" so i was unable to play xbox and neither were my two brothers with whom i share the account. a month after that they sent an email saying that it was out fault and we're stuck with the points.
Idk much about investigation but shouldnt there be a way for them to check the IP address or somehow tell where the purchases were made from? I mean I was in high school at the time, wouldnt it be obvious that it wasnt me if the purchase was made in the UK? and how are these people not going to jail?! This is theft! MS needs their own team of hackers to take down these a$$holes who are stealing our money.
Thanks for sharing your story and also for letting our voices be heard!
P.S. I hate you Microsoft Customer service, but damn it if Gears of War doesnt make it all worth it
I've had problems with Microsoft twice. I allowed my little brother's friend to use my credit card on his Xbox to buy an xbox live subscription, and he paid me back the money every few months. This was fine, until his xbox was stolen from his house. By this time, my brothers and he had fallen out of touch, and I didn't know that his xbox had been stolen until an $80 charge from xbox showed up on my credit card a few weeks later. I contacted Microsoft in an attempt to cancel the friend's xbox live account. They made this next to impossible. After about an hour on the phone with their "customer service," and answering an absurd amount of questions, the account was finally cancelled. They did absolutely nothing as far as refunding my money, I had to contact my bank to take care of that (which they did quickly and very well).
The second time, someone hacked my Xbox live silver account, which I never use, but still had my credit card information linked to it from a purchase I made a long while ago. I was able to get into my account (apparently the moron who hacked it didn't think to change the password), change the password, and remove my credit card information from the account. This time, I did not even bother with Microsoft's customer support and went directly to my bank for the refund.
In short, Microsoft's customer service is awful.
Granted it is not Susan's fault, but it is really shameful that the only people Microsoft moves fast for are those that post up a blog or work for a news site. What about the regular Joe that has been waiting for 100 days? In comparison, me waiting for 14 days seems minor.
At least despite having her issue resolved, she has kept this area up for those of us still fighting – I thank her for that.
I've sent in my story to you already and we've been going back and forth. I'm at 4 months without my account and was told on Friday that their time-frame for returning it to me would be between 3 to 6 months at which point I'm sure they'll require another '30 day extension.' Terrible.
I would file a complaint with the Better Business Bureau at this point.
I know this is different console im on about, the ps3 but my account was hacked and password changed and i rang sony so many times but i had fake date of birth because i was to young at the time and then became the right age( i know this was stupid) and every time i rang them i got referred to higher people up all the time and but the stupid thing with psn is they confirm its you by your date of birth which is so easy to find out and stupid i did not have this so they would not let me prove my self any other way so afet ringing them for months i got no where so at the end i keep guessing my fake date of birth and got into my account and i got my account back and 1 year later they never rang me to see if the hacker still have my account or notting at all…. so one thing sony fu*k you
I dont know if someone has said this or not but, my cousin got his account hacked last year around September and the same thing happened. They bought 10,000 points. All he remembers was that the night before it happened, he downloaded an app off the App Store (iPhone, iPod Touch, iPad) which lets you sign into your account and see your friends and what they are doing and even look at your account. Now he thought since it has to be approved by apple (the app), it must be safe, but the next day he got hacked. So a little warning, don't use any app on android, ios, etc. unless its an app created by microsoft. Don't be a victim to these hackers.
I'm on a 30 day lock down after getting hacked. They need to fix their security… BIG TIME.
I had my amazon account hacked.
$200 gift card purchased and mailed to a new address that the hackers added. The purchase was blocked, the gift card not sent, my credit card was never purchased. How hard is it for Microsoft to "identify unusual account activity" and not allow it like Amazon did within 5 minutes of this unusual purchase?
I did call Amazon about it and I was told that it was my fault, that I must have clicked on a link from an email and entered in my information on that "fake" site. Which I never did. I never even click on any of my bank, insurance, power bill, Directv bill or anything from an email sent to me. I always go to my favorites or type the page in there.
my account was hacked on dec 31, and the bastards spent all of my 4000 points i got for christmas and about $128 worth of points they bought after the breach on fucking FIFA crap. as of today i'm still waiting for a response. my bank has already credited me the amount charged and replaced my card. still waiting on MS to do something. i don't have much faith on getting it resolved quickly. boo.
Wow that's quite the ordeal. I"m going to change all my passwords so they're the maximum length they can be with as many numbers, capitals/smalls and special characters i'm allowed. Also make sure i'm running a few different anti-malware softwares to catch those trojan horse drive by installs that could install key loggers and pass along login information.
That horseswallow about malware is from trolls trying to live by their "just-world" fallacies, while you should make sure that your computer is protected it is more than likely not the reason behind these hacks. I would sincerely doubt these hackers made malware for Mac specifically to steal my XBOX account information.
Tradetang has been dealing in these types of xbox live "purchases" for years. There are many other sites as well that do the same thing.
Always keep your details private and don't use obvious passwords and you'll be fine, like the vast majority on xbox live.
Yes, that is exactly it. We all used obvious usernames and passwords and gave out our details everywhere. Also we had keyloggers on our Macs and iPhones.
Let me just put this here: http://en.wikipedia.org/wiki/Just-world_hypothesi…
You people shock and awe me. It is 100% your fault most of the time, either by logging into a phoney website cloning what xbox.com looks like and being ignorant or having a trojan on your PC with keyloggers installed, there was no breach in security at microsoft. The only breach is your ignorance and failure to keep up to date anti virus on your PCs. P.S. Stop downloading or watching porn you pervs, thats how most of you end up with worm virus's.
you've clearly failed to read anything from anyone here. I've never logged into a phony website, I always check the urls of site. A virus? umm no. I scan my computer every day and with multiple programs to ensure safety, and my xbox profile itself has no personal info on it whatsoever and never did in the past. For 4+ years my account was safe and sound until all of the sudden everyone else is starting to get hacked as well. So did we all just randomly decided to start going on unsafe websites at the same time frame as well to get hacked?? NO.
Your ignorance of thinking all of us are getting our accounts stolen by phishing is just plain and utterly hilarious. When you randomly get hacked one day when you know you took every precaution and safety to prevent such a thing there is nothing left but some loophole int he system that is out of your control.
People like you who assume we were all stupid and were not careful to protect our property is what makes me facepalm daily.
Nice try, Microsoft employee. Troll harder.
This coming from the same person who banned thousands of innocent users and sent them emails calling them pirates because Microsofts security team failed at detecting pirated game copied disc. Which I might add they still continue to fail detecting. So to trust Microsoft a company who cannot even stop piracy on their own console, I don't think so. You ask me they need to fire the entire security team and hire a real one.
Dude, your ignorance is showing. I've been around the Internet since before you knew anything about it (original Netscape browser beta at 1200 baud) and I know better than to click on email links, not have virus protection on my pc, etc. I had exactly one friend listed on my Xbox live account (real life son). I wasn't socially engineered, don't download porn, and don't click on email links. Yet I was hacked, my security question hijacked, and password changed, and hundreds of dollars of charges made to my account. I was on the phone to Xbox watching the points being drained from my account but there was no urgency from them to check it out. So according to you it's my fault….geez.
Yeah my account was hacked in early Jan. Luckily I had no credit card attached to my account but they stole all my points on it and tried to freeload off of my gold subscription.
There is NO WAY that I was 'scammed' or fell for some 'phishing scam' trick to get my account hacked. That is such a lie. I never visit any unsafe websites and have never had a problem in the past with my account. Then one day I wake up to find some dumb fifa game was played on it will all my points stolen. Luckily I was smarter than whoever stole my account since I had safety nets on my windows live ID and got my account back by myself. I'm still very mad that I've lost my points forever and I'm still unsure if my account is 100% safe even though I changed my passwords. I also now required any console that isn't mine to re-download my profile if they waned to use it. Hopefully the safeguards I put in place will prevent anymore intrusions.
If it keeps happening then I might as well make a new live ID but I don't want to do that because that ID is tied to my other profiles for other places. It's such a pain and hassle and the sad part is the normal gamers (us) are the ones who pay while hackers run freely stealing and joyriding off accounts like nothing is wrong.
Same thing happened to me. The kicker was That I was at the gym, getting email updates that I was buyin points, which I was not. I called them and they said I was logged on and buying points. I told them I was not at home and to cancel all transactions and cancel the account. Approx. 125 dollars were stolen from me and they told me to call my bank after 30 days of “investigation” and then said they couldn’t find any wrong doing … Like being on the phone with a customer (a recorded message) while a theft is taking place. My bank refunded my money (graciously, thank you Wells Fargo) , but Microsoft dropped the ball. I have not renewed my account and might not ever again due to security concerns. My trust cannot be placed in Sony or Microsoft with any information.
Jason
Although I agree this is horrendous customer service by Microsoft, and that it is their responsibility to refund you and give you back access to your account, I don't think you should dismiss the fact that you fell for a scam in the first place.
"I am quite peeved that they are still insisting the abuse of my account was my fault. Fuck you Microsoft." If people had found a way to hack Xbox Live I think we would be seeing a much bigger impact on the service. So don't just say Fuck you Microsoft. Based on the fact that all you have to defend yourself is that you are careful online and there is absolutely no evidence of Xbox Live being compromised (Even though it is a fucking pain in the ass service.) I would say it is your activity online that allowed someone to get your details. Not really your fault as there is much more than just the easy to spot scams out there. There are viruses and many other methods all designed to get your details. You don't even have to log in with them, some can be a key logger. Anyway I just don't think you should blame the initial event on Microsoft when their is no evidence that it was on your end. Still good on you for getting this news out there about there horrible treatment of you and management of the situation. If fact the url of this site gives the idea that you were hacked and that the service is compromised. I'm not saying you should change it cause it works and is 'catchy' but don't try and blame everything on them.
So they make keyloggers for Mac now that steal XBOX live details? Had you have read the comments, I think you might have thought a little bit more about your statement. If you can't read everything posted previously, why bother leaving a comment?
Bear in mind, xbox live is the same password as msn messenger, hotmail, zune (if you have it), all rolled in to one account. There are plenty of ways to get a username and password in that instance. None of them involve a phishing scam or any malware on the account owners pc. There are programs/scripts out there which will just do random attempts to log in with passwords until it finds a good one. All MS needs to do on this one is set a rule where you get an email or the account becomes temporarily locked after a couple incorrect password entries. They do not have this enabled. Additionally, considering a simple online search about xbox live hacked account brings up multiple articles written by people in the gaming industry, I would say MS is taking more of an approach like Damage Control than anything else. There is evidence to suggest a compromise in security with the live service, it's just a question if someone is willing to accept what's out there as evidence.
Exactly, there even used to be an email template that you could send that would send the password reset to any email you choose. Videos of the steps are still on YouTube to this day, even though they no longer work. Evidence is ALL OVER the place that Live accounts are quite often compromised. This is one of the many reasons people have defected to other email services from MSN/Hotmail/Live.
I believe it is downright deplorable that the people feel the need to continue to insinuate that everyone affected by the hack were "keylogged" or "phished". Many I have spoken to work in IT, and a few such as myself use Macs and iPads as our computers for work and home. I know it makes you feel at ease to simply write it off as "our problem", but I assure this is not the case. As I have stated previously, this is likely an issue with a week API or an insider compromised our accounts either directly or indirectly. Do you know how easy it is to fool EA support into giving up your account details for EA? I have seen many accounts of this online, do you think this is not at all possible for Live support? XBOX Live phone support can be good at times but the support for the Live accounts themselves are downright terrible.
Regardless of any of that, 20 days is a ridiculous amount of time to resolve these sorts of issues. Banks do not take this long, retail stores do not take this long – anywhere else that did would lose customers by the droves. Microsoft knows they can get by with this because they know the likelihood of you defecting to another platform is slim-to-none regardless of being hacked or losing money.
For any of you waiting longer than 30 days, I would HIGHLY recommend filing a complaint with the Better Business Bureau. It does make a difference, and it lets other informed consumers know about the customer service complaints so they can also make an informed decision. I certainly wish I would have kept my Wii and Steam for Mac at this point.
Well obviusly you have all my thanks and well i don’t speak english very well but i try to explain what i am thinking about this.
Maybe you say great y win but well imagine that you have a windows phone 7 “linked” to your windows live ID the hacker can erase all the data black your cell phone and make it waste and what happend with all you have linked with your windows live ID like facebook tweeter or itunes store acount? all you do all you brought for nothing? all your money spend in xbox or itunes say goodbye? well i know y don’t speak english very well but i think you can understand what i thinking haha
It was never made out to be that way at all, and for some of us that are single parents and transplants to an area an XBOX is a way to socialize that is cheap. I, as a single-parent, traded in a Wii and sold some items on eBay to afford my XBOX so that I can keep in touch with friends and family in other states and have a stress release. Playing XBOX is a good way to socialize to some extent when you can't go out or anything like that with a kid at home and no babysitter. Having someone take away one of your few forms of stress release, and hinder you providing for your children at same time, is unacceptable.
It is my sincere hope that, as a non-parent, you continue to not breed.
I'm starting to wonder if there's not someone inside Microsoft (some low-level peon) who is selling this login info. It would match both Microsoft's company line (and explain why they haven't been able to close this security loophole despite months of complaints) as well as user's claims that they haven't been phished.
i was hacked last september and someone spent all my points on fifa 12 and i dont even play sports games. they also changed my password they told me i had to wait for 30 days but it was more like 3 weeks.
Please keep going. I had a similar issue. My account was hacked this past September. I called and reported it and was told it would be shut off for up to 4 weeks and then restored to me. I called back 6 weeks later as I had not heard from them nor gotten a refund for the $150.00 in purchases made on my account. I reported the charges as fraudulent to American Express and was told it would be fixed asap. 3 weeks later – I was FINALLY issued a refund, given my points back and had my account restored. The entire time – Microsoft kept saying that I must have given away my account access. I have never linked facebook or given any outside company access to my XBLA account – the ONLY way that it could have been hacked was a breach in MS security. BTW – their apology to me was an extra two months of Gold membership to make up for the time I couldnt use my account. I haven't touched my xbox or bought ANY xbox products since….
I was hacked 6 hours after New Years, great way to get the year rolling. Received an email from EA saying my password was changed, I was asleep during this and was not able to respond until about 3 hours later. I later found out my Xbox account was hacked as well and 19,400 point were spent on FIFA DLC. I called and put the claim in, 8 days later I receive confirmation that my account is under control and that there we no purchases made while it wasn't which clearly is bullshit since it's there in black and white. Talked to someone at customer service who sounded like he was 10 and now I'm waiting for the rest of my refund.
Hi,I have a similar story here. In 2006 I bought an xbox360 with call of duty2. A few months after that my friend told me to bring it over and we would go on xbl since he had internet and I didn't at the time. Well I did,I brought it over he went through the process of setting up the gamertag for me,using his email as the windows live id. well in 2009 me and my friend had a falling out. By this time I had internet,and really got into xbl. I had around 50-60 live arcade games and 10 or so xbox original games downloaded. So I poured quite a bit of money into my account with a continuous gold renewals via prepaid cards. Well one night I get a message on xbl via MSN messenger from him saying" watch this boitch" and then he signed out. The next day I had learned he changed my sign in credentials (password,security question etc.) I called Microsoft they said they would lock the account which they did,and launch a full investigation. A week later they emailed me saying they could find no evidence of tampering and were unlocking the account. Well i had been pretty much battling them from then on. They wanted me to try and request a password change from login.live.com which did no good since I didn't know the security question. I asked if I could just have them transfer the gamertag to a new windows live id,they said they couldn't do that. I added a new email account as a secondary but could not use it for password change retrieval but it kept sending it to his email,resulting in him trolling me. For the lulz. He doesn't even own an xbox! For 3 days I was on the phone with these customer service imbeciles with no resolution in site. Finally I gave up and took my loss. Created a new gamertag and started over again. All game licenses were gone,all that money wasted. This was in 2009. It's now 2012 and Microsoft got what it wanted,more money from me as they watched me eat crow. My gamertag was calebnlyssa,the first names of my son and daughter and Microsoft was acting like I was trying to steal the account from my friend. I admit it was my own daamn fault for letting him use his email when I first got xbl,but still I'm pissed. That's my story,I hope you all have better luck than I did. -Eddie (formerly calebnlyssa)
When I was hacked they accused me of giving out my information and that it was almost my fault that it had gotten stolen. Multiple charges later my bank was gracious enough to lock my debit account and refund my charges. A week later I finally gave up on Microsoft and logged back into my account and changed my tag and all information. I have my pseudo tag back but all kinds of gamerpoints I did not earn nor want.
The customer service at Microsoft regarding fraud is garbage! My account was hacked back in September. I found out on the day of my wedding reception when I tried to buy a pass on Pandora to play music at the reception and my card was declined. I checked my account to see that the hackers had taken every last cent I had left after the wedding. I immediately cancelled my card, changed my passwords, and contacted Microsoft. The hacker was Chinese or Japanese, and I found out because the hacker had all of my emails forwarded to his account so they could delete sales receipts from Microsoft. I sat on hold for over 30 minutes with customer service. When I finally got someone they couldn't tell me how it happened, or how the hacker was even able to transfer Microsoft points off my Xbox account, since I did not have it enabled. Like everyone else I was blamed for the cause. I asked to be kept in the loop, and I wanted the name of the person who had hacked my account so I could report them to the authorities and file a civil fraud claim against them. They refused. Apparently the hacker's privacy is more precious than my own. It took almost 2 weeks to have my account returned. My bank returned my money within days. It took Microsoft almost a month. I love my Xbox and the Xbox community, but this is unacceptable and left a real sour taste in my mouth. How a class action lawsuit has not been filed regarding this issue is beyond me.
If you want to see this in action, just google trade tang and then search xbox accounts on that site. There's people selling accounts left and right – looks fishy. M$ needs to get on top of this!
I was hacked on 12/28 and $80 of microsoft points (4 charges for 1600 points each) were charged to my account and these points were then transferred out along with another 2400 points I had on tap.
I traced the likely culprit to an Xbox Live application I installed from the Android market 3 days earlier though I cannot prove, however it seems very coincidental and I also found a post on Itunes Appstore for same app, citing the same issue: XBL account stolen with $100 charged to CC.
The app I downloaded was an app by dev Galaxy4Gamers called 1337pwn.com Xbox Live Friends. https://market.android.com/details?id=com.pwn1337….
I've filed a complaint with the FBI, as well as sent a nasty note to Android Market moderaters. Not sure anything will come of it. My account is still locked under investigation.
BTW, even though my account is locked, I can still log into it on my Xbox, simply for the purpose of loading my profile. As told by MS, only the 'online functionality', i.e. GOLD features are blocked.
Hello,
My xbox account was hacked over 3 years ago, I phoned them endless times, only to get know where. I the end I got refunded the 800msp that the person who hacked my account used to change my gamertag name. But this was despite my losing £100's worth of Arcade games and add-ons, not to mention all my online leaderboard rankings. I did all I could to get fully refunded for everything that was stolen from me, but all they gave me was £7 back. Microsoft completely killed me enthusiasm to pursue this matter, so they made me give up and I sold my xbox in exchange for a PS3. But one of the things that angered me most, was when I asked for this thief's details so that I could report them to the police, as I dont take kindly to being robbed, they told me they cant give me the person's details as it goes against there confidentiality regulations!
But now several years later, seeing all these people having there accounts hacked and Microsoft being as useless as ever and not helping there customers who have been robbed!, just makes me angry all over again. I hope everyone gets back what there owned and dont end up being robbed only from the person who hacked your account, but robbed from Microsoft as well x
My sons account was hacked 3 days ago and it was reported to microsoft. He also had xbox live for three months. I wonder if there is something about that. Well guess well find out sometime.
My account was hacked yesterday. 2000 Points were purchased and even an EA account was setup under my e-mail address. Called Xbox Live Support today, My Xbox Live Account has been locked and suspended, they put my case through to the Fraud Dept. Called my Bank to tell them to stop the payment going through – too late. Advised my bank to stop all payments to Microsoft Xbox. Over the 8 years of using Xbox Live – no problems with my Live Account whatsoever !!. As I work in IT, I know not to give out any personal information via e-mails and perform virus scans / updates daily. Last time I logged onto Xbox Live was prior to Christmas to perform the Dashboard update. I reckon Windows Live has been hacked or there is a security issue with the Dashboard Update (prob coincidence !!).
I have had my account successfully charged back in october.
Microsoft refunded me in november.
Got charged again in December and now the hackers have also spent the points they purchased.
Today they tried to buy more points using one of my old cancelled credit card, i received the email stating the purchase had failed.
I have just deleted all my active payment options from the XBOX Live, eventhough the call center said not to.
I dont want to risk getting charged again!!!
From now on it will be pre-paid card only for me even if they are a bit more expensive.
Interesting events going on at Microsoft. I have to question their whole story regarding the "we were unable to" lock the account. I think that internally that at the beginning they thought that a relative of Susan was doing this behind her back. Obviously after it started to hit the gaming sites, they went to cover their asses and started working on her problem right away. I think it would have been faster if she had gone to the local media and reported the fraud to them ( not sure if her local media would have paid any attention to her).
As far of as the statement from Microsoft regarding the part "there was no breach of Xbox Live" (like what has happened to Sony, Steam, etc). Here is something that I thought about after reading Susan's entire post. XBox Live doesn't have to be directly attacked in order to hack into XBox Live accounts.
Think about this, Xbox Live is tied to Windows Live which in turn can be linked with other services such as Facebook. So there is always a door slightly open. I mean, if they someone knows your Windows Live login (such as a hotmail account or MSN messenger) then they have access to your XBox Live account. That still doesn't answer why Susan's account was hacked. According to her, she didn't login to any other suspicious sites. However, that doesn't mean that you are safe. Malware can be a way to get this info.
So you see, Microsoft can cover their asses since they can say that technically Xbox Live was not breached. It just happens that some hacker used the backdoor that Microsoft leaves blatantly open.
Just thought I would add my name, my manager at work and another online friend to the list. I was just hacked today. They originally tried $75 worth of MS Points but they tried the expired CC I had on file. Then they did $25 on my active CC and transferred those points along with the 1,600 points I already had on my account to someone else. I noticed when I checked my activity on xbox.com that it showed the last game I had played was Fifa, which I don't even own and have heard it's used as a part of this scam. My manager just told that she had been hacked back in November for $1,000! Why hasn't anything been done to make Live more secure?!? When PS got hacked they immediately stepped up and addressed it. Why is it that MS can't seem to own up to their mistakes/problems? It's the Red Ring of Death all over again!
You should know that anytime an Xbox Account is hacked, it's either because you didn't protect your account, or because you gave out account info. If you protected your account, you wouldn't have even been in this situation to begin with…so yeah, it is your fault. The fact that it takes Microsoft so long to investigate is probably because so many people like you put "pizza" as their security question answer and then demand to know why they got hacked…Geniuses. It's also not your banks responsibility to make sure there is money in your account, that's yours. I guess when you signed up for Xbox Live, Microsoft should have demanded you to be responsible before you signed up…but I suppose they thought that was common sense?
Oh look, a clever idiot.
Oops, strike clever. How is working at Microsoft going for you anyhow?
What more could I have done to protect my account? My Windows Live ID used an email address unique to my Xbox only, the password was a random assortment of letters/numbers that had no relation with one another or to myself, my security question answers were the same. I had never logged into my Xbox account through a site other than xbox.com, nor did I even receive any emails that looked remotely like a phishing email. On top of this I run daily virus/malware/spyware scans on both of my computers (it's all set up automatically) so I don't believe any sort of keylogger etc was installed on my computers. I just don't see how I could've made my account more secure. What would you have done on top of what I had done already? I'd be interested in hearing suggestions so I can ensure my account will never be taken over again.
Those are all recommendations a trusted IT person would make, therefore there isn't anything you can do. Obviously this breach is more sophisticated than Microsoft is letting on, and people are trying to insult you and others and discount our stories for a couple of reasons:
1.) They work for Microsoft or a similar customer, they assume the few cases they deal with phishing are exactly the same as our cases. If they work for Microsoft, they do not like their job performance and security being put into question.
2.) They don't want to fear that the same could happen to them, therefore they exert their just-world hypothesis and treat us affected as inferior. Insulting us helps them to feel better about their insecurities that they themselves might be hacked.
You'll spend a lot and time and trouble responding to idiots like these, he only did it to troll you which is also clear by his choice of username. Frankly I find the insults, especially geared towards single parenting insulting and I respond in kind.
Chalk me up as another that was just hacked today, i'm tired of being told I was involved in some phishing scam when all I did was renew my annual family gold pack subscription. MS either has someone selling these user names and password internally or they dont know how it's happening.
I was also told I couldn't remove my PP account from my Xbox account if I wanted to be refunded it had to stay linked to my acocunt. $300 later here I sit waiting in Xbox Fraud purgatory wondering when I'll get my money back and if this will happen again.
Had my account hacked into yesterday. First I got an email from microsoft saying that my purchase for 1600 msps could not be completed (because my CC on my account is old and I haven't updated it). I then knew something was wrong. I was online and checked my account and noticed I have a new game in my played games list… Fifa 12. I also noticed that I now have 50 msps left when I had around 4000. I called them (Microsoft) immediately after finding this information and while I was on hold I went through and changed my email password as well as security questions. I also noticed during this that there was a new email address linked as an alternate email address, it said that the email is "pending confirmation". I jotted down the email address but decided to be sure to remove it from my alternate emails. When I got done being put on hold I explained the situation to the CS rep and he didn't want to bother taking the info about the email address and said that "this situation is going to be escalated". So basically he told me that he didn't want it because he wouldn't be handling the situation. As of right now that's all I have to say because I am still waiting for my case to be escalated.
also going to add myself to the list, hacked nov 6th, watched as the little scumbag took over my account while my brother was playing on his, phoned MS and they locked account for the investigation bullcrap.
Dec 3rd and investigation complete, monies refunded but still no account, they sent recovery details to mis-spelt e-mail address.
15 days they said it would take to change ONE LETTER in an e-mail…………………..i've now been waiting 40 days since their cock-up and 70 days since the initial account lock down.
Got here from Joystiq.
I'm sorry to hear this, Susan.
AnalogHype found out how the hackers are hacking accounts and Microsoft knew about the issue! http://bit.ly/zwjd4k
Good posting, brute force has been around for quite some time and it has always been easy to do so to Hotmail aka Live accounts. There are tons of listings, there are even people that have the listings from when they were stolen from their respective services.
http://www.skullsecurity.org/wiki/index.php/Passw…
Luckily, he removed the email addresses these passwords were associated with.
Simple solution to the problem.
1. lock Live account to device by IP or MAC and stop all billing unless MAC and IP have both been authorised.
2. When account is accessed from other place send a unique numerical text message to customers mobile phone which must be entered to authorise the new MAC or IP.
3. Changing email adresses requires a unique mobile phone confirmation number.
Authorising a MAC will allow for mobile device access for checking mail and other services that may be used on the go but having an authorised MAC/IP combo for financial transactions would stop people spoofing MAC then buying points unless they are on a system under your WAP IP.
This technique is used by my bank whenever I am using internet banking and could easily be implemented by MS.
I was hacked back in October 2011. It took 26 days for MS to restore my Gamertag, Game Score, & points. through the whole process they denied that MS/Xbox was hacked & blamed it on me.
Also I am on my 5th Xbox 360, due to MS' poor quality control.
Love Xbox & Xbox Live, but they need to improve their hardware, security and customer service.
I was hacked back in January 2010, I accidentally gave my friend my Live ID login information, and then his brother finds the login information, and buys… I think it was like $21.06 USD out of my parent's credit card, and they contacted Microsoft, it was alright, but I waited A LONG TIME to finally get back on to play. It's so sad how Microsoft can fix hardly any hacking issues nowadays.
When I log back into my account when it's finally reinstated, I find, ALL OF MY FRIENDS, GONE.
I wanted to really get back at my friend's brother.
How did this all happen? My friend told me he could get me free recon on Halo 3, so I did give him my login information.
On the morning of like, January something 2010, I attempt to login, but it says that the account was transferred elsewhere, and then I told my mom,
"Mom, on Xbox I was hacked."
I told her that I was hacked because I immediately knew that I was hacked, at first I thought my friend hacked me. She was like, "What do you mean you got hacked? Did you recover your account somewhere on your brother's xbox?"
I told her, that I didn't, then my dad calls Microsoft about this, I start telling lies to them, and saying I didn't give out any info, but then Microsoft says something like "It appears in our moderating, your son has given out his Live ID login information." then my dad and my mom, they start asking me, Did you give out login information to somebody? I told them lies for a while, and then I finally told them the REAL truth, I did.
Yeah, this story's going all over the place, but it was fixed like, 3 months later, I could finally get back on and play, however, I had to start all over again with friends.
I told my friend, that I hated him and I never trusted him again, but he told me that it was his brother, that was when I was outraged. I wanted to get back at his brother so badly, I just felt like taking all of their money out of their account.
Now, I know I said I was HACKED, but I actually fell for a scam.
While I am sorry to hear this happened to you, this is a bit different than what others are experiencing. These incidents are coming with little to no knowledge of how the accounts are obtained. I am doing some investigating myself.
Why did the site owner/author change the name of her own original article and/or updated the original article why? Did Microsoft request it?
I have been looking up problems like this and have found so many i think xbox needs to get some white hats (aka hackers hired by corporations ect to upgrade security against hackers) because no matter what they say it is clear they have a breach in security deny it all they want it's the masses and consumers who in the end have the final say but honestly if they dont want to admit it just work on it covertly instead of prolonging all of this crap and losing costumers and over all profit really im in high school and i can see this is not a good way to handle it whatever they are doing right now so white hats actually solve the problem and swallow your pride xbox is all i can say
Haven't been hacked or anything, but I'm definitely switching to prepaid cards as soon as I get up the money for a 12-month one.
Why did the site owner/author change the name of her own original article and/or updated the original article why? Did Microsoft request it?
I was hacked last night.
They stole my 2600 points to buy Fifa 12 content.
They tried to buy another 6000 points but my card attached to the account had been cancelled due to the recent PSN hacks so the transaction was declined.
I hate football, and EA.
The only EA game I have ever played is Burnout Crash.
Now, Fifa 12 is listed as a played game in my profile, but it shows the USA box art so it was someone (probably) in the USA that hacked me.
Microsoft are investigating and my account is now on hold.
I have no doubt in my mind that they gained access to my XB account via an exploit with the linked EA account that I had to create to play Burnout crash.
EA deny all knowledge and fob you off to Microsoft, Microsoft blame EA and nothing gets done about it.
You can't even unlink an EA account once it's been linked so it'll almost certainly happen again at some point.
Think I'm done with the 360 for good now.
If anyone has Paypal or a credit/debit card stored on their 360/PS3/Wii I would remove it now. It's not worth the hassles if you get hacked.
Is there a problem with the RSS feed here. Appears to be a missing link to me?
Goodbye MS, it's been real nice knowing you….
Let me start off by saying that I'm not a big gamer or anything like that, I just like to get on MW3 with some family and friends on occasion and turn on NetFlix when I need to. I've been on Xbox live from the day the 360 was released, and I've been on ever since. It's been the nucleus of my entertainment center at times, but now with AppleTV that is no longer the case.
My brother's account was recently hacked and since the "investigation" was taking so long he decided to go out and buy a PS3. He's been updating us via email and I cannot believe the way MS has chosen to address his issue. Not only does he not have access to his Live account, they've botched their troubleshooting efforts twice now by collecting the wrong information (Console Serial and Email Address).
Since he's my brother and one of the guys who I looked forward to gaming with I've decided to sell both of my Xbox's on Craigslist, cancel my Xbox Live Acount, and like him I too will purchase a PS3.
Good luck everyone…
person who paid for the bogus account should also be charged with fraud.
It’s not my first time to pay a quick visit this website, i am visiting this web site dailly and get pleasant data from here everyday.
I had the misfortune of my account being hacked also. I was woken by my iphone pinning to see multiple transactions on my paypal account to MS. I have reclaimed the funds (paypal were great) and contacted MS. They have suspended my account and it is still suspended. I subsequently went to log into windows live and was kicked out and MS forced me down a route of setting up an new password via their customer team. Since then I have not received verification and worse still i cannot even access my GT to play offline.
All in all this is an utter shambles from MS, I may as well throw the xbox out as its useless at the moment. It seems others have the same issue. And when you call MS, well…….i'd might as well speak klingon for all the good it does, i'd like to say they are inept……but they are far beyond that….they have created a perfect organisational structure and service department to answer no customer questions at all. Shambolic.
If you've been hacked, please ensure you visit the xbox live site online, click 'forgotten password' and go to the step for 'reset password' and select by email. You will then see a list of emails, which should only be yours. If there are extra ones it means they can access your account at any time by simply doing this online reset. This happened to me, a rogue @hotmail account was one. I've been waiting for 3 days for xbox to remove despite them refunding my points – so I'm just waiting for them to reset the password and steal the points again.
I have no idea how they got this email in the reset list as if I try and add it via Live then I get an email and have to verify it. This proves to me that Microsoft servers have been hacked and emails forced into gamer's accounts.
Got hacked, found out after going through account.live.com, that an unauthorized email address had been added to my profile. and through xbox.com found out there was a console that accessed my profile which didnt require password verification. I didnt even know that was possible!
This is absolutely incomprehensible how this can continue to happen. I have been hacked twice now. Once in Sep, and again this month! I Got everything resolved in 30 days the first time around, got my points back. Thankfully attempted charges never went through as MS Was using an expired CC at the time so they were immediately rejected.
This time however no charges were made, but yet again all my points were spent. Changed my passwords yet again. Ran a sweep of my computer and verified no keyloggers, I'm a huge advocate of Personal Internet security having trained many about it during my time as an IT in the Navy working for the NetSec division on my ship.
However my account was hacked a 2nd time. And the password was different from the one I had linked to EA for my xbox account. I would love to know how this is happening. "Victims of a scam" my ass.
Fix your shit Microsoft and EA! Tear down your FIFA FUT.
How this polish managed to bypass the security questions and long password? how the f* he get this? Is there a way to close my account because I'm in fear.
I just had exactly the same experience. The same email was used to reset the password on my Live account, and the thief (aided by Microsoft, since they automatically logged him into my Paypal account) then proceeded to buy 8000 MS Points. At this point I just happened to check my email, and caught him in the act, reset my Live password (twice, the first time he was faster than me and beat me to the "enter a new password" dialog). My Live account seems secure now, but Microsoft support have been VERY unhelpful, basically ignoring me.
What's worse, Microsoft have obviously known about this guy for at least six months, if not more, and they're doing absolutely nothing to stop it.
If you can read swedish, the whole sorry story is on my blog.
This happened to me a couple of years back, however it didn't take as long nor was as painful with MS as your case was. That being said they did take a good $800 out of my friends bank (used it to get some points at his house once) so the direct damage was just as great (and extremely awkward, as it wasn't my money).
Also should note that to get my account back the same processes were pursued, new windows live account and a simple password reset with a new Gamertag. I was surprised it was this easy, as logically that in itself is a massive security flaw and even though it got my account back, i can only imagine how bad that can turn out.
After being an Xbox live user since 2006, I was 'hacked' just 2 hours ago. I received an email from Paypal telling me that a transaction for £51 had been made and I knew something was up, so I quickly changed my password for both Xbox live and Paypal. I also phoned Microsoft up about the issue and they have apparently frozen my account (though I see no changes). — actually, it was frozen whilst I was typing this.
Nothing in my Xbox live account had been changed though. No additional emails and my password and the security question remain the same (I changed them both). I just had 6000 more Microsoft points on my account. After looking at the stories on here of how they bought Microsoft points then made family gold accounts, I figure I must have got lucky as after they spent the £51 on points my debit account was left with a mere £30 which wouldn't be enough for a family gold account. Who knows. Now to see how long it takes to be refunded with my money. Haven't got a clue how they got into my account in the first place though!
update it with the guys personal info please? so that everyone can know to avoid the thief like the disgustinf garbage he is
This is still happening word of warning don't link paypal account to xbl this is how I got hacked. I am selling my xbox at least Sony admited they were hacked microsoft think they are beyond reproch.
Currently waiting for a reply from Microsoft as my account has been compromised and £370 was stolen from my sisters bank account which resulted in the hacker buying nearly 65,000 msp. Absolutely furious with them!!!
to all of you having does kind of problem with hackers , here´s a good advise put a parent control on your account example : Gamertag X with 15 years and gamertag Y with 21 and there so gamertag y on x and everytime you will change your password on gamertag x or purchase something it will ask you your parent password and email(gamertag y) , already happen to me. lets say i make it possible i go to a person online on MW2 and tell him to prestige 10th me , he told me to give him my account and password from gamertag x … oh yes perfect i gave it to him , and after a while i was talking to him on another account and boom chat closed youre account have been hacked…. lol
and my account free like a bird…
)
well i started my xbox put recover my account and from my parent account gamertag y(put the email of gamertag y and it should appear both account y and x)
finally i recovered my account. and private chat him again , his expression was like" ….. WTF how are you talking to me with that account" well sillyboy im more intelligent than you and i called microsoft and that child got himself a permt ban
PS:put parental control on your account