This is the most sophisticated phishing scam we have seen so far. The phishing scam is in the form of an email informing you that your World of Warcraft will be disabled, the email then directs you to a web page to log in and “confirm” your account information. The web page you are directed to looks very much like an official Battle.net account login page and this is the reason this scam is more sophisticated then others.
The web page you are directed to looks like this:
Click here to view full page version
The email that is sent for this scam also looks very legitimate. However one of the links in the email directs to the phishing web site seen above. The scam email can be viewed below:
Greetings,
Account Action: Warning
Account Offense: Violation of EULA and Terms of Service - Transfer of Account Ownership
Details: An investigation of your World of Warcraft account has found strong evidence that the account in question is being sold or traded, and a dispute has been filed regarding your account ownership. Blizzard Entertainment can provide no details regarding the origin of the dispute. In accordance with EULA section 4, Paragraph B, listed below:
World of Warcraft -> Legal -> End User License Agreement
and Section 8 of the Terms of Use:
Blizzard Entertainment -> Legal -> Terms of Use
A 3-hour probationary suspension is pending on this account, awaiting confirmation from a specialist. A warning has been issued. The investigation will be continued by the Account Administration team to determine the any further suspensions. If the account in question is found in violation of the EULA and Terms of Use, further action will be taken. Be aware that any additional inappropriate actions may result in the permanent closure of the account.
Thank you for respecting our position on this matter.
=========================================================
It is recommended that you verify legitimate ownership of the account here:http://us.battle.net/login?service=https2F%2Fbattle.net%2Findex.html
THIS IS THE LINK THAT DIRECTS TO THE PHISHING SCAM PAGE. THE LINK LOOKS LIKE A BATTLE.NET LINK. IT IS NOT A BATTLE.NET LINK. MOVE YOUR MOUSE OVER THE LINK, IN THE STATUS BAR OF YOUR COMPUTER YOU WILL SEE THE LINK ACTUALLY DIRECTS TO: http://is.gd/HN6mAny further changes in account information, including email address, security question answer, account name, password, and/or account ownership name will be duly noted during the investigation and may or may not lead to further disciplinary action.
=========================================================Any disputes or questions concerning this account action can only be addressed by Account Administration. To learn more about how Account Administration is able to assist you, please visit us at http://www.blizzard.com/support/wowaa/.
Account security is solely the responsibility of the accountholder. Please be advised that in the event of a compromised account, Blizzard representatives typically must lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.
Please visit the World of Warcraft Policies and Terms of Use Agreement: http://www.blizzard.com/support/wowgm/?id=agm01712p and http://www.worldofwarcraft.com/termsofuse.shtml for further information.
Regards,
Billing & Account Administration
Blizzard Entertainment
http://www.blizzard.com/support/accountadmin/
How to protect yourself from this scam:
NEVER click on a link in an email without checking where the link is going. You can check the true direction of a link by moving your mouse over the link and checking the status bar on your computer.
PLEASE REMEMBER BLIZZARD ENTERTAINMENT WILL NEVER ASK YOU FOR ACCOUNT SPECIFIC INFORMATION OVER THE INTERNET. THE ONLY TIME BLIZZARD ENTERTAINMENT WILL EVERY REQUEST INFORMATION FOR AN ACCOUNT IS OVER THE PHONE. NEVER PROVIDE ANY OF YOUR ACCOUNT DETAILS TO ANYONE.
RSS feed for comments on this post. TrackBack URI