Xbox live accounts being hacked?


Recommended Posts

I do not fail to realise anything.

Did i say those accounts was brute forced ? Absolutely not.

I said from an outsider perspective the security looks to be bad. And i still don't understand why people here lose time saying otherwise. Those are basic things about security. Generic error messages. Freezing an account after too many bad login attemps. Ask for secret question when someone login from a different system and/or from a different country. Ask for CC 3 digits security code. This is not rocket science this is the basis students learn in school. 1 layer of security aint enough and will never be.

If the security looks bad from the outside then why all people assume this is impossible some of those accounts got compromised from MS side and not from clients side?

I'm not naive enough to assume all those are phishing. If i still had my XBox Live account i would remove my CC from it asap.

It's simply not plausible in a short amount of time.

It really depends on the password. But like you I don't think it is plausible with the number of people being affected. Even if they can try a new password every 10 seconds, it would take quite some time unless the user was using a dictionary word with no variation.

I don't buy into the phishing explanation either. Usually when there is phishing going on someone is able to point to the culprit site. Given the scale of the "hacking" I find it very hard to believe that no-one has noticed that an email purporting to be from Xbox/Live/Microsoft has actually come from and is directing them to another address. Would have to be a fairly advanced form of phishing. May be possible by using one of these new domains that allows non-latin characters to be used? Remember some comments at the time they were started that they could be used for phishing due to similar non-latin characters.

No clue how relevant this is, but from the past few years, brute force hacking become increasingly easier and faster.

http://www.mandylionlabs.com/PRCCalc/BruteForceCalc.htm

I haven't bothered to read through that site but if it's about any of those theoretical gpu based crackers then that won't work with Xbox or any other websites. They are limited by the websites ability to process request and even for Microsoft it's not in millions/s.

Well if anyones been reading this thread from the start you,ll have seen some of my posts and the endless hassle ive had in getting myy cash back.

The saga continuess... yip thats right

Back for the sequel, tho this times it seems the bank has finished there investigation and contacted Microsoft/Xbox. Microsoft told them, they had refunded me and the case was closed. So bank took back the money.

So back again now wrestling with Microsoft. Watch this space.....

On November 22, 2011 my XBLA account was compromised. I was billed for $54.61 for MS points I did not purchase. Since then I have been trying to get the money back via phone support.

They have been unable to aid with this. They keep telling me that all phone support can do is give one month of xbox live gold. With phone support like this I don't trust them at all anymore! If they have no power, why do they even have jobs? That could be an automated system and be this effective.

Every time I talk to support, I'm told the investigation is still ongoing, but that there's no new notes on the case. This investigation was suppose to take 30-31 days, but it's been 63 now. I have been trying this whole time to get my money back and them take their points back!!! They will not do it!!!

As it stands, my account is frozen, and I still do not have my money back. As of now I have NO faith in xbox support as this has taken months and nothing has been done.

I urge everyone to stop using XBLA for any purchases! If you get compromised/hacked, Xbox, Microsoft, will just keep your money!

Hacked on October 31st and I've still got nothing back yet. It's only $25 but I'm tried of having to deal with this. Called about 5 times now and every time they make note that I called and say it's being escalated or being sent to a supervisor and I should get a call back in a few days. Yet every time it just disappears into a black hole and I never hear anything.

It was held up in the past because they needed an xbox serial # when I only have a games for windows account which they knew the first time. They don't call to let you know this of course. The latest excuse is that they needed an email address not tried to my account. Everyone is nice and apologizes but they don't seem to know what's happening with the fraud department. The whole system they have in place to deal with this needs to be fixed.

  • 4 months later...

Sucks it can be exploited in that way by anyone who wanted to put a bit of time in to it, I can believe it too.

I remember back in 2004 all you needed to "jack" someones UK Hotmail account was to know there last name, favorite food or colour. That was it you could easily reset someones password just by knowing the answer to a simple pre defined question. In comparison US accounts had all this additional security such as asking for your address, phone number and other info.

Hopefully Microsoft will look in to that as it sounds like a pretty major issue if that article is true. Could explain how someone managed to hack Major Nelson's account the other year: http://kotaku.com/5504145/xbox-live-directors-account-hacked-are-you-next

Very interesting read, what a well targeted and thought out process :o :cry: The internet....

You just knew everyone screaming phishing scams (MS included) last year were talking out of their arse.

The annoying part about all this is not being able to use my CC to pay for stuff on my Windows Phone - meaning I have to run it through my operator's phone bill. Thankfully there's no charge, but it's annoying to realise your bill is ?5-?10 higher then you expected because you forgot your paid for some apps on your second day into the bill.

All CC info is tied to the account so if I add my CC info to use on my Windows Phone, jackers can then grab that info via my XBL GT. Very frustrating.

Very interesting read, what a well targeted and thought out process :o :cry: The internet....

You just knew everyone screaming phishing scams (MS included) last year were talking out of their arse.

Wait - if true, this again pretty much echoes what MS had been saying all along that the XBL network was not hacked? This is classic social engineering/phishing, just that MS never admitted that it was occurring with their support staff. :shiftyninja:

So..

You just knew everyone screaming OMG Xbox Live is TEH HACKED!!!11!! last year were talking out of their arse.

I woke up this morning to check my bank account(payday) and realized my total balance was smaller than my expected paycheck. I clicked to look further into the account and found that I was billed almost 80$ from microsoft. I immediately got on the phone with them. While on hold I checked my email to find 4 emails from them. 3 regarding points purchases, and a 4th titled 'Account Switch Confirmation'. That email stated that my region was successfully changed to Russia from the US.

Well. Currently Microsoft locked my account, pending an investigation. I've found that 4 of my friends also had their information stolen and used last night. I'm in New York, 2 are in the same town as me, 1 in maine, and 1 in california.

Microsoft claims the investigation will take roughly 25 days. I'm ****ed. They claim I'll be 'compensated'. I'm planning on getting my money back, and terminating any financial connection I have with them. If they were half a decent company would compensate me immediately. They guy claimed 'Well we have to make sure you didn't do it.' A) he could see that my xbox was used from the US last night. B) Another xbox with a matching serial number was accessed from Russia at about 7am. Then at 10am the SAME xbox was accessed from New York again. I told him "Well spaceman, I have to use more primitive forms of travel and as of right now it is impossible for a middle class new yorker to travel that fast."

While he found that funny, 25 ****ing days. I'd highly suggest that if you don't purchase stuff on a daily basis on xbox live, remove your credit card information just to be safe.

it happened to me a few months back, 3 days later thank god it was just points, got them back, oh and 3 different 1 month codes for xbox live gold lol!! no worries it shouldn't take long

Wait - if true, this again pretty much echoes what MS had been saying all along that the XBL network was not hacked? This is classic social engineering/phishing, just that MS never admitted that it was occurring with their support staff. :shiftyninja:

So..

You just knew everyone screaming OMG Xbox Live is TEH HACKED!!!11!! last year were talking out of their arse.

And your point? So it wasn't hacked, but the fact remains that it is Microsoft's fault and the issue needs to be resolved. A simple change in authentication ala what Apple does with their ID's would solve this for the most part.

And your point? So it wasn't hacked, but the fact remains that it is Microsoft's fault and the issue needs to be resolved. A simple change in authentication ala what Apple does with their ID's would solve this for the most part.

My point? Just keeping audioboxer's facts straight because he loves to hammer that somehow Xbox live was hacked and in the same manner as PSN.

You can calm down now :p

A better option would be two factor authentication similar to google and a good number of people raised it to MS guys in that hotmail thread.

And your point? So it wasn't hacked, but the fact remains that it is Microsoft's fault and the issue needs to be resolved. A simple change in authentication ala what Apple does with their ID's would solve this for the most part.

I think his point was Xbox Live wasn't hacked, as many sites and users had erroneously assumed. Doesn't make the situation any better for those who had their accounts stolen, but the network as a whole wasn't hacked.

Actually I just noticed yesterday that it was asking me for a code to authenicate my laptop.

When logging in on xbox.com? It was talked about a while ago on the major nelson podcast that they were going to a 2 factor auth (like gmail) but I have yet to see it on mine.... tried it just now and still was able to get right in on my account from a new computer.

My point? Just keeping audioboxer's facts straight because he loves to hammer that somehow Xbox live was hacked and in the same manner as PSN.

You can calm down now :p

A better option would be two factor authentication similar to google and a good number of people raised it to MS guys in that hotmail thread.

Ehh I said nothing about it being the same as PSN, cause, it's not.

I was commenting on the whole finger being pointed at people and MS saying "your fault, you signed your password away on some dodgy site/email", when it was as clear as daylight it wasn't as simple as that.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Again, this is an irrelevant attempt to attack the messenger. The truth does not require any justification.
    • Removed the blue and underline as you did not post a link. This would also  be considered spamming.
    • Why it's almost impossible to produce a smartphone in the United States by Hamid Ganji If you look at the back of some Apple products, you can see the famous phrase “Designed by Apple in California, Assembled in China.” This phrase appears on products from one of the largest smartphone brands in the United States. These products are designed in the U.S., but their manufacturing takes place in China, India, Vietnam, or even Brazil. But why can’t Apple, as one of the largest American tech companies, produce its iPhones on U.S. soil? The idea for this topic came to me after the Trump Foundation launched a smartphone called the T1 and claimed that it was designed and built with American values in mind. However, this claim did not last long, as it was revealed that Trump’s phone was actually a rebranded HTC U24 Pro, with only a gold case and minor internal component changes. You see? Even a phone that is supposed to represent American values is manufactured in China. With a gross domestic product (GDP) exceeding $32 trillion, the United States is currently the world’s largest economy, while China ranks second with around $20 trillion. On the other hand, the United States is by a wide margin the global leader in various technological fields, and American companies spend hundreds of billions of dollars annually on research and development. From Apple and Google to Microsoft, Lockheed Martin, Boeing, and others, American tech and industrial giants lead their foreign competitors in many sectors. The United States also has no shortage of smartphone brands. Apple, Google, and Motorola are among the major brands in the smartphone market, collectively holding a significant share. However, the vast majority of their products are manufactured outside the United States. So why is it that the world’s largest economy, home to the most advanced technology companies and industrial powers, cannot produce a smartphone on its own soil? Let’s explore this question together. Even threats to impose tariffs won’t work After Trump entered the White House as the 47th President of the United States, his administration adopted strict tariff policies. One of these policies was the imposition of a 25% tariff on smartphones manufactured outside the United States. Trump said he “had a little problem” with Apple CEO Tim Cook over producing smartphones outside the U.S. So he thought that threatening a 25% tax on imported phones might force Apple to bring manufacturing back to the United States. “I have long ago informed Tim Cook of Apple that I expect their iPhones that will be sold in the United States of America will be manufactured and built in the United States, not India, or anyplace else,” Trump wrote on Truth Social. Image via The White House Although Apple currently manufactures some of the iPhone’s chips in the United States with TSMC's help, it still shows no willingness to shift full iPhone production to the country. At the time, renowned Apple supply chain analyst Ming-Chi Kuo wrote on X, “In terms of profitability, it’s way better for Apple to take the hit of a 25% tariff on iPhones sold in the US market than to move iPhone assembly lines back to the US.” However, manufacturing a smartphone in the United States is not as easy as it might seem, and many technical and economic barriers are involved. The lack of necessary manufacturing hubs There is a clear reason why many companies prefer to manufacture their products in China. China has established itself as the main global manufacturing hub for international companies, and over the past few decades, large contract manufacturers have emerged there, allowing companies like Apple to outsource production. One such example is Foxconn, which also manufactures some Apple products in India. Building the infrastructure required to produce smartphones in the United States would require tens of billions of dollars in new investment. Factories would need to be built, essential manufacturing equipment would have to be installed, and, most importantly, a skilled workforce capable of operating these systems would need to be recruited and trained. The United States currently lacks the core infrastructure needed to manufacture smartphones, and for this reason, many companies prefer to outsource production to Chinese contractors rather than spend tens of billions of dollars to build that infrastructure, which is significantly more economically efficient. Additionally, building such infrastructure in the United States could take up to a decade, ultimately leading to a significant increase in the product's final price for consumers. Shortage of trained labor in the U.S. compared to China Decades of serving as a global manufacturing hub have allowed China to build a massive talent pool in the production sector that is almost unmatched worldwide. Today, if a company chooses to manufacture its products in China, it can be confident that the workers involved in production have years of experience in their respective roles and are capable of producing high-quality goods with minimal errors. Even if we assume that tens of billions of dollars were invested in building smartphone manufacturing infrastructure in the United States, finding skilled workers would remain highly challenging. Apple CEO Tim Cook visiting the iPhone 6 assembly line in China in 2014. Image: Tim Cook on X In a 2015 interview on CBS’s 60 Minutes, Tim Cook said the main reason Apple isn’t producing in the US is a lack of skills. "China put an enormous focus on manufacturing, in what you and I would call vocational kind of skills. The US over time began to stop having as many vocational kinds of skills. I mean you could take every tool and die maker in the United States and probably put them in the room that we're currently sitting in. In China you would have to have multiple football fields,” Cook said. Also, in 2017, at the Fortune Global Forum in Guangzhou, Cook once again emphasized the importance of highly skilled Chinese workers. “China has moved into very advanced manufacturing, so you find in China the intersection of craftsman kind of skill, and sophisticated robotics and the computer science world. That intersection, which is very rare to find anywhere, that kind of skill, is very important to our business because of the precision and quality level that we like. The thing that most people focus on if they’re a foreigner coming to China is the size of the market, and obviously, it’s the biggest market in the world in so many areas. But for us, the number one attraction is the quality of the people,” Apple CEO said. Higher labor costs in the United States Producing almost any product in the United States is more expensive than in many other countries, and one of the main reasons is the higher cost of labor in the U.S. According to the Bureau of Labor Statistics, median weekly earnings of full-time workers in the United States were $1,235 in the first quarter of 2026. Meanwhile, the average annual salary in China's private sector in 2025 was RMB 71,590 (US$9,961). In many parts of the world, the weekly wage of an American worker is equivalent to several months of income. Another important factor to consider is that in the United States, the workforce capable of working on a smartphone assembly line is highly specialized and therefore commands higher-than-average wages. According to an estimate by Bank of America, producing an iPhone in the U.S. is technically possible, but “iPhone cost can increase 25% purely on higher labor cost in the U.S.” However, this 25% increase applies only if final assembly is performed in the United States while components are still sourced from China or elsewhere. In this case, the price of a base iPhone would rise from $799 to around $1,000. But in another scenario, if Apple were to produce the required components for the iPhone within the United States, production costs could increase by more than 90%. Trump’s dream for a “Made in the USA” iPhone might never come true In a free-market capitalist economy, one of the primary responsibilities of any CEO is to maximize profit. Using Apple as an example, Tim Cook’s role is to maximize the company’s profits so that it can fund research and development for new products and invest in areas such as artificial intelligence, while also keeping shareholders satisfied. Therefore, it is entirely understandable that Apple would choose not to bring its manufacturing back to the United States and instead keep production in countries where labor is cheaper, and products can be manufactured at a lower cost, thereby maximizing its profit margins. What is your opinion about manufacturing smartphones in the United States? If you are an American citizen, would you be willing to pay hundreds of dollars more for a smartphone made domestically in the USA? Let us know in the comments.
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      153
    4. 4
      Steven P.
      72
    5. 5
      FloatingFatMan
      65
  • Tell a friend

    Love Neowin? Tell a friend!