Feeds

Account pretexters plague Xbox Live

Account thieves numerous and brazen

5 things you didn’t know about cloud backup

After initially denying that the service had been hacked, Microsoft said the company is now investigating the issue, but stressed that the problems seem more to do with pretexting than with a security breach of its systems.

"Recently, there have been reports of fraudulent activity and account theft taking place on the Xbox Live network," the software giant said in a statement sent to SecurityFocus. "Security is a top priority for Xbox Live, and we are actively investigating all reports of fraudulent behavior and theft."

Pretexting - another term for social engineering schemes designed to facilitate access to a victim's account - came to national prominence last September when a member of Hewlett-Packard's board revealed that the company had hired private investigators to uncover a leak and that the investigators apparently used pretexting to get access to board members' and journalists' phone records. Patricia Dunn, the former CEO of the company, was recently cleared of charges in the case.

Microsoft and Bungie have not indicated how widespread their own pretexting issues might be, but anecdotal evidence points to endemic account stealing issues.

Groups other than Clan Infamous have also boasted about their account-stealing capabilities, and victims have posted complaints in both Xbox Live forums and in other sites around the internet.

Finisterre may have gotten off lightly. Other victims have more serious stories to tell.

Mr Jokerz, the online handle used by a 19-year-old college student from Michigan, used to run his own clan, T3am Hazard, for playing Halo 2. The teenager, who asked not to be identified by name, found his team at a disadvantage against the cheats commonly used by abusers such as Clan Infamous. Complaints were immediately met with retribution.

Over a matter of months, Mr Jokerz's account was stolen six times and several thousand dollars worth of Microsoft points charged to his credit card, the teenager claimed. The attackers, which Mr Jokerz identified as Clan Infamous, quickly decimated the accounts belonging to the leaders and staff members of T3am Hazard.

"They go after anybody they want to," Mr. Jokerz told SecurityFocus in an online chat. "They just went after me a lot because I was the overlord (leader) of the clan."

The bullying went beyond the game world as well. From his account, the attackers harvested Mr Jokerz's home address and telephone number and called his house more than 100 times, the teenager said. Eventually, the teenager filed a police report. The Halo 2 player also said he identified the names and addresses of the clan members involved and gave them to both the police and Microsoft, but has heard no response back regarding any investigation. Microsoft could not immediately confirm Mr Jokerz's account.

The apparent lack of action has made Clan Infamous quite brazen. In a statement on the clan's site, they dismissed the efforts of Microsoft and Bungie to halt cheaters and account stealing and threw down the gauntlet in front of the company's investigators.

"You guys can't even freeze our accounts," the clan stated on their site. "You are pathetic, a joke...We aren't afraid of you one bit, so we will continue to steal accounts (and) max out credit cards until you find a way to stop us."

This article originally appeared in Security Focus.

Copyright © 2007, SecurityFocus

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.