PDA

View Full Version : [Ubisoft_Account] Stolen Uplay-account



Pages : [1] 2

Kaname1304
12-30-2012, 12:22 PM
Just got the same problem a couple of hours ago and I don't have to mention that I'm pissed off as **** right now since I can't do anything to take it back!
Hope someone can help us as soon as possible. :mad:

anders_190
12-30-2012, 12:41 PM
Totally agree with you there. It ruined my weekend pretty badly too. :(

The weird thing is that the confirmation for the changed info is sent to the new mail, not the old so you are totally locked out from all of your games while waiting for any responses from Ubisoft. I noticed it when creating this new account for contacting Ubisoft Support that the confirmation on email change gets sent to the new mail and not the old.

I did see this one after creating this thread so it doesn't seem to be that unusual: http://forums.ubi.com/showthread.php/742313-Can-t-login-to-uplay-Forums

Would be nice if these issues would be prioritised. As far as I can see, they should be working today. :)

Squanchy83
12-31-2012, 03:33 AM
I received the exact same email. All my games linked to uplay are unplayable since 24th December. I just opened a ticket to have it resolved. Was it fixed in your case?

Kaname1304
12-31-2012, 10:26 AM
Still waiting, though the support actually asked me more details. Luckily I already finished Far Cry 3 or I'd be even more pissed off right now :P

UbiHawk1ns
12-31-2012, 04:16 PM
Anyone having this issue, if you would please send me a Private Message with your account username and email address, I will be happy to help. Please do not post this information on the forums, as it is visible to all. Also include the reference number for the ticket you submitted via our Support Site (http://support.ubi.com).

anders_190
01-01-2013, 02:27 AM
Anyone having this issue, if you would please send me a Private Message with your account username and email address, I will be happy to help. Please do not post this information on the forums, as it is visible to all. Also include the reference number for the ticket you submitted via our Support Site (http://support.ubi.com).

PM'd. :)

Happy new year also!

diesalittle
01-01-2013, 05:50 AM
Anyone having this issue, if you would please send me a Private Message with your account username and email address, I will be happy to help. Please do not post this information on the forums, as it is visible to all. Also include the reference number for the ticket you submitted via our Support Site (http://support.ubi.com).


Pm'd. have also just had this happen to me

Greyvorn2
01-01-2013, 08:59 AM
This happened to me as well. I was two days into Far Cry 3. Trying to find help and support on this issue is terrible. Especially as I have found that I have had to create another Uplay account to log a support request about my stolen account. Ubisoft really should be jumping all over this (holiday or not). I guess they don't want bad press.

CoooolRaoul
01-01-2013, 09:31 AM
Same thing here, PM sent.

I'm very suprised since the stolen account was using a strong password (randomly generated)

How can this be possible?

ilbarbagianni
01-01-2013, 10:39 AM
PM'd me too. Happy new year

OuPoot_ZA
01-01-2013, 10:54 AM
I also PM'd. I really hope this gets looked at ASAP.

Barnsey09
01-01-2013, 11:01 AM
Me too. Similar thing happened with Origin some weeks ago.

madeup01
01-01-2013, 11:47 AM
PM'd me too. Happy new year all

kerafardd
01-01-2013, 12:36 PM
Account just stolen too. I was also using a strong password.

Once again, DRMs only piss off fair users. Pathetic.

ToiletenTaucher
01-01-2013, 12:59 PM
Greetings from Germany!

Same problem here!...
Just received that weird email that my account data has been changed by some very strange emailadress with the domain "playbay.su"...
Pls publish a help thread or something like that, because lots of people seem to have this issue. (saw them at Facebook Ubi-Support, Forums, Friends)

Volaz
01-01-2013, 01:23 PM
Hi from France

exact same business here too ...

My account data has been changed by a email adress "...@playbay.su"
I can't get access to my Uplay account anymore, I can't change password cause my email has been modified and is no more in your database, so I can't play ubisoft game online.
I have sent a ticket to support but no response for now.

Aure772
01-01-2013, 02:19 PM
Same thing here, PM sent.

I'm very suprised since the stolen account was using a strong password (randomly generated)

How can this be possible?

I Think that Ubi Uplay accounts have been hacked (on ubi servers) and accounts modified by a hacker.
That will explain :
- We receive the same email notification
- We can't login or retrieve our password (email address changed without our permission !)
- We are a lot of people with same problem !!!!!!!

I just check my computer : no virus, no spyware, no malware... I always check my security !
The only think I have install is Uplay with my new game and since that date, my account have been hacked (This is an old account furthermore...).

Ubi please do something !

kerafardd
01-01-2013, 02:33 PM
The notification mail was sent to my real adresse and to uplay1104102@playbay.su

Here we go :
http://www.google.fr/search?client=opera&q=playbay.su&sourceid=opera&ie=utf-8&oe=utf-8&channel=suggest#hl=fr&client=opera&hs=VI3&tbo=d&channel=suggest&sclient=psy-ab&q=%22playbay.su%22&oq=%22playbay.su%22&gs_l=serp.3...5434.6516.0.6654.2.2.0.0.0.0.69.132. 2.2.0...0.0...1c.1._wJKV3siKxA&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&bvm=bv.1355534169,d.ZG4&fp=303ae57c45bb9217&bpcl=40096503&biw=1647&bih=936

Russian websites, what a surprise...

What's more, it obviously is an intrusion into Ubi's network. My password could not be bruteforced. Again, pathetic.

Aure772
01-01-2013, 04:24 PM
qdsl464@yandex.ru

Russian website too...

Alphaksli1
01-01-2013, 05:05 PM
Happened to me too... I hope Ubisoft gives a solution to this soon and offers some compensation too as well as strengthens their protection system ...

Space_Hippy
01-01-2013, 07:02 PM
Hi,

I was hacked too, looks like a Russian again = rus-nik-89@mail.ru

I've been unable to play Far Cry 3 for 2 days now, I'm totally locked out of my Uplay account & can't even play Far Cry 3 in offline mode!?
Uplay doesn't recognise my current email addy so I can't change the password!
I had to register another account with my old Hotmail email to report it here! (I have PM-ed Hawk1ns24)
I'm worried that I am unable to get a Support Ticket to get this sorted, especially as I have invested a lot of time in this game!

It seems to me that Ubisoft has had a massive attack on its servers!?

K.

Aw4ter
01-01-2013, 08:51 PM
PM'd too. Happy new year

prefix3331
01-01-2013, 09:15 PM
I'm in the same boat.. playbay.ru , i've looked up the domain and it seems its hosted by http://ispserver.com/
I've sent a mail to their abuse mail which is abuse@ispserver.com more than likely this is a server used for alot of bad ****. (www.playbay.ru) i mean.
Looks like a linux server with its own mail system to me, all our accounts are probably stored on there atm.. including our emails n ****, and it's up;

PING playbay.ru (94.76.205.132) 56(84) bytes of data.
64 bytes from 94-76-205-132.static.as29550.net (94.76.205.132): icmp_req=1 ttl=55 time=28.7 ms

anders_190
01-01-2013, 09:45 PM
The mail that stole my account was some Gmail-account actually, no russian mail. That said, it could always have been changed after that too. Will be interesting to see what Ubisoft Support has to say about all of this and how they will secure their systems so this hopefully wouldn't happen again.

prefix3331
01-01-2013, 09:55 PM
Either there is an exploit in uplay (which i hadn't updated for months until i got this email) their servers have been hacked, or we've all been hacked. I use anti-virus and regularly scan my computer. I'm a certified Networks Administrator, and i find this really horrible, consider the people who have billing information connected to their accounts. Maybe this is just the tip of the iceberg, alot of users haven't gotten their email/pass changed yet, some haven't noticed yet, some just haven't reported it. I wonder when we'll be seeing this thing in the news.

gennavar
01-01-2013, 10:04 PM
Looks like hacked here too about 3 hours ago :(
Support ticket raised and PM sent .....

alamar3
01-01-2013, 10:29 PM
Got an email about 8 hours ago... PM sent and support ticket raised.

Why was there no confirmation email sent when changing both email *and* password? Surely a basic security measure... :-(

anders_190
01-01-2013, 10:36 PM
Got an email about 8 hours ago... PM sent and support ticket raised.

Why was there no confirmation email sent when changing both email *and* password? Surely a basic security measure... :-(

It's been sent to the hackers mail. Try changing your email on your new account to another you own and the confirmation-email is sent to it. If anything, the confirmation email should be confirmed using both your old and new mail. Should be a bit safer I guess.

prefix3331
01-01-2013, 10:39 PM
You shouldn't be able to change the e-mail unless you contact support, simple as that :)

poduser
01-02-2013, 12:19 AM
The email address used to steal my account was at a playbay.su address.

I've replied to the email and i had to create a new account just to log this complaint and submit a help ticket since you can't do anything without an account and it's hard to do that when your account has been stolen.

sasquire2
01-02-2013, 12:31 AM
Yup, got this email myself and account cannot be accessed.
And the whole "you need your account to contact support over this" just makes you laugh (in a bitter, angry sort of way).

prefix3331
01-02-2013, 12:31 AM
I know right.. so annoying.. You should be able to submit a ticket without an account.. For anyone who missed the post from the Ubisoft representative in this thread, go back to page one and read what he said, then PM him.

kerafardd
01-02-2013, 12:41 AM
What about credit card numbers ? If you previously bought something from Uplay, can the credit card number be discovered by logging into Uplay client or website ?

poduser
01-02-2013, 12:42 AM
How many of you folks that got hacked were using a trainer of some kind?

thetongatonga
01-02-2013, 12:47 AM
I had not logged into Uplay since last summer. I got the email yesterday and am in the process like everyone else trying to get this whole debacle straightened out.

kerafardd
01-02-2013, 12:53 AM
How many of you folks that got hacked were using a trainer of some kind?

Not me.

Hey, I just noticed something strange... The setting allowing my Uplay client to connect through a proxy was enabled... I didn't remember that being enabled by default and I never enabled it myself.

prefix3331
01-02-2013, 12:59 AM
How many of you folks that got hacked were using a trainer of some kind?

Nor me. I'm a legit gamer. I haven't been using my ubisoft account (or uplay, which i only use for Anno) for quite a while, then i get this in my face in the new year :) I just want to make sure i keep the game i bought, as well as not lose my account, and if they did lose my account information, i want to see some sort of action being taken..

(I'm sure there are people who are much much MUCH more frustrated than i am at the moment.)

poduser
01-02-2013, 01:14 AM
Well it took me an hour but I just changed every game/online password I have.

Ubi do you folks have any ideas why so many people are getting hacked on the same day? Some of these guys it sounds like haven't used their accounts in ages. Is it possible that somebody got into your systems and either did some sql injection or got a hold of some hashes or user information?

Since many of these seem to be redirecting to email addresses at playbay.ru and playbay.su it might be good business sense to block any account changes to those domains until we get this figured out.

Also for the hell of it what do you guys, and Ubisoft think of the idea of posting the email addresses they were changed to so we can make an organized effort at fighting back and notifying ISP's etc.?

prefix3331
01-02-2013, 01:20 AM
Well it took me an hour but I just changed every game/online password I have.

Ubi do you folks have any ideas why so many people are getting hacked on the same day? Some of these guys it sounds like haven't used their accounts in ages. Is it possible that somebody got into your systems and either did some sql injection or got a hold of some hashes or user information?

Since many of these seem to be redirecting to email addresses at playbay.ru and playbay.su it might be good business sense to block any account changes to those domains until we get this figured out.

Also for the hell of it what do you guys, and Ubisoft think of the idea of posting the email addresses they were changed to so we can make an organized effort at fighting back and notifying ISP's etc.?

Don't use the same password for every single thing you have online :)

And we don't know yet if they got the passwords (which SHOULD atleast be encrypted) my guess is someone has found a way to login to an account without the password, they're simply trying it with known emails.

Lord_Starwolf
01-02-2013, 01:20 AM
This is exactly why I hate extra services outside steam that I need to use to play my games. Honestly the whole uplay thing sucks anyway... I'm never going to purchase something online that isn't steam.

My email that had my changes notifying me also had a ...playbay.su address. I've never used a trainer or anything else for that matter. Hopefully we all get our accounts back.

OuPoot_ZA
01-02-2013, 01:22 AM
When are they going to look at these cases? I'm sitting with Far Cry 3 I payed a lot for but cannot play due to this guy stealing my account and Ubisoft taking forever to adress it.

prefix3331
01-02-2013, 01:54 AM
When are they going to look at these cases? I'm sitting with Far Cry 3 I payed a lot for but cannot play due to this guy stealing my account and Ubisoft taking forever to adress it.

Hopefully they are already investigating it, but the website says there won't be much staff available 1.jan.

That's probably why these people/this person picked this particular time to start stealing accounts..

RonFerrier
01-02-2013, 03:01 AM
Add me to the list.
Playbay.su email address, occurred Jan 1

PM sent.

Time for a press release, management of the security compromise, and customer remuneration. Reality is if you are going to force us to use another DRM on top of Steam you are on the hook for securing your servers which obviously hasn't been done adequately. For the love of god disable account changes until you get it sorted.

Greyvorn2
01-02-2013, 06:00 AM
So i just rang my local Ubisoft help line and spoke with a person in the UK. Completely Useless. Told me that they are all away on holiday. I tried to explain the situation but I dont think she cared to much. Just kept saying that I should appreciate that there was nothing that could be done because there was nobody there. She still thinks however that my ticket that I logged will be " responded to today", whatever that means. I think its time to start letting others know the pathetic response Ubisoft has for its customers.

erbotto
01-02-2013, 08:39 AM
I got account Stolen.
Ubisoft need a police report to be active on that?
this account i'm using now has beed crated to be here to type this replay.
My account stolen is Smere.it
AccountSupport@ubi.com Your account information has been changed 31/12/2012 18.04 2.8 KB
AccountSupport@ubi.com Uplay Password Change Request 31/12/2012 18.03 3.2 KB
AccountSupport@ubi.com Your account information has been changed 31/12/2012 18.02

Than got a mail ref changed into this email : <d1mqaaaashow@gmail.com> <<< someone used this email to open a youtube gaming channel, - i dont know if it's the same for other ppl.
Waiting for you.

stainmasterg
01-02-2013, 08:54 AM
Stolen account here too. Yesterday. playbay.su again.

Brotown22
01-02-2013, 09:24 AM
It turns out mine was stolen back at the beginning of december. Though not a playbay address. Oblomov321@mail.ru. While this guy is probably smarter than me (not that hard) I'm willing to bet I'm a lot bigger. Can I have his home address, ubi? A trip to Russia AND the opportunity to take care of business in more of a "hands on" manner sounds like way too good of a time to pass up

RonFerrier
01-02-2013, 10:06 AM
I'm sure there are more than a few of us who would gladly take the opportunity to join you in russia. Companies should start publishing locations for this type of stuff so we can be more effective than the police.

erbotto
01-02-2013, 10:30 AM
lol guys i know we are all rage... but do not get the wrong way :)
I really I hope youtube will close this channel, that will be a nice message for all and just a little satisfaction.
i've no baby thing, no faircry 3 , just AC3 as new game.

hdonk007
01-02-2013, 11:53 AM
My account is another one on the casualty list. *sigh*
Edit:
playbay.su too

anotherthomson
01-02-2013, 12:52 PM
I actually got my email on the 25th of December, but I ignored it - thought it was a phishing attempt. Turns out that it was real. Hmph.

Anyway, for what it's worth - my computer is virus-free (as far as I can tell), I haven't lost any other accounts , and I haven't downloaded anything strange at all recently (certainly no trainers, or anything like that). So I'm thinking that the problem might be on Ubi's end.

Oh, and my email was addressed to 'anton.patsarr@gmail.com', whoever that is.

anders_190
01-02-2013, 01:09 PM
I got my first response from the Ubisoft Support. They wanted extra confirmation that I was the right person (name, mail, username and date of birth) so hopefully my account will be accessible soon. I hope everything get sorted out soon enough for everyone. :)


I actually got my email on the 25th of December, but I ignored it - thought it was a phishing attempt. Turns out that it was real. Hmph.

Anyway, for what it's worth - my computer is virus-free (as far as I can tell), I haven't lost any other accounts , and I haven't downloaded anything strange at all recently (certainly no trainers, or anything like that). So I'm thinking that the problem might be on Ubi's end.

Oh, and my email was addressed to 'anton.patsarr@gmail.com', whoever that is.

I wonder how many people that just deleted the message or got stuck in a spam-filter or something. :(

Xaraxx2
01-02-2013, 01:14 PM
I submitted my Support Ticket 15min ago. It's really annoying that you've to create a sedcond account to gain the the control over your first account.

Alphaksli1
01-02-2013, 01:48 PM
My question number one is why does not Ubisoft or EA use confirmation email as a part of their methods in preventing account takeovers.

If I change my email address in Steam, I get an email that requests me to confirm the change. Ubisoft and EA just sends me an email and basically tells me that it seems that I have moved to Russia or Ukraine or any other Eastern Europe low life country and successfully changed the email and password etc.

Maybe I am being a bit unreasonable here, but why on Earth isn't such an easy protection method used in these 'so-easy-to-steal' game accounts. Then they at least had to hack email provider at the same time too.

prefix3331
01-02-2013, 02:33 PM
My question number one is why does not Ubisoft or EA use confirmation email as a part of their methods in preventing account takeovers.

If I change my email address in Steam, I get an email that requests me to confirm the change. Ubisoft and EA just sends me an email and basically tells me that it seems that I have moved to Russia or Ukraine or any other Eastern Europe low life country and successfully changed the email and password etc.

Maybe I am being a bit unreasonable here, but why on Earth isn't such an easy protection method used in these 'so-easy-to-steal' game accounts. Then they at least had to hack email provider at the same time too.

I know right? It's such a simple process and adds so much security.. i hope Ubisoft really gets it for this, i mean.. handling account security in such a bad way, and then trying to become a part of Steam.

anders_190
01-02-2013, 03:36 PM
Just got my account back, I can log in on it using Ubisoft.com but not in the Uplay-client for some reason. Will try or check with them what's wrong if it doesn't start working soon enough.

The thief that stole my account uses the mail brendanjuno@gmail.com

Hopefully Ubisoft get their act together and fix these security issues soon enough.

EDIT: Just got into my Uplay-account too, it didn't like my new password (to many symbols).

Trisher2013
01-02-2013, 03:41 PM
Good for you. I hope we others can get our accounts back as fast as you.

anders_190
01-02-2013, 03:45 PM
Good for you. I hope we others can get our accounts back as fast as you.

I really hope they solve it soon for the rest of you too. I followed Hawk1ns24's suggestion on the #6 post in the thread. The rest of you should do it to since everything seems to be done through their Technical Support.


Anyone having this issue, if you would please send me a Private Message with your account username and email address, I will be happy to help. Please do not post this information on the forums, as it is visible to all. Also include the reference number for the ticket you submitted via our Support Site (http://support.ubi.com).

theheptadragon
01-02-2013, 04:32 PM
My account was also affected on the 31st. I realized this morning that I have my Uplay and Facebook accounts linked, so I was able to log in by connecting to Facebook and reset the email/password. Filed a ticket & sent a PM anyway to make sure Ubi is aware of how many accounts were affected by this hack.

FWIW, I don't have many Uplay-enabled games either (and I've been playing them without cheats).

cbebopgamer
01-02-2013, 04:38 PM
Mine was just hacked. I checked my uPlay login just hours earlier. The new email was a gmail account. Ubisoft made a major disaster with this. BTW, how am I supposed to feel confident that the account won't be stolen, again? This is still happening to people, after all. Ubisoft, REMOVE THE EMAIL CHANGE OPTION! I am simply furious.

hdonk007
01-02-2013, 04:43 PM
Mine was just hacked. I checked my uPlay login just hours earlier. The new email was a gmail account. Ubisoft made a major disaster with this. BTW, how am I supposed to feel confident that the account won't be stolen, again? This is still happening to people, after all. Ubisoft, REMOVE THE EMAIL CHANGE OPTION! I am simply furious.

Well that's highly embarassing - I guess even if you get your account back if the attack is live, there's no guarantee you'll keep it...

Trisher2013
01-02-2013, 05:37 PM
Can anybody else confirm that he or she gets his/her account back? I'm still waiting and want to play again...

cbebopgamer
01-02-2013, 05:38 PM
Can anybody else confirm that he or she gets his/her account back? I'm still waiting and want to play again...

If you don't need to be logged in to play the game, then you can start Uplay in offline mode. You can find it under Settings.

Space_Hippy
01-02-2013, 06:16 PM
If you don't need to be logged in to play the game, then you can start Uplay in offline mode. You can find it under Settings.

Not so, I've tried doing that & it has never worked, I'm totally locked out of my whole game.
It's been over 24 hours since I contacted ubisoft about this & I've not heard a squeak back from them, I appreciate that it has been the holidays but I've not seen any official statement from ubisoft saying that they are aware of this problem & things are in progress to rectify it.
Not Good.

Trisher2013
01-02-2013, 06:17 PM
I know this but on the one side Anno 2070 does not allow to play without being logged or if so you need to be logged in to deactivate it. On the other side I bought the DLC package via amazon before i recognized that my account was stolen. I also cannot change the 'stay offline' settings after started ANNO 2070 because it seems to deleting the saved account information for offline playing.

Skiedragon81
01-02-2013, 06:28 PM
I got hacked and am now trying to get through to support, i did change mine back by going through my ps3 into uplay since ur sn is linked to ur systems, then login with ur user name on ubi and change it back, there has been rumors flying around that uplay accounts are getting hacked and then sold by hackers- funny how ubi has draconian drm but doesnt have this covered for gods sake its a dutch hotmail linking to a USA account why does that not throw flags up in ur system? Didn tthis just happen with ur last update and u promised us it was fixed whats up?

c100_radio
01-02-2013, 06:38 PM
Me too..

I have loged a PM with support.
Had to create a new account to log in here

Trisher2013
01-02-2013, 06:48 PM
Sometimes I think the Ubisoft CEO is sitting at his desk and laughs

alamar3
01-02-2013, 07:18 PM
Just an update: got a reply to my support ticket about 6 hours ago - unfortunately it got marked as spam so I've only just found it. Asked for the same details I'd provided in the original ticket (full name, email address, username and date of birth) to confirm my identity. Hopefully it will get read this time...

Ajcrash
01-02-2013, 07:45 PM
Got hacked too, email used was: uplay21145511@playbay.su. Email hit my inbox at 2:56 am local time.

After 40+ minutes on the phone (mostly on hold) I got everything sorted out. All my Uplay points are still their. Not sure if the hacker was looking for info or just screwing with folks because they could.

louisbs2
01-02-2013, 08:28 PM
Just had mine stolen!

eGe7in
01-02-2013, 09:00 PM
My account got stolen yesterday too. I just submitted a support ticket and sent a PM to Hawk1ns24 and am now waiting to continue playing... I have to say Ubisoft has pretty poor security in Uplay. It is of course annoying to always enter a pin code when I log in to Steam from new computer but at least it prevents something like this from happening...

louisbs2
01-02-2013, 09:16 PM
Origin & U-Play must be made by the same people.. Shocking security!! I had my origin account stolen a while back too!
wwertop23@hotmail.com << Email used to steal account

Yet with Steam.. It required a pin sent through email & text to my phone to let me login.

xnelliewilsonx
01-02-2013, 09:27 PM
Just got my message too. They stole my account. Put the name Hukr, email address as uplay21232600@playbay.su. WTF? I haven't used uplay in a long freakin' time because it sucks. I only signed up for the free multiplayer character in Assassin's Creed Brotherhood. Uplay is practically worthless and now it appears to be detrimental. Way to go Ubisoft. You know I have to tell everyone I know to stay away from Uplay now. Uplay should be called Ufuqs.

louisbs2
01-02-2013, 09:36 PM
I got a quicker reply posting on there facebook page.. sort this out.

louisbs2
01-02-2013, 10:09 PM
Account recovered :D
Moan on there facebook lol

ste312
01-02-2013, 10:41 PM
this is really poo ive been waiting for 2 hours now and no reply nothing ive emailed moaned asked questions, pm'ed the other guy nothing

kryton01
01-02-2013, 10:46 PM
Mine was hacked yesterday. Ive PM'd Hawkins24 so hopefully he can help. Hopefully this will be sorted soon. Had to set up an additional account just to log into the forum.

Alphaksli1
01-02-2013, 10:47 PM
this is really poo ive been waiting for 2 hours now and no reply nothing ive emailed moaned asked questions, pm'ed the other guy nothing
2 hours, seriously? I've waited for 60 hours.

ste312
01-02-2013, 10:58 PM
2 hours, seriously? I've waited for 60 hours.

and i feel for you and you have every right to have yours sorted before mine

super14
01-03-2013, 12:55 AM
Stolen here too uplay21213207@playbay.su, fortunately was able to recover via PS3 but now I'm changing all my passwords, thanks Ubisoft!

poduser
01-03-2013, 03:19 AM
No response yet to my support question on the ubisoft support website. And that Ubisoft guy that posted on the first page hasn't responded to the PM I sent either.

This whole experience is one bitter pill and I am going to think twice before buying another uplay enabled game. Steam does it right, why can't anyone else?

poduser
01-03-2013, 03:37 AM
Guys since Ubisoft seems to be pretty mum on responding to our concerns in light of our accounts, and games being stolen because of their weak security, I think it's time to start contacting games journalists.

thetongatonga
01-03-2013, 05:05 AM
Has anyone actually had a reply from the moderator at the beginning of this thread? I know he is swamped, but I have not heard anything from Ubisoft through Facebook , twitter or this thread.

zunzun2010
01-03-2013, 05:11 AM
thats the problem with them, they are leaving everyone in the dark and not a word... at least an update the forums or facebook or tweet would be good even though no solutions are up yet. i was a WoW player and now i really start to appreciate how much better their support staffs were

cbebopgamer
01-03-2013, 09:16 AM
I just sent a tip to Kotaku. We'll see what happens.

Ste4lthW4r
01-03-2013, 10:00 AM
Hey Ghosts,

A little help pls, i can not find were to get a support ticket for this matter, went to support, but no luck

Never mind, found it

Ticket number 130103-000666

Aure772
01-03-2013, 10:19 AM
Why Uplay should not use the same security system as Steam or Guild Wars Launcher : send an email for every new computer (new IP address) detected by sending country/state, IP address of the new connection request.

User should allow access by a simple verification !

Or you can integrate a phone security system : when you change you're email or password, you need to enter a special code send by SMS for validating this change.

Is simple, but Ubi doesn't thought about this security problem found on most of authenticated system...

Trisher2013
01-03-2013, 10:21 AM
I send a user news to the german magazine pcgames. Curious whats upcoming next

kerafardd
01-03-2013, 10:53 AM
Good idea, I'll do the same with french ones. The way Ubi handles this case is pathetic, they deserve a ****storm.

gribbsy2
01-03-2013, 11:08 AM
Another account stolen here. Thought it was spam at first. It's fairly typical for a company to not publicly acknowledge a security breach so I wouldn't be surprised if this doesn't get an official response until the cause of the breach has been found.

Imho they should shut uplay down until this is resolved.

hdonk007
01-03-2013, 11:33 AM
...

Imho they should shut uplay down until this is resolved.

Or at least disable email address changes...

bobpullen
01-03-2013, 11:38 AM
Same problem here. Received the account change notice shortly before Midnight last night (UK time). Again, email address had been changed to the russian domain playbay.su. It seems clear to me that this is a blatant compromise of Ubisoft's systems and something they should be forthright in grabbing by the balls and making an official announcement about/notifying users.

Whether it's due to previous security breaches (http://www.computerandvideogames.com/360644/ubisoft-uplay-hacked-data-allegedly-exposes-security-flaw-update/#) affecting their systems, or if this is a new one I don't know. It stinks though IMO.

FWIW, I somehow managed to claw my account back by logging into these forums using my Facebook account which I believe was linked to uPlay. This allowed me to get back into my profile and change the email address, password and zip code. I've used a new password that I don't use for anything else and would recommend others do the same. I can't change my country to UK for one reason or another but I'll contact support about that.

Come on Ubisoft, sort it out.

Alphaksli1
01-03-2013, 12:04 PM
Too bad I did not have my Facebook account linked to Uplay. I still haven't got any progress on this and I'm starting to feel that my almost-a-virgin Farcry 3 is a goner (along with the older games).

Maybe this happened because my Farcry was the insane edition. This is really making me insane. Oh the irony.

BTW, Hawk1ns24, when you next time visit the forums, please give us at least a bit of information on this case. I'm sure many of us would highly appreciate it.

kryton01
01-03-2013, 12:12 PM
Just contacted Ubi Customer Support services via phone. They have taken my details and told me that someone will ring within 24 hours (we will see!!!!).

hdonk007
01-03-2013, 12:30 PM
Just contacted Ubi Customer Support services via phone. They have taken my details and told me that someone will ring within 24 hours (we will see!!!!).
Lucky - no answer on the UK cs phone number.

kryton01
01-03-2013, 12:41 PM
Bought my game from Amazon. Just got a confirmation that I can return this based on the worldwide problems with it crashing so sending it back. I will see if I can get the Steam version as there does not seem to be the same problems with Steam and Ubi are VERY un-helpful to say the lease.

bobpullen
01-03-2013, 12:48 PM
I can't change my country to UK for one reason or another but I'll contact support about that.

In fact no I won't. All I get when trying to open a support ticket is:


There was an error accessing the requested web page.

singprb0
01-03-2013, 03:31 PM
Another account stolen. **** Ubisoft, you think they'd notice a lot of email changes to the same shady "playbay.su" domain.

ptr07_2
01-03-2013, 04:43 PM
My account stolen too :/ also from by somebody from "playbay.su"

hdonk007
01-03-2013, 04:45 PM
My account stolen too :/ also from by somebody from "playbay.su"
Welcome to the thread. Please pull up a chair and join the long wait for some information and Ubi to return your account.

Alphaksli1
01-03-2013, 04:48 PM
Just got my support ticket case closed 30mins ago - they changed the account back to my custody.

I opened the ticket on 31st, so it will take some time, but I hope everyone gets their accounts back and the security problems will be resolved.

Ste4lthW4r
01-03-2013, 04:52 PM
Those who got the account back on GRFS, was your stats reset?

poduser
01-03-2013, 05:46 PM
Still nothing from Ubisoft. No response to my ticket, and no explanation or warnings to it's user base about the security breach. Google "Uplay account stolen" and look at all of the results opened in the last week....this is major.


What really sucks is I had just bought Farcry 3 and Hitman Absolution when my account got stolen. Farcry at least got installed and registered before the theft, but Hitman hasn't. If I try to play it now it wants a uplay account, and I don't have one to give it. I could make a new account but then some of my game would be on the new account and the rest on the one that was stolen. I really hate uplay. Why do PC users get stuck with this stuff but console users just stick a disk in?

The funny thing is if you were using a pirated version of a program you don't get stuck with DRM and things like Games for windows live, Uplay, and other much hated DRM schemes. So the paying customer gets punished and the pirates aren't affected, and the hackers get your stuff...

hdonk007
01-03-2013, 05:51 PM
From the Facebook support forum:

'Ubisoft Support: We are investigating the origin of these hijackings. In the mean time, if you have had your account compromised make sure you check and change the passwords of all of your important online services. We've heard people mention services like Yahoo, Amazon, and EA were also compromised at the same time. To make your Uplay account more secure, link Facebook. This is my personal suggestion. If you have a Facebook account attached you can always go back to uplay.com and take your account back because the user cannot unlink this account. Customer support is here to help while the security team works on it and we are giving the accounts back to the rightful owners.'

poduser
01-03-2013, 05:55 PM
Ok I just got a reply to my open support ticket.

Hello xxxxx,

Thank you for reporting this issue. Due to the sensitivity of this issue, we would need you to contact our support office directly. For your security, one of our reps will need to verify some account info before making any changes. You can reach our support team at (919)460-9778 M - F 9am - 12am EST. We hope to hear from you soon


So on top of getting my account stolen, after 3 days of waiting their response is to have me call long distance on my dime and spend an hour on hold to get this fixed? Ubisoft you are unbelievable. When I get my account back I'm never buying another one of your products again.

Space_Hippy
01-03-2013, 06:19 PM
Ok I just got a reply to my open support ticket.

Hello xxxxx,

Thank you for reporting this issue. Due to the sensitivity of this issue, we would need you to contact our support office directly. For your security, one of our reps will need to verify some account info before making any changes. You can reach our support team at (919)460-9778 M - F 9am - 12am EST. We hope to hear from you soon


So on top of getting my account stolen, after 3 days of waiting their response is to have me call long distance on my dime and spend an hour on hold to get this fixed? Ubisoft you are unbelievable. When I get my account back I'm never buying another one of your products again.

Oh great! Phone calls to get your account back! That's going to be VERY hard for me as I am Deaf!

I'm still surprised I've not seen anything mentioned about this elsewhere?! ubisoft seem to be keeping a tight lid on all this!!

My main worry is that I was well over half way through my very enjoyable game of Far Cry 3, better not have to go all through that again?! I know I enjoyed it but doing it all again will be a bit of a grind!!

poduser
01-03-2013, 06:20 PM
I spent 15 minutes on hold and only moved up 1 spot from number 13 in queue to 14. I don't have 2 hours to spend on hold to get a @#$#@$@ video game account back. This is ridiculous.

Korchaa
01-03-2013, 06:55 PM
Hi everyone,

We are of course taking any report of stolen account very seriously and are investigating the source of the hijackings, taking into consideration any possible lead.

Our Customer Support team will reach back to you very soon to help you with your account if it hasn't yet, but please understand that there might be some additional delay with the Holiday Season before your ticket is answered.

I know it's not a pleasant situation to be in but rest assured that we will restore access to your account as soon as possible once we have confirmed personal details with you.


Oh great! Phone calls to get your account back! That's going to be VERY hard for me as I am Deaf!

Please simply reply to the email and our Support representatives will get the required information via the ticketing system.



Farcry at least got installed and registered before the theft, but Hitman hasn't. If I try to play it now it wants a uplay account

HItman Absolution is not a Ubisoft game and shouldn't be linked to your Uplay account. Are you referring to another Ubisoft game?

Dralamar
01-03-2013, 07:29 PM
Account restored! (previously posting as alamar3)

Got notification emails of my account information being reset and a ticket update around 3:20pm (for reference, the original ticket was two days ago, but that was posted on the 1st when the CS was closed). Everything seems to be back to normal...

Trisher2013
01-03-2013, 07:30 PM
Thanks for your response i am now a little bit more hopeful to see my account back soon. Gladly I sent all informations I have with the ticket including my keys and a copy of my personal id next to my anno 2070 key. That should be enough, shouldn't it?

poduser
01-03-2013, 07:33 PM
That's good to know. I thought from a google search it was.

I replied to my ticket telling them a phone call wasn't going to work for me. I did try to call them on my break a few hours ago and after 15 minutes on hold I only moved up one spot with 13 people in front of me. A lot of people don't have the time to spend hours on hold on long distance in order to get their video game accounts back. It's unreasonable to expect customers to go through that when support should be able to do it through email or the ticketing system.


Also I just got an update on my ticket from "Matt" who suggested I call on a cell phone to avoid long distance fees. Are you folks trying to upset your customers?

1. Not all cellphones have nation wide long distance
2. Instead of paying long distance you're then paying in cellphone minutes
3. That is all besides the point, I don't have time to spend hours on hold and I've now asked 3 times for this to be handled via the support ticket system.

I'm getting tired of repeating myself and the insensitive answers I'm getting back from support. I'm surprised they didn't ask the gamer who was deaf to have a friend call on his behalf or something lame like that.

StinkinLumberja
01-03-2013, 07:46 PM
My problem is solved.
I have GRFS on both pc and ps3, logged in with my ps3 and changed from hackers mail, to a new mail of mine, and made a new password.....logged in with new mail and password.....WORKS.

How to tell ubi support my problem is solved?

Dark_Fread
01-03-2013, 08:17 PM
Account restored thanks to the Facebook linking (didn't remember I did that).


How to tell ubi support my problem is solved?

http://tof.canardpc.com/view/56d20a5f-bcfe-4c71-90b8-fe8aaf692ee0.jpg
Uh, no, no, no, don’t tell him, let’s see if he can figure it out.

widgen
01-03-2013, 08:29 PM
My problem is solved.
I have GRFS on both pc and ps3, logged in with my ps3 and changed from hackers mail, to a new mail of mine, and made a new password.....logged in with new mail and password.....WORKS.

How to tell ubi support my problem is solved?

JESUS CHRIST LIFE SAVER!! was posting on ste312 but i used my GF's copy of asscreed III to login to uplay and change all of my info back

Barujin
01-03-2013, 08:30 PM
I just got mine back with a simple phone call.

EDIT: Now that I have it back, I've noticed that it's linked to a Facebook account. How do I unlink it?

EDIT 2: Okay, after another phone call, I got it unlinked from the other person's Facebook account and then linked it to my own. *sigh* What a mess this has been. My account will probably get stolen next week, again.

poduser
01-03-2013, 08:35 PM
Okay, after a lot of time on hold over my lunch break I got my account back.

Interestingly they had changed my zip code in account information to 28693 which comes up as Warrenville North Carolina. Stranger and stranger. Is it possible that whoever stole the accounts is selling them to other people in the US?

Also one more thing, I really wish I had kept the guy on the phone longer because when I go to change anything it keeps telling me that my email address is invalid. I've triple checked it, it's my email, and it is valid. The person who stole it deleted it and now the system won't let me use it anymore. Who fixes that? I don't want to spend another hour on the phone and do this multiple phonecall drill to get things back to normal.

PhilPhil2341
01-03-2013, 10:36 PM
My Account was stolen but no answer from the Support yet. I update my question and all that. But no response yet. I want my account as fast as possible back

Greyvorn2
01-03-2013, 11:58 PM
My account is still not fixed. This is the latest response I got.

We have checked your cd key code and we realise that your account have been modified.
For that reason we need you to send us a new email address that's not used on any Uplay platform.
If you like to use this email again you need to delete this username account so we can use your email again.??

WTF

paulrgibson
01-04-2013, 02:06 AM
My account just got restored over email support.
Took 4 days. Good luck to the rest of you.

Matt0782
01-04-2013, 02:57 AM
Just got mine back using the facebook log in. My email was changed to uplay1163152@playbay.su

kodack10
01-04-2013, 03:49 AM
Guys check the new thread I just made. It looks like something might have been done to our uplay installations that might make it easy to get re-hacked. You should uninstall and reinstall uplay and ubisoft game launcher from add/remove programs and make sure "use a proxy" is unchecked.

I couldn't log in to uplay from the client after getting my account back and it's likely that something was making uplay redirect my login credentials to the hackers. Reinstalling it cleared up the problem once I told steam to verify cache integrity.

Trisher2013
01-04-2013, 07:33 AM
In Germany there is still no action. No response to e-mail support request, forum request or facebook request. We just being ignored.... ;( Uplay Games never again for me so far...

Can you tell us germans when our problems get solved?

hdonk007
01-04-2013, 11:42 AM
In Germany there is still no action. No response to e-mail support request, forum request or facebook request. We just being ignored.... ;( Uplay Games never again for me so far...

Can you tell us germans when our problems get solved?
It looks like European customer support is still on holiday. Nothing from UK CS on ticketing system or on phone...

Twobase
01-04-2013, 12:34 PM
Mine just got stolen too, I can't believe what an utter screw up this is - how can Ubisoft not realise what is happening to their systems, something as blatant as this is quite obviously a security breach - there can't be THIS many accounts being stolen in such a short amount of time. I sure hope they're doing something about it.

Angroshim
01-04-2013, 12:37 PM
I was hacked too, writing from other account, sent pm

hdonk007
01-04-2013, 01:56 PM
Cross post from FB:
Bl**dy h*ck. Just got an email from CS on the ticket about my hacked UPlay account -> "Please confirm that you still have a problem. Also give us all the information you've already given, *again*"
ARGHHHH!!!!

Dark_Fread
01-04-2013, 02:09 PM
Everyone should warn video games websites to make them publish a news about that situation. Ubi deserves it.

Trisher2013
01-04-2013, 02:22 PM
I tried but they also give no response... I think they want make bad publicity for Ubisoft in order to get exclusice stories in future

hdonk007
01-04-2013, 02:27 PM
Noone wants to publish anything unless Ubi confirm there's a problem.
Because it might be our PCs/consoles that got hacked, not Ubi. Or something...

Dark_Fread
01-04-2013, 02:44 PM
Because it might be our PCs/consoles that got hacked, not Ubi. Or something...

Many people who have been hacked were using strong passwords. There are two hypothesis : someone broke into Ubi database, or there is an exploit in Uplay.
I would say it is an exploit in Uplay because I even doubt the hackers actually saw our real passwords. If it was the case, the hacker who stole my account had a perfect couple : my email and my password. Therefore he could have log (or at least try to) into my Steam account, for example. And no one tried that, according to Steamguard.
And many people here can swear their computers are virus/malware free. Finally, the Uplay plugin have been recently known to introduce security issues.
http://www.rockpapershotgun.com/2012/07/30/psa-possible-security-risk-in-some-ubisoft-pc-games/

So, even if our computers have been hacked, it is highly possible that it's Ubi's fault.

Anyway, I did some research and I could not find any evidence about the Amazon/EA/Yahoo hacks the Ubi Facebook page are talking about. This is ridiculous.

Terminoc
01-04-2013, 03:22 PM
I just got the email that was also sent to a @playbay.su

hdonk007
01-04-2013, 03:42 PM
Welcome to the club...

Space_Hippy
01-04-2013, 04:18 PM
I'm not too sure if my account will be sorted, I've just remembered that I wasn't able to create a support ticket a few days ago when I realised I had my account hacked.
I gave Hawk1ns24 a PM with all my details but that was it, not heard anything more! Probably just being impatiant!
Still worried about not being able to create a support ticket though!

xxMrSunshine
01-04-2013, 04:35 PM
I got my account stolen during the holidays as well. Submitted a support ticket on the 29th, sent images of my activation keys, barcodes etc. that the Tech support guy asked on the 31st and have not heard anything since. Super awesome. Got no idea what's going on.

I even got AC3 a couple of days ago and now I can't even play it unless I tie it to another dummy account.

Dark_Fread
01-04-2013, 04:55 PM
I tried but they also give no response... I think they want make bad publicity for Ubisoft in order to get exclusice stories in future

Well, we can start threads on Reddit and 4chan. Could be fun.

StinkinLumberja
01-04-2013, 05:08 PM
When I came to the idea that I might be able to access via my ps3, I could see the attacker's mail, but not his password, I could easily change the email and password without knowing the password to his account. This is not very reassuring that it is SO easy to change

Trisher2013
01-04-2013, 05:17 PM
There we go: http://www.reddit.com/r/gaming/comments/15y4i8/uplay_account_compromises_hacked/

hdonk007
01-04-2013, 06:02 PM
Now Ubisoft want answers to a raft of questions, and still haven't reassigned my account to me:

Allow me to ask a few questions about the account you believe is stolen.
Was the user using a weak password?

Were you using a weak/obvious password?

Was the uplay account the only account compromised?

Have you baught games from a website?

Did you use a trainer or a crack for any Ubisoft games?

Did you install anything new on your PC before your account was compromised? (even non game related)

Are you using an Anti-Virus / Anti-Malware?


Trying to determine what's happened, or trying to pass the buck?

chrwe1972
01-04-2013, 06:39 PM
Well, I joined you guys today.

I cannot access any of my games on Uplay, even the ones bought on Steam. I had not logged on Uplay for quite a while, and I am 100% sure my computer is virus free and secure. I have not installed any 3-rd party programs, trainers or similar. What`s more, I am one of the more paranoid users and sweep my computer regularily (ccleaner, virusguards etc.).

I believe it is a disgrace that Ubisoft has such lax security measures.

My account was stolen by hackers (easily identified by the email @playbay.su) and I was not asked to confirm the e-mail and password change via my normal e-mail adress. And I cannot get the account back without sending loads of personal data (which I partly cannot send due to not having a scanner and partly do not WANT to send only to have it stolen, too!). All this while I am 100% sure Ubisoft knows perfectly well the account was stolen. I already spend ages on the phone - paying for that - and they ask me all the data again.

They are making it hard for ME to get my account back, thereby helping the hackers. And before anyone tells me that its a good thing they want a scan of my personal ID to verify my account: They did not have any security measures in place. I do NOT want my personal ID to end up somewhere in ... as well. They know the account is stolen without it.

A disgrace.

Dark_Fread
01-04-2013, 07:20 PM
Were you using a weak/obvious password?

Not really. I admit that was not a very strong password though (letters/numbers, that's all).

Was the uplay account the only account compromised?

Yes, so far.

Have you baught games from a website?

No.

Did you use a trainer or a crack for any Ubisoft games?

No.

Did you install anything new on your PC before your account was compromised? (even non game related)

Of course... Drivers (just changed my mobo) and games, mostly.

Are you using an Anti-Virus / Anti-Malware?

Yes. MSE combined with Spybot, SUPER Antispyware and Malwarebytes.

madeup01
01-04-2013, 07:36 PM
My account is still not fixed. This is the latest response I got.

WTF

I asked to use the same email address then got..........................

Thank you for contacting Ubisoft Technical Support regarding Account Changes.

In order to respond to this email, please update this incident (Please do not create a new incident).

We are very sorry to hear that you would like to delete your Ubisoft account. Before we can do this, you need to be aware of some very important points.

Please note that having a ubi.com account is FREE, and we will not send any emails unless you specifically ask to be sent promotional emails from our company. We respect your privacy and will never sell or share account information with anyone outside of Ubisoft. It will cost nothing to just leave your ubi.com account intact in case you ever decide to come back. If after consideration of these facts you STILL want to permanently delete your ubi.com account, please see below:

Consequences of Deleting an Account

By deleting your account, any keys for games already purchased will be disabled as your ubi.com account is linked to them. Therefore, those games will no longer be accessible to you. Your Ubisoft username and all the CD keys (install keys, activation keys etc) of Ubisoft games will be permanently banned!

Once a CD key is banned, it will not be possible to use it again. As well as this, you may not be able to re-create the Ubi.com account using the same username.

Deleting your ubi.com account will also result in loss of access to UPLAY, achievements, forums, and access to support on the specific account.


Please be aware that this process is final and may not be revoked. After deletion, we will have no more records in our system. Please be aware that you will not be able to contact us in the future regarding your deleted account, unless you create a new account.

So that we can perform the deletion, we require your final and unequivocal consent for this procedure, including all the consequences. For this we need to ensure that you have been informed of the consequences and explicitly request the cancellation of your Ubisoft account. Please carefully follow the procedure below:

Please submit a ticket to us by clicking on the Ask A Question tab above. Include in your request the following information (copy paste this into the ticket):

1. Yes, I want my Ubisoft account madeup01 to be completely deleted from the system.
2. I am aware that my Ubisoft Games will be permanently banned.
3. I also was informed, that any connections to services (Uplay, online saved games) will be irrevocably lost and these services will therefore no longer be available.
4. I have no current orders from the UbiShop with this account.
5. Once the account is deleted it can't be reinstated at any later time.
6. I am aware of the consequences of the deletion and agree and accept the procedure of Ubisoft.

Please be aware that after we delete your account, we are not able to send you a confirmation e-mail as there will be no remaining records of your account. The deletion process can still take several days. We ask for your patience and understanding.

We regret that you want to leave us but of course we accept and respect your decision.

For further questions please don't hesitate to contact us, otherwise we wish you all the best.


If you have any further queries or issues please do not hesitate to contact us again and we will assist you further.

you couldnt make it up!!!

Trisher2013
01-04-2013, 07:36 PM
Were you using a weak/obvious password?

Combination of letters and numbers, not obvious, random generated...

Was the uplay account the only account compromised?

Yes, so far.

Have you baught games from a website?

Anno 2070 DeepOcean Addon from amazon.de

Did you use a trainer or a crack for any Ubisoft games?

No.

Did you install anything new on your PC before your account was compromised? (even non game related)

Yes, installed UPLAY

Are you using an Anti-Virus / Anti-Malware?

Yes. AntiVir and hardware firewall

Kraken395
01-04-2013, 07:48 PM
i have smae problem .... playbay.su ..... **** this !!!! please help me i have 3 expensive games my stolen accout !! i contact email support but not answer. Help please

RonFerrier
01-04-2013, 08:00 PM
Well I've gone to the UbiSoft facebook page and posted now (we'll see how long before they decide to delete it) and have also started tweeting about the issue to various industry publications.

Does anyone have the number for the Canada/US support, the Steam version comes with the UK number only.

RonFerrier
01-04-2013, 08:48 PM
For those that have had their account hacked/hijacked/stolen perhaps it's time for a twitter hashtag to get things noticed more publicly. #UbiHack

devnu1l
01-04-2013, 08:49 PM
Me too. Just PM'd the admin here from 1st page. Not sure how long it will take them to restore my original account. Nothing I can do until that as my CD key is bound to that account and won't work on the new one I had to create to open a support ticket and respond on these forums. WOW what an freak'n mess! Never had an account hacked in all my life online and that is a long time now...

RonFerrier
01-04-2013, 09:07 PM
Better sit tight and wait, most are waiting 4-5 DAYS for a response.

Trisher2013
01-04-2013, 09:12 PM
Wrong RonFerrier, i think all are waiting 4-5 days for the first action. In my case it was the renaming of my ticket nearly 30 hours after creation now 40-50 hours nothing happened. and no response to me

RonFerrier
01-04-2013, 09:17 PM
Unbelievably bad user experience and the fact that they are trying to blame it on the users is disgusting.

Angroshim
01-04-2013, 09:27 PM
I solved my problem by myself... Thanks Ubisoft!

How to recieve stolen account[/SIZE]
This method works only if you have assassins creed III xbox version ...(may work on ps, and/or other games that support uplay I don't know)
So:
1. Run any game that uses uplay (ex. Assassin's Creed III)
2. Run uplay.
3. Check profile ( start button)
4. Email and password
5. Change it back
6. thats it.

Twobase
01-04-2013, 09:46 PM
I solved my problem by myself... Thanks Ubisoft!

How to recieve stolen account[/SIZE]
This method works only if you have assassins creed III xbox version ...(may work on ps, and/or other games that support uplay I don't know)
So:
1. Run any game that uses uplay (ex. Assassin's Creed III)
2. Run uplay.
3. Check profile ( start button)
4. Email and password
5. Change it back
6. thats it.

Thanks so much, this actually worked! It's a good thing I can access Uplay on a console!

Korchaa
01-04-2013, 09:57 PM
Hi guys,

We are taking all reports of stolen accounts very seriously and are of course investigating all leads in order to identify exactly how these accounts have been compromised and take any additional action that might be needed. This is why our Support team might ask some questions to get more contextual information.

As mentioned in my previous post, our Support team is currently processing all requests and will soon get back to you in order to restore access to your account if they haven't done so yet. I know that having to go through all these steps to show you are the rightfull owner of your account is not pleasant, but I am sure you will understand why this procedure is all the more important right now.


Now, if you have previously linked your account to your Facebook, Playstation or Xbox account, you can use these logins to edit back your email address and password:

- Go to www.uplay.com and use Facebook Connect or your PSN credentials to connect to your account, then update back your account information.
Your Facebook or PSN credentials are not shared with Uplay at any point. As an additional security measure, I recommend though that you do so from a different computer than the one you usually use to play or login to our website/forums.

- Start a Uplay-enabled from your Xbox or PS3, launch Uplay from the main menu of the game, press Start to access your profile and edit your email/password. This is only possible from a console you have already linked your account with.

Once you've regained access to your account, please double-check that it has only been linked to platforms you do own by going to www.uplay.com, logging in and clicking on your username below your avatar picture. Should this not be the case, please contact Support as soon as possible to unlink your account.

I hope the situation will soon be sorted out for all you. Please rest assured that on our side we are working hard to resolve this situation.



When I came to the idea that I might be able to access via my ps3, I could see the attacker's mail, but not his password, I could easily change the email and password without knowing the password to his account. This is not very reassuring that it is SO easy to change

You need to first log in to PSN or Xbox Live to access Uplay and it's only possible if you have previously linked your accounts on the console. This is why it is one of the option for editing back your account suggested in the notification email you've received.


I'm not too sure if my account will be sorted, I've just remembered that I wasn't able to create a support ticket a few days ago when I realised I had my account hacked. I gave Hawk1ns24 a PM with all my details but that was it, not heard anything more!

Please make sure you also send a ticket to Support, for example using your Space_hippy account.

Trisher2013
01-04-2013, 10:00 PM
Its nice to get such a long post from somebody official. Can you tell us something about support on the weekend, espacially for me in germany?

kodack10
01-04-2013, 10:22 PM
Everyone should warn video games websites to make them publish a news about that situation. Ubi deserves it.

I've stated several times that contacting games journalists is in the communities best interest at this point. Go to youtube, find out who has a lot of subscribers and pm them. Industry sites like Destructoid, Kotaku, IGN, all have 'tips' email contacts you can use. I've already notified a few but unless more people do the same it will seem isolated to them.

kodack10
01-04-2013, 10:32 PM
Many people who have been hacked were using strong passwords. There are two hypothesis : someone broke into Ubi database, or there is an exploit in Uplay.
I would say it is an exploit in Uplay because I even doubt the hackers actually saw our real passwords. If it was the case, the hacker who stole my account had a perfect couple : my email and my password. Therefore he could have log (or at least try to) into my Steam account, for example. And no one tried that, according to Steamguard.
And many people here can swear their computers are virus/malware free. Finally, the Uplay plugin have been recently known to introduce security issues.
http://www.rockpapershotgun.com/2012/07/30/psa-possible-security-risk-in-some-ubisoft-pc-games/

So, even if our computers have been hacked, it is highly possible that it's Ubi's fault.

Anyway, I did some research and I could not find any evidence about the Amazon/EA/Yahoo hacks the Ubi Facebook page are talking about. This is ridiculous.

I too had my account stolen and only got it back yesterday. I work for a global security company you've all heard of and you probably use their products (but if you're smart you disable them before gaming cause they make your pc SLOW hehehe). I threw every piece of software my company had at it (I get them all free), as well as other vendors, booted a debian forensics suite, and I am 100% that my computer was virus, trojan, and keylogger free at the time. If a legitimate applications configuration were modified to use an unprotected proxy however it would not ring any alarm bells so to speak.

Often in situations like this, the hack is done at the companies end by compromising a database. The attackers are usually not able to get passwords or credit card info as these are heavily salted and hashed. But it would allow them to make changes to the account or initiate a password reset without raising too much suspicion. Everything account related is stored in databases on the server end and while the DB is physically and network protected, it must allow 'legitimate' traffic through in order to do it's job. By spoofing communication from legitimate sources like the ubi.com, uplay, etc it is able to initiate these account recovery options without looking to the server, or it's security policies, like an attacker.

That is my best guess at the moment. The fact that the uplay client still wouldn't log in after getting my account back is the only thing that suggests the hack was client side. As somebody else stated, the uplay client was found to have several sql injection/cross site scripting bugs a few months ago, and it's possible there was a zero day exploit used here on our clients, but there is no proof of that.

Bonezz55
01-04-2013, 10:34 PM
How am I supposed to get my account back and WHY IS ANYBODY allowed to change my information without email conformation? This is BS. What am I even supposed to do now? I just lost all my games because of this and the person changed my email address on my account. I can't even login by playing a game using the method above because it just tells me my information is invalid.

Where do i even go to email support? I can't even find one thing that points me in the right direction.

kodack10
01-04-2013, 10:45 PM
How am I supposed to get my account back and WHY IS ANYBODY allowed to change my information without email conformation? This is BS. What am I even supposed to do now? I just lost all my games because of this and the person changed my email address on my account. I can't even login by playing a game using the method above because it just tells me my information is invalid.

Where do i even go to email support? I can't even find one thing that points me in the right direction.

Logging a support ticket is useless. After 2 days of back and forth I was left with no choice but to call a long distance number and spend an hour on hold. The worst part is my account is still broken and that necessitated another hour long call and it still hasn't been resolved.

You will have to call ubisoft support at their 919 area code number. It sucks, it had me wondering if it might not be better to just let them have my account as the effort it took to get it back wasn't worth my time or money.

The phone number I was given is
(919)460-9778 M - F 9am - 12am EST

anders_190
01-04-2013, 10:52 PM
Hi guys,

We are taking all reports of stolen accounts very seriously and are of course investigating all leads in order to identify exactly how these accounts have been compromised and take any additional action that might be needed. This is why our Support team might ask some questions to get more contextual information.

As mentioned in my previous post, our Support team is currently processing all requests and will soon get back to you in order to restore access to your account if they haven't done so yet. I know that having to go through all these steps to show you are the rightfull owner of your account is not pleasant, but I am sure you will understand why this procedure is all the more important right now.

Like Trisher2013 said, it's nice to see a longer answer from someone official. I do have two questions. Why is the confirmation email being sent to the new email (if anything, it should be confirmed using both the old and new mail)? Shouldn't most of the users problems be solved by undoing changes to accounts that has gotten their mail and password changed to @playbay.su mails? The fact that so many accounts seem to have been changed to mails from that domain (and most probably with different IP's than usual) should make it obvious enough what probably has happened.

I, for one, will look forward seeing how all of this work out. Got my account back the this wednesday and have finally gotten back to FarCry 3 and my second playthrough. I just hope that the rest of those affected can get back to their games ASAP too. :)

//Anders

hdonk007
01-04-2013, 11:06 PM
There's an article on theregister:
http://www.theregister.co.uk/2013/01/04/ubisoft_gaming_account_hijack_caper/

Bonezz55
01-04-2013, 11:20 PM
So what if I didn't use my actual DOB on the account? Honestly I have no idea if I did or not. I'm assuming I'm just completely screwed even though I can provide all of my personal information including all my CD keys that have been used on my garbage uplay account?

UbiHawk1ns
01-04-2013, 11:43 PM
Some Uplay users have contacted us about issues with their Uplay accounts. The accounts were compromised but no personal or financial details have been exposed, and the number of people affected is limited. Ubisoft is working hard to find a solution. Meanwhile, we encourage users to set strong passwords (including numbers and capital letters) for Uplay and any other online accounts to reduce the risk in the future.

Please open a support ticket on our Support Website (http://support.ubi.com) if you have this problem and we will help in any way we can.

thetongatonga
01-05-2013, 12:03 AM
Just got mine back. I think I was very very fortunate in the timing of my call. 5:30pm est. What was interesting was the fact that when they sent me the email to reset my password, with in the minute it took to get to me the link was dead and no chance to reset password. Now it may have been because they sent multiples by accident and killed the link but...

Well hopefully I won't have to worry about having the permission to play the games I "own" now, definitely don't have to worry about any future ubisoft games, done with them for the rest of my life and my son's life also... and any of my clients I can convince. SO long ubisoft.

A few years late, but you live and learn.

imperialyap2
01-05-2013, 01:26 AM
I've been away for the holidays to come back today to find my account was hacked on December 31st. I've sent i