Phished XBox Live Accounts In Circulation

Have a read and let us know what you think.
Post Reply
User avatar
jockavelli
Herald of RHPG
Herald of RHPG
Posts: 274
Joined: Wed Mar 05, 2008 7:20 pm
Location: Livingston, UK

Phished XBox Live Accounts In Circulation

Post by jockavelli »

Phished XBox Live Accounts In Circulation
By Christopher Boyd

Today we came across a collection of approximately 270 sets of login details that have apparently been Phished via a fake XBox Live login page. The list, some 27 pages long in Word format, would allow people to access stolen XBox Live accounts, some of which may have credit card details stored against them (along with other forms of personal information, of course).
Image

The list itself is actually around 300 or so entries, but it seems some of it is duplicate and / or obviously fake data, entered by people annoyed at the Phishers the list has come from (as a side note, I should add it's never a good idea to enter fake info on Phishing pages - it not only makes it harder for people who wade through this info looking for victims to contact, it also opens you up to potential retaliation attacks from the Phishers).

An additional "bonus" of grabbing Live ID data is that you can use it to check out EMail accounts associated with it - not a great situation, and one of the reasons I've never been too keen on "one login to rule them all" situations. We've already seen some people boasting on forums about the info they've pulled from various EMail accounts associated with the list - how quickly "stolen XBox account" becomes "stolen everything else".

This list seems to be in circulation on a number of hacking forums; the majority of the accounts were phished between November and December of last year. Despite the relatively long time that's elapsed since the data was first collected, a lot of the accounts still seem to be accessible based on comments we're seeing on those underground sites. It seems someone might have put their personal stash on "general release" to gain some kudos with others.

We've passed the stolen data onto Microsoft, and we're sure they'll move swiftly to lock down the accounts involved.

I feel bad for the people that this happens to, however if they aren't checking the login pages properly well then it's their own fault.

That said i have never been phised(to my knowledge), but i bet i'd be more than pissed if it did ever happen.

Anyone here ever had details phised before????
Bringing NEWS & VIEWS to RHPG
Image
Image
User avatar
Backslash
Possible Ally of Robinhood
Possible Ally of Robinhood
Posts: 744
Joined: Sun Jan 04, 2009 1:51 am
Location: New York
Contact:

Re: Phished XBox Live Accounts In Circulation

Post by Backslash »

man that does stink, thats why i took my dads card details off my account... took 30 days to get off but its peace of mind for me. i hopefully will never be phished.
Image
User avatar
HaGGardSmurf
Ally of Robinhood
Ally of Robinhood
Posts: 4088
Joined: Tue Feb 03, 2009 9:46 am
Location: Alberta, Canada

Re: Phished XBox Live Accounts In Circulation

Post by HaGGardSmurf »

Never been phished (to my knowledge) TBH I have never seen a phishing site that you couldn't tell pretty easy it was a phisher...

Also in reference to that comment in the article discouraging you from leaving fake info, that doesnt make sense...

These phishers only log what is in the text box's user and PW, and maybe the date... Even if they log your IP who cares what are they going to do with it? Spam you with packets? So phone your ISP, they will give you a new IP.

Also, it doesnt make it harder to find information... I have seen phishing logs they like:

Name: X
Password: X
(Maybe the date and IP, but not usually)

Name: X
Password: X
(" ")

if one says "Go f--k yourself" and password is "your a looser" it literally takes no effort to scroll down to the next one...
User avatar
ohnoacucumber
Bandit
Bandit
Posts: 120
Joined: Mon Mar 16, 2009 9:29 pm
Location: Ohio?

Re: Phished XBox Live Accounts In Circulation

Post by ohnoacucumber »

Once by myspace i got my account stolen because i didnt check the address bar because i clicked a link off google that was wrong and my acount was gone :o


~cucumber :shock:
Image
Post Reply

Return to “Front Page News”