Compromised PoE Accounts: Stolen Items and Hacked Accounts - Discussion and Leads

"
"

What happened to those that had no standalone account, or got hacked recently, is still unclear.


A week ago, my friend got robbed. He played only through Steam, didn't link his email. After he got robbed, he went into his account settings and found out that hes account had been linked to an email he didn't know.


Since I have never connected a secondary login method, I don't know if any further confirmation is required.

Could it be the admin account hacker just assigned a secondary login method with admin UI in the background to gain access?

The hacker doesn't even need to know the player password if this is possible.

It's like the hacker creates a throwaway steam account and attaches it to standalone player.
Or create a throwaway standalone account for steam-only player.
And it can extend to other login methods as long as on the same platform.

Later on just remove the attached throwaway account after stealing items so no one would notice. But the hacker failed this step on your friend?


"
"
"

What happened to those that had no standalone account, or got hacked recently, is still unclear.


A week ago, my friend got robbed. He played only through Steam, didn't link his email. After he got robbed, he went into his account settings and found out that hes account had been linked to an email he didn't know.


Since I have never connected a secondary login method, I don't know if any further confirmation is required.

Could it be the admin account hacker just assigned a secondary login method with admin UI in the background to gain access?

The hacker doesn't even need to know the player password if this is possible.

It's like the hacker creates a throwaway steam account and attaches it to standalone player.
Or create a throwaway standalone account for steam-only player.
And it can extend to other login methods as long as on the same platform.

Later on just remove the attached throwaway account after stealing items so no one would notice. But the hacker failed this step on your friend?




This is just a speculation, but I'm guessing the hacker added an email and password through the admin panel to log into the friend's account.
I have been a long time supporter of PoE. I returned to PoE2 because I new it would be a great game. I have no doubt of that.

I made a Youtube channel several weeks ago and kept everything positive.

I was greeted with great success and had 1000 subs in the first week. I was so happy. Some of the RMT sites could not help visiting my 40k View video and posting "maxroll" over and over. Lets fire some shots here. They are involved in RMT and are likely some of the major kingpins.

After telling them I would not influence viewers to go their site, all of the sudden I started having to moderate the channel because of hate posts. To further escalate things these same people downvote all my videos now and crush any chance of actually enriching my viewers with the proper content. Think about this number 1500 like with 8% downvote.

That my friend is a toxic community, and to have it come from them sickens me. I thought it was only on the forums.

Let's move on.

We almost all paid at least 30 bucks to play. You only stream on twitch and no youtube? Why is that? I know why and shame on you.

Next we have this issue of hacked accounts and some round about answer of someone was hacked at GGG and you fail to clarify who, what, when, and how it affects each of us.

The remedy for this is simple.

I will delete my account. Everything on Youtube as well. The whole channel. I will never play anything from GGG EVER AGAIN.

See the badges you really messed up here. I wasn't even hacked. Do you have any idea if the server has permanent backdoor access to what obviously is linked to RMT? Why would an RMT hack accounts, they aren't smart enough to sell divines they can make?

I will cancel every card that has been used to purchase anything from your site and will send you a written letter that must be signed for that you remove all of my data to prevent "future" incidents.

I am very sad that this must be posted but since it is nothing short of the truth, weep in shame.

This post will be up for a couple hours before I delete myself or you ban me.
Everything in here is a fact so do what you must.
One sad Exile
"
"

What happened to those that had no standalone account, or got hacked recently, is still unclear.


A week ago, my friend got robbed. He played only through Steam, didn't link his email. After he got robbed, he went into his account settings and found out that hes account had been linked to an email he didn't know.


that makes alot of sense ... he could link the account thro the PoE admin tool,

after getting hacked i changed everything on my account so didnt end up checking but thats probably the case
Last edited by Crainus#7059 on Jan 16, 2025, 9:10:03 AM
They hacked my acc which was linked via Steam (it all happened after the trade for the ring which he quickly canceled because I gave him EX). Not only did he steal everything from my account(POE2), he even changed my email and password on Steam I managed to recover my account barely after 3 days after I contacted Steam Support) just to add that I have over 50 or more games on Steam. He replaced my email and password on Steam without me they get any notification on my email as I always get. I know who did this to me, I have his name screenshot 93lvl sorsores (I don't know if I can write his name ingame). I informed GGG about the situation that happened to me (I sent them all the screenshots that I made it when I contacted STEAM SUPORT as proof) but after that GGG banned me i cant believe, I don't know what to say...... MY DISAPPOINTMENT IN POE2 I CAN'T DESCRIBE TO YOU
Spoiler
[Removed by Support] i need help does anyone know anything or have a similar problem
Last edited by JC_GGG#0000 on Jan 16, 2025, 2:00:01 PM
"


Since I have never connected a secondary login method, I don't know if any further confirmation is required.

Could it be the admin account hacker just assigned a secondary login method with admin UI in the background to gain access?

The hacker doesn't even need to know the player password if this is possible.

It's like the hacker creates a throwaway steam account and attaches it to standalone player.
Or create a throwaway standalone account for steam-only player.
And it can extend to other login methods as long as on the same platform.

Later on just remove the attached throwaway account after stealing items so no one would notice. But the hacker failed this step on your friend?




I tested this on my account - it does work for your second scenario.
You have to confirm any new link, but only via email.
So if you have a standalone acc and want to link steam, you have to confirm this by email.
If you only have steam and want to link a standalone account, you have to confirm it by your new email.
So yeah, for users without a standalone account the hacker could just use his own email and password and the user would never get informed about this new link. They could both login without problems since the user still uses the known steam login and the hacker could use his own email/password and also receive the unlock code. Not sure how easily this can be unlinked tho - at least I dont have an option for this (but I dont have an admin panel :o) )
Last edited by justanotherlockedaccount#3122 on Jan 16, 2025, 5:36:22 PM
"
They hacked my acc which was linked via Steam (it all happened after the trade for the ring which he quickly canceled because I gave him EX). Not only did he steal everything from my account(POE2), he even changed my email and password on Steam I managed to recover my account barely after 3 days after I contacted Steam Support) just to add that I have over 50 or more games on Steam. He replaced my email and password on Steam without me they get any notification on my email as I always get. I know who did this to me, I have his name screenshot 93lvl sorsores (I don't know if I can write his name ingame). I informed GGG about the situation that happened to me (I sent them all the screenshots that I made it when I contacted STEAM SUPORT as proof) but after that GGG banned me i cant believe, I don't know what to say...... MY DISAPPOINTMENT IN POE2 I CAN'T DESCRIBE TO YOU
Spoiler
[Removed by Support] i need help does anyone know anything or have a similar problem


if you could msg me privately your evidance i would aprecciate it seems like an interesting read
My ticket has been open for 24 days now and no response. I read somewhere that GGG only keeps their protocols for 30 days because of data protection. Fits in well with your stuff if you need to respond in a few weeks, you can also say that unfortunately we no longer have any logs to check
"
Esukho#3565 wrote:
My ticket has been open for 24 days now and no response. I read somewhere that GGG only keeps their protocols for 30 days because of data protection. Fits in well with your stuff if you need to respond in a few weeks, you can also say that unfortunately we no longer have any logs to check


Interestingly, GGG themselves claim that data is only retained for 30 days, yet they take even longer to respond to your messages. This provides no help to the victims; GGG is merely punishing the victims further and driving us away from the game.
Was anyone able to get their account unlocked in the meantime? I feel like they just took the money, hacked us (or at least lacked security to prevent it), locked everyone and deleted all emails.
Last edited by justanotherlockedaccount#3122 on Jan 18, 2025, 2:40:47 PM

Report Forum Post

Report Account:

Report Type

Additional Info