Compromised PoE Accounts: Stolen Items and Hacked Accounts - Discussion and Leads

"
General questions:

Has this happened to anyone using standalone accounts?

If so, did you use different passwords, one for the e-mail and a different one for the PoE account?

If so, does your mail get any hits on sites like 'haveibeenpwned' ?


If you read though the 100s of posts. You will see that it's not a user issue it's a GGG issue within the poe2 game.

Most state their password is strong
2fa on steam
Don't use 3rd party sites
Don't use 3rd party apps
PC is clean, nothing else effected

Yet we keep having people talk about passwords, virus etc. the only thing in common is poe2.
"
Malejas#1960 wrote:
"
General questions:

Has this happened to anyone using standalone accounts?

If so, did you use different passwords, one for the e-mail and a different one for the PoE account?

If so, does your mail get any hits on sites like 'haveibeenpwned' ?


If you read though the 100s of posts. You will see that it's not a user issue it's a GGG issue within the poe2 game.

Most state their password is strong
2fa on steam
Don't use 3rd party sites
Don't use 3rd party apps
PC is clean, nothing else effected

Yet we keep having people talk about passwords, virus etc. the only thing in common is poe2.


Actually, I wouldn't wish anyone to be hacked... but the people who blame it on the players and say they're to blame for viruses, real money trading, etc. should also be hacked, then maybe GGG will react to that
Someone hacked using standalone client? Too much 2fa mention, like problem somewhere between steam and linked to the steam account
"
Someone hacked using standalone client? Too much 2fa mention, like problem somewhere between steam and linked to the steam account


I am not sure how much it needs to me be mentioned. But the only common in all of these posts

Poe2
And
In game trading.

Some have noticed strangers being able to idle in their hideouts and suspect it has something to do with session keys etc. so now you have people saying after you trade, switch your hideout layout to kick everyone, switch back, log off then back on.

I can't confirm any of that hopefully that's a GGG conversation very soon. But I have seen steam and standalone players hacked. I have since stopped reading unfortunately because that's a fun part of the game and what makes farming worthwhile.

I think 80% of those Hacking problems could be solved if ppl could pick a username and even change it to login.

Sites also just should block more.

Many hackers probably use old leaked mails with passwords and simply try them out. I just looked up my Microsoft account and there are tons of failed login atempts daily - so not having the Mail as login would be a huge step to make all thos leaks pointless.


Also i wouldnt even be suprised if peoples e-mails were hacked aswell to bypass security measures.

By the way - does Steam 2FA even work with POE? Can login with the website and poe client without linking steam? If not can you even use the Trading post without linking?



Also i think what would be really important is to act hard on real money sellers. The main reason why there is so many hacks etc. is because there is real money involved.
I think a zero tolerance policy would be good - anyone that buys from those real money sites should be permabanned. Only if the userbase that buys those things stops to exist then the sellers will aswell.

Also people probably know that lots of those offers besides having a high chance of beeing a scam or stealing your data often probably also get their items in questionable ways.
Last edited by _N0ctus_#6387 on Jan 8, 2025, 10:02:37 AM
"
_N0ctus_#6387 wrote:
I think 80% of those Hacking problems could be solved if ppl could pick a username and even change it to login.

Sites also just should block more.

Many hackers probably use old leaked mails with passwords and simply try them out. I just looked up my Microsoft account and there are tons of failed login atempts daily - so not having the Mail as login would be a huge step to make all thos leaks pointless.


Also i wouldnt even be suprised if peoples e-mails were hacked aswell to bypass security measures.

By the way - does Steam 2FA even work with POE? Can login with the website and poe client without linking steam? If not can you even use the Trading post without linking?



Also i think what would be really important is to act hard on real money sellers. The main reason why there is so many hacks etc. is because there is real money involved.
I think a zero tolerance policy would be good - anyone that buys from those real money sites should be permabanned. Only if the userbase that buys those things stops to exist then the sellers will aswell.

Also people probably know that lots of those offers besides having a high chance of beeing a scam or stealing your data often probably also get their items in questionable ways.


Again a full post of

Passwords
Hacked emails
Maybe a hacked PDF you downloaded 8 months ago

None of this wants your bank info, money they just want your poe2 divines lol.

It's not passwords
It's not hacked emails
Its something within the game and exploit that GGG hopefully finds soon, it would be nice if they commented about this to stop the finger pointing but from their point of you they have unlimited free public relations so why even shed light on the issue.

20 people can say they have strong passwords change their passwords. Nothing else is compromised. They don't use third-party apps or websites.

The next five replies would say maybe your passwords compromised... Lol
"
Malejas#1960 wrote:
Again a full post of

Passwords
Hacked emails
Maybe a hacked PDF you downloaded 8 months ago

None of this wants your bank info, money they just want your poe2 divines lol.

It's not passwords
It's not hacked emails
Its something within the game and exploit that GGG hopefully finds soon, it would be nice if they commented about this to stop the finger pointing but from their point of you they have unlimited free public relations so why even shed light on the issue.

20 people can say they have strong passwords change their passwords. Nothing else is compromised. They don't use third-party apps or websites.

The next five replies would say maybe your passwords compromised... Lol


Exactly this.

That "hacked PDF" thing gave me a laugh, thought the exact same yesterday.

People should actually open their mind a bit from a technical perspective, instead of blindly saying ALL PLAYERS DID RMT or IT MUST BE THE OVERLAY.

This game is a far more valuable target in this state right now than POE1. Just compare the playerbase. Makes it even more attractive to code shady software and reverse engineer things.

I did talk a bit to Crainus (Threadowner) the last days about this topic, and we already got some info on software that was able to decrypt packets back in 2018 (Reverse engineering POE game protocol).

Beeing able to read player IDs, player health etc just from sitting in your party. To make the server send this information you had to do an interaction inside the party. (This just as a small information refering to the manual of the tool)

Sure 6 years have passed, but it's just highly ignorant to think this isn't a possiblity here people didn't extend or already made better tools for this.

Security systems intact?
Yes maybe detection systems are running: But ever heard of a Bypass?

There is a lot of non-public shit that doesn't get wide-spread.
And why would you spread it?
Method would get fixed pretty fast by the game dev.
add me to the list of robbed people madge

came here to find some answers from ggg but seems they are actualy hiding???

also was it a mistake to write the support about this and now my account could get fully locked? thats just insane!
"
x420#1909 wrote:
add me to the list of robbed people madge

came here to find some answers from ggg but seems they are actualy hiding???

also was it a mistake to write the support about this and now my account could get fully locked? thats just insane!


Everything is fine, I suppose more than one account that has addressed this problem has not been unblocked yet. It follows from this that GGG clearly understands that they have problems somewhere and are trying to solve it, probably, I'm not sure. You and I, guys, you know, gave our time for the good, so that this serious error would be removed (I HOPE). We are heroes!
"
x420#1909 wrote:
add me to the list of robbed people madge

came here to find some answers from ggg but seems they are actualy hiding???

also was it a mistake to write the support about this and now my account could get fully locked? thats just insane!


Welcome to the club of the hacked who insecure passwords, stolen emails, and downloaded infected PDFs 8 months ago ^^

Yes, GGG doesn't say a word, and even if you've written to support, it'll won't be read for a few months anyway. You've still got plenty of time to play and supply the hackers with new currency.
Last edited by Esukho#3565 on Jan 8, 2025, 2:17:18 PM

Report Forum Post

Report Account:

Report Type

Additional Info