Account hack/scamm

So while I am playing WOW I suddenly notice an open ticket. When clicking on that ticket I noticed somebody had made a ticket in my name saying that “I needed to reset my phone due to technical difficulties and please adjust the email to an to xxx” For me an unknown mail. Luckily I noticed that and was in time to change my info and such back before my account could get stolen.

So I made a ticket saying that this was a scam and that I didn’t understand how this could have happened. I have an authenticator on both my wow account and my personal mail. The GM that contacted me said that someone made a ticket using a fake ID but since they can’t store those it was already deleted.

SO here is my question even with all those security measures in place someone can still make an fake mail from outside asking your authenticator to be removed and your mail address changed with out them having access to either one of those. Cause once they changed to mail address and removed the authenticator they can do what ever they want with your account since they changed the mail address and get all the info there now.

I am wondering why people would even ask in one mail to have those things changed and blizzard just blindly following that request. I can’t imagine that someone on the same day gets their authenticator ruined and wants a new mail address. I wished blizzard would secure this better by not allowing those to be changed at the same time. I even had my phone number attached to my account. But all my info got either removed or changed, luckily I was in time to change it all back. So people can just send out a fake mail and ask for everything to be removed and there is nothing you can do if you are not behind your PC to notice this in time.

What are your thoughts?

Hey Milkyway,

An incident like this can be very distressing indeed and you did well being as vigilant as you were during this. Please do note this suggests another party knows your email and possibly your usual password as well, and I strongly recommend you follow our security recommendations here. Rest assured we do verify all these requests as thoroughly as possibly, as seems evident by the fact a Game Master you spoke with mentioned it had a falsified ID attached.

As for allowing “anonymous” contacts, that is necessary to allow people to contact us. Ironically, if you forget about an authenticator and ever need it removed, you may not be able to login to your account to submit a ticket about it. This is one of many reasons we do not require a login in those cases, but we do ask for additional ownership verification which will be thoroughly checked and verified before we’ll consider assisting.