1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
  2. Greetings Guest!!

    In order to combat SPAM on the forums, all users are required to have a minimum of 2 posts before they can submit links in any post or thread.

    Dismiss Notice

Another thread about compromised CC info

Discussion in 'UHall' started by EDA_GL, Jan 13, 2015.

  1. EDA_GL

    EDA_GL Journeyman
    Stratics Veteran

    Joined:
    Oct 19, 2008
    Messages:
    191
    Likes Received:
    24
    Seriously?
    I have had my same CC info attached for nearly a decade and NOW (1/12/2015) something gives?
    Some slightly irradiated individual is now playing Fifa or w/e cost 39.75 from EA/JPY.
    For anyone else having a similar issue....
    1-650-628-1500 is a phone number to EA.
    8-9 M-F pacific time.

    *Updated* 1/17/2016

    Here is the story I got regarding my issue.
    EA has been aware of an issue in their security since mid-2014 yet has not posted anything public regarding this issue. I suggested that they claim ownership of it; it’s their issue, and blast an e-mail to their clients. I even made mention of the Home Depot issue and how they claimed it as their error.

    Apparently there is some type of coin/currency in Fifa 2015.
    There is a bot/script/hack or something of that nature that somehow gets CC info from Origin.com and then tries to purchase Fifa 2015 (the game may vary, but for me it was Fifa 2015). This bot will try all CC that you have on file. I had an ooooooold card still on file that it tried 3 times, and then it tried 2 times on my active card.

    What was told to me is that once the attempt to pay for Fifa 2015 the account becomes active. When active they log in, get the coin or in-game currency and then sell it to get real cash. Then the Fifa account is left to 'die'. The analogy to me was strip mining.

    Here are the steps that I took when I saw this happening to me.

    Called the number on the back of my card, blocked my card till the next day.
    Started a fraud claim. Pin pointed what charges I did not authorize.
    Contacted EA/Origin. Explained what was happening.
    My bank canceled that card, issued a new one.

    *****Here is the biggy*****
    On the Origin site, there is an option to set a security 'passcode' that can be emailed or texted to you. This passcode is needed to finalize a purchase on their website.


    At the very least Origin/EA should blast an email telling clients about this feature. I had no idea this existed till the customer service guy told me about it.

    The phone number provided in this post works, gets you to a call center. The call center gets you put in a queue for a return call. It’s the only/quickest way to get a LIVE body. The callback from them may take a while, so be patient. Remember it’s not their fault!
     
    #1 EDA_GL, Jan 13, 2015
    Last edited: Jan 17, 2015
  2. petemage

    petemage Seasoned Veteran

    Joined:
    Oct 6, 2013
    Messages:
    460
    Likes Received:
    328
    For the love of the game, they charge because they care. This is around for a while now, yet no official statement, because they care.
     
  3. DJAd

    DJAd Stratics Legend
    Stratics Veteran

    Joined:
    Aug 17, 2007
    Messages:
    7,936
    Likes Received:
    3,587
  4. Prince Erik

    Prince Erik Journeyman
    Stratics Veteran

    Joined:
    May 18, 2008
    Messages:
    173
    Likes Received:
    91
    If it's not too much trouble - is there a definitive description of how best to pay for UO now? I'm one of those insanely scatterbrained people (I mean, VERY bad) so if a bill isn't auto paid eventually I'm going to forget about it. I haven't kept up with the new housing decay timer thing so I'd hate to forget to pay and lose my houses!

    If I remove my credit card do I get reminders of when I need to apply game time codes or will I have to remember to do this myself for each account? Do you get email notified before the time runs out or after, or.. not at all? Are people still having problems using the EA store? Is it too late to remove my card if the payment database has been compromised i.e. should I cancel the card now before I get hit?

    Sorry for such newb questions, but this is disturbing me greatly. Also, since I'm assuming putting your card into EA's storefront is probably not secure either, is there a better place/way to buy codes? Is there a way to use a bill paying service to pay for a subscription? I really want to remove my payment method but I'm afraid of losing my grandfathered houses because my brain doesn't work right. ;)

    Thanks for any help you can give me!

    -P.E.
     
  5. DJAd

    DJAd Stratics Legend
    Stratics Veteran

    Joined:
    Aug 17, 2007
    Messages:
    7,936
    Likes Received:
    3,587
    I removed all my card details and now just buy gametime codes and apply these instead. Yes I get an email to tell me when it has expired but I also save the dates into my Google calendar so I get a nice notification popup on my phone a few days before to remind me that the accounts need paying.
     
    Prince Erik likes this.
  6. azmodanb

    azmodanb Grand Poobah
    Stratics Veteran Stratics Legend

    Joined:
    Jun 3, 2004
    Messages:
    5,912
    Likes Received:
    1,186
    i use game time via paypal
     
    MalagAste, Zynia, petemage and 2 others like this.
  7. Zynia

    Zynia Lore Master
    Stratics Veteran Alumni Stratics Legend

    Joined:
    Jun 16, 2005
    Messages:
    1,100
    Likes Received:
    236
    Gametime / paypal has worked good for me..
     
  8. DreadLord Lestat

    DreadLord Lestat Social Media Liaison
    Moderator Professional Wiki Moderator Stratics Veteran Social Media Liaison Stratics Legend PITMUCK

    Joined:
    Feb 26, 2004
    Messages:
    3,161
    Likes Received:
    1,147
    Thank you for this info! I just set mine up, I had never noticed it before. I routinely check for unauthorized purchases but this makes it a bit more safe, EA definitely needs to spread the word on that with the issues that they are having.
     
    RueTor likes this.
  9. DreadLord Lestat

    DreadLord Lestat Social Media Liaison
    Moderator Professional Wiki Moderator Stratics Veteran Social Media Liaison Stratics Legend PITMUCK

    Joined:
    Feb 26, 2004
    Messages:
    3,161
    Likes Received:
    1,147
    You will only get an e-mail when the account closes, nothing ahead warning you. If you can afford the 6 month game time codes, you save some money and you don't have to worry about it. You can also purchase 3 month codes as well but do not save as much. When you purchase the game time codes, there is a box to store the credit card info, make sure that stays unchecked.

    Another thing you can do which I like to is to purchase EA Game cards from Best Buy. I get rewards for the purchase, it doesn't cost you any fees. I buy a $60 card for $60 and get $60 in my EA Wallet which I used to purchase a $59.99 6 month game time token. I get rewards from Best Buy which I use towards new EA Game Time Cards. Just remember not to leave a balance in the wallet or they can still buy the FIFA or whatever it is that they are doing.

    As far as remembering, Smart phones have calendars which can notify you and there are desktop calendars as well. Unless you stop playing for months at a time, the worst thing that will happen is that you try and log in and cannot so you add more game time and resub. Just don't miss more than 2 months to be safe on your house in game or it could IDOC. 6 month game time is the way to go, it works out to $9.99 a month which saves you $18 every 6 months. It's not much but every penny counts and you save even more if you have multiple accounts.

    Make sure to use the security function that the OP talked about, it takes a couple of minutes of time and can keep you from unauthorized billing no matter how you try and pay for it. :)
     
    Prince Erik likes this.
  10. PlayerSkillFTW

    PlayerSkillFTW Lore Master
    Stratics Veteran

    Joined:
    May 12, 2008
    Messages:
    1,020
    Likes Received:
    430
    Yep, just got the same exact thing. Went and checked my e-mail today, noticed some wierd e-mail from Origin [email protected] in Chinese, so i went and checked my Origin order list, and it was some fraudulent charge for Fifa 15 for HK$384.35 (which is along the lines of $50.00-60.00 US dollars) on one of my cards associated with my Origin account.
    It's already past 9:00 PM Pacific time when i noticed it, and tomorrow is a national holiday, so i'm gonna have hell contacting EA about this fraudulent ********. This is completely, 100% on EA's ass for knowingly having a faulty system. I'm running a fully updated paid antivirus program, and regularly scan.
     
    #10 PlayerSkillFTW, Jan 19, 2015
    Last edited: Jan 19, 2015
  11. Uvtha

    Uvtha Grand Poobah
    Stratics Veteran

    Joined:
    May 24, 2008
    Messages:
    6,526
    Likes Received:
    2,914
    Just happened to me... Really unhappy about it. :/

    Multibillion dollar company just can't ****ing be bothered to have a secure site... I honestly don't know if the month or two a year I play UO is worth giving this garbage company a dime of my money.
     
  12. Speranza

    Speranza Slightly Crazed
    Stratics Veteran Alumni Stratics Legend

    Joined:
    Mar 18, 2004
    Messages:
    1,451
    Likes Received:
    760
    Contact your bank today, have them reverse it. It will take a few days to complete that. In the mean time you can force EA to refund it by letting them know you have requested a charge back with your bank/CC. This will get them to refund it slightly faster or they get dinged extra fees for a charge back.
     
  13. Prince Erik

    Prince Erik Journeyman
    Stratics Veteran

    Joined:
    May 18, 2008
    Messages:
    173
    Likes Received:
    91
    So, has it been confirmed by EA that their billing database has been compromised and our card numbers are now obtainable by others? I'm actually nervous even trying to log in to their site if it's not the database itself but the transmission vehicle that's compromised.

    I know in some states it's a matter of law that any security breaches must be reported and it doesn't sound like they've done this as the last comment I've found from EA is that "everything is fine, users weren't careful" .. blah blah blah. Some of the states require mandatory identity theft protection and mitigation for their residents (California for example). I see on the FTC's website there's a place to submit a complaint for identity theft, is this an appropriate response?

    -P.E.
     
  14. Kayhynn

    Kayhynn Certifiable
    Stratics Veteran Stratics Legend Campaign Supporter

    Joined:
    May 12, 2002
    Messages:
    1,534
    Likes Received:
    541
    EA says they haven't been compromised. I strongly disagree.
     
  15. petemage

    petemage Seasoned Veteran

    Joined:
    Oct 6, 2013
    Messages:
    460
    Likes Received:
    328
  16. Tanivar

    Tanivar Crazed Zealot
    Stratics Veteran Stratics Legend

    Joined:
    May 28, 2003
    Messages:
    3,594
    Likes Received:
    1,463
    I did a chat with customer service at the Origin Store and got an EA wallet set up, needed their help because the link to the terms of service you have to agree to doesn't work. You can then buy $20 EA gift ecards at Best Buy & other big retailers websites and add it to the EA wallet to pay EA with. The customer service advisor can wipe your CC info out as well.
     
    Prince Erik likes this.
  17. Prince Erik

    Prince Erik Journeyman
    Stratics Veteran

    Joined:
    May 18, 2008
    Messages:
    173
    Likes Received:
    91
    Ooooh, I like the EA wallet thing. I might do that. Did you just open up an online chat or did you have to phone them?

    Thanks for the tip!

    -P.E.
     
  18. Lythos-

    Lythos- Lore Keeper
    Stratics Veteran

    Joined:
    May 20, 2007
    Messages:
    898
    Likes Received:
    575
    From what I gather they are scripting login attempts. Using an automated program to try every possible known user/pass and store which ones work. The ones that work and have people stupid enough to store payment info are donating FIFA to poor Asian café gamers.

    By Federal law you cannot be held responsible for ANY unauthorized charges on a credit card. I'm not sure about debit/atm cards and I assume they all have different policies with false charges at your local banks. You can do giftcards and prepaid cards but if they get hacked then it's basically you against EA in which EA says screw off. A valid credit card offers protection against liability and EA.

    I've been doing the same monthly buying of gametime as I always have spending those extra 2min to enter my info in everytime and I've never been hacked cheated or robbed. Common sense people. It works.
     
  19. Tanivar

    Tanivar Crazed Zealot
    Stratics Veteran Stratics Legend

    Joined:
    May 28, 2003
    Messages:
    3,594
    Likes Received:
    1,463
    There's a contact option for a chat given.


    I order the ecards to cover what I want, their emailed to me, I put them in the wallet and make my purchase. There will be a few dollars left in the wallet that could be hacked but likely not worth the hackers bother.
     
  20. TheScoundrelRico

    TheScoundrelRico Stratics Legend
    Stratics Veteran Alumni Stratics Legend Secret Society

    Joined:
    Aug 12, 2001
    Messages:
    35,539
    Likes Received:
    908
    I went to Gamestop and bought ea gift cards with the Visa Gift cards I bought. All you do is enter the codes into the system and they are added to your EA wallet attached to your origin account...la
     
  21. DreadLord Lestat

    DreadLord Lestat Social Media Liaison
    Moderator Professional Wiki Moderator Stratics Veteran Social Media Liaison Stratics Legend PITMUCK

    Joined:
    Feb 26, 2004
    Messages:
    3,161
    Likes Received:
    1,147
    They also have $60 EA cards
     
  22. PlayerSkillFTW

    PlayerSkillFTW Lore Master
    Stratics Veteran

    Joined:
    May 12, 2008
    Messages:
    1,020
    Likes Received:
    430
    Called that number, still sitting on hold after an hour and a half...
    Go to change my security "passcode" for my Origin account, and the security question pops up in Chinese...
     
  23. PlayerSkillFTW

    PlayerSkillFTW Lore Master
    Stratics Veteran

    Joined:
    May 12, 2008
    Messages:
    1,020
    Likes Received:
    430
    Well, finally got a hold of someone at Origin, and gotten it straightened out. Thanks for the number, EDA_GL.
     
  24. EDA_GL

    EDA_GL Journeyman
    Stratics Veteran

    Joined:
    Oct 19, 2008
    Messages:
    191
    Likes Received:
    24
    Another option for people using a debit card to pay for UO...
    Most, if not all, banks offer a text if more than (ammount here) dollars is used/withdrawn/charged from your account.
    Example: 20.00 dollars has been withdrawn from ATM NAME. This is above your requested limit.
    I would suggest setting it at 19.99. Ive never seen an atm let you withdraw less than 20.00.
    Just a thought.
    Glad people are finding this info useful!
    EA in need of a PR body?
     
  25. Tomarke

    Tomarke Seasoned Veteran
    Stratics Veteran D^A

    Joined:
    Oct 22, 2011
    Messages:
    373
    Likes Received:
    182
    I have two step verification enabled on my origin account so I get a text whenever someone tries to login to my account. Then I login and change my password.

    This just happened the other night. I got a text for login verification with a language that looked like it came from Eastern Europe. Changed my password and all is good for the time being. Luckily I also don't have my CC info stored on the site as I use the PayPal/game time code option.
     
    DJAd likes this.
  26. PlayerSkillFTW

    PlayerSkillFTW Lore Master
    Stratics Veteran

    Joined:
    May 12, 2008
    Messages:
    1,020
    Likes Received:
    430
    Lol, great. EA has locked my Origin account because "We have taken this step as we have detected suspicious activity on your account during on-going standard systems analysis", when i had already resolved the account compromise earlier.

    So now, i'm having to call EA once again, and their Customer Support extension is just some recorded message basically telling me that they no longer do Customer Support over the phone, and that i have to go to help.ea.com instead. That website wants me to login to my Origin account in order to contact them, which the entire problem in the first place, is that they locked my Origin account and i can't log into it. Dee dee dee.

    Called them again, sat on the phone until it directed me to someone to talk to, so i told the woman that my Origin account was locked and that i couldn't use help.ea.com because of it, so she redirects me to some dude whom i have a hard time understanding what he's saying (probably Indian). I explain my problem to him, he tells me to e-mail [email protected], and says he'll e-mail me with the information i need. Well, i'm not so sure he got my e-mail right, i still haven't received an e-mail from him...
     
    #26 PlayerSkillFTW, Feb 20, 2015
    Last edited: Feb 20, 2015
  27. The Zog historian

    The Zog historian Babbling Loonie
    Stratics Veteran

    Joined:
    Feb 25, 2010
    Messages:
    2,165
    Likes Received:
    870
    I hope no one's using a debit card to pay for UO. It's better to use the debit card to buy a game time code. If a debit card has been compromised in any way, most any bank will still treat it as a lost card, and the account holder can be liable for the first $50. Even if you get fully reimbursed, it can take a couple of weeks versus a few days with a credit card.
     
  28. MalagAste

    MalagAste Belaern d'Zhaunil
    Reporter Professional Governor Stratics Veteran Stratics Legend Campaign Supporter Royal Knight

    Joined:
    Aug 21, 2000
    Messages:
    18,960
    Likes Received:
    5,449
    My Bank won't allow "out of country" charges on my CC. This means they can't charge the FiFa thing on there. Infact my bank doesn't want to do any business with EA at all right now saying that it's been dealing in fraudulent charges for a long time now and often times they have had to file fraud against EA too many times they prefer not to deal with them.

    Paypal and Gametime cards is a good way to go. Adding that extra security to being called before transactions are made is also good.

    I've never had much problem with paypal however I must warn folk that currently there are scammers in-game wanting to "buy" things from you using Paypal..... this person then gets the item from you in game and then has Paypal reverse the charges claiming he never "got" the item. Seller beware this guy has done it several times. Another reason not to use RL money for in-game stuff that isn't from EA/Origin... I'll be happy when they get something better than the Origin store for selling us stuff for UO.
     
  • About Us

    Stratics is the oldest continually running MMORPG Fansite on the Internet. Founded in 1997 Stratics has served the Ultima Online Community for 18 years. We strive to provide the most complete social experience for Ultima Online players.
  • Subscribe Now!

    Want to provide Continual Support? Subscribe and gain additional benefits as a patron of Stratics.com!
    Subscribe Now!

    Stratics Professional Accounts feature the following advantages:

    • Ad-Free Browsing of our Forums
    • Upload a custom Profile Cover
    • Unlimited media upload storage space
    • Use of the theme styler
    • Ability to collapse the sidebar
    • Premium background themes to choose from
    • Access to additional features of the Classifieds System
    • Ability to Customize Your User Title
    • No Post Delays
    • Additional Signature Allowances:
    • Special Professional Banner Display with your Account
    • PM Allowance Upgrade
    • Additional Thread Allowances
  • Support Us!

    Don't feel like subscribing? Donations to benefit the further development of Stratics and for purchase and inclusion of additional features are always welcome.

    Donate to us!