Post Reply Compromised Account - Email Changed
10063 cr points
Send Message: Send PM GB Post
F
Offline
Posted 11/14/15
I have already used the help/contact form but the last time I used the help forum it took 13 DAYS for CR support to reply to me. Basically my account email has been changed (and verified) by another user and my account password was changed. I can't change my password as my email has been changed and verified. This sucks. The only way I am able to log into my account right now is through Facebook login which I fortunately have linked to my Facebook account. Fix this! I cannot wait 13 days to have a piece of mind of where my billing information is accessed! This seriously makes me consider leaving CR for good. I never even received an email from CR letting me know that my email was successfully changed, that's just bad account security! I'm a premium member and for some stupid reason I can't cancel my membership. I'm stuck sitting here with an account someone likely has logged into and has already seen my billing info and my home address.

16757 cr points
Send Message: Send PM GB Post
Hoosierville
Offline
Posted 11/15/15
Most people get hacked because they have viruses/key loggers on their computer. Hackers are too lazy anymore to target anyone specific when people are more than willing to install viruses.
37709 cr points
Send Message: Send PM GB Post
45 / Seattle
Offline
Posted 11/15/15

yennster wrote:

I have already used the help/contact form but the last time I used the help forum it took 13 DAYS for CR support to reply to me. Basically my account email has been changed (and verified) by another user and my account password was changed. I can't change my password as my email has been changed and verified. This sucks. The only way I am able to log into my account right now is through Facebook login which I fortunately have linked to my Facebook account. Fix this! I cannot wait 13 days to have a piece of mind of where my billing information is accessed! This seriously makes me consider leaving CR for good. I never even received an email from CR letting me know that my email was successfully changed, that's just bad account security! I'm a premium member and for some stupid reason I can't cancel my membership. I'm stuck sitting here with an account someone likely has logged into and has already seen my billing info and my home address.



I'm really sorry to hear about your experience, and I hope the financial damage is minimal.

1) If you haven't already, please check your credit card statement or bank statement (if debit) immediately. The intruder is likely to have run up a bill in the CR store, and this can do more damage than most people realize (particularly with a debit card). If it were me and I had a debit card on file, I would report it lost or stolen right away. (Among other factors, the time frame in which you're protected is limited.)
2) Once you've done that, this will help to put things in context and provide some answers to your implied questions above.
3) Take your card information off file, the instant your subscription has expired and you're allowed to. If you decide to stay on despite what's happened, this offers a few payment alternatives.

There is one bit of good news: The intruder doesn't have access to your full card number. But CR will let them keep buying items in the store until they see your post and act on it, so you need to quickly decide whether to report your card lost or stolen.
Der Zoodirektor
23405 cr points
Send Message: Send PM GB Post
34 / M / Germany
Offline
Posted 11/15/15

yennster wrote:

I have already used the help/contact form but the last time I used the help forum it took 13 DAYS for CR support to reply to me. Basically my account email has been changed (and verified) by another user and my account password was changed. I can't change my password as my email has been changed and verified. This sucks. The only way I am able to log into my account right now is through Facebook login which I fortunately have linked to my Facebook account. Fix this! I cannot wait 13 days to have a piece of mind of where my billing information is accessed! This seriously makes me consider leaving CR for good. I never even received an email from CR letting me know that my email was successfully changed, that's just bad account security! I'm a premium member and for some stupid reason I can't cancel my membership. I'm stuck sitting here with an account someone likely has logged into and has already seen my billing info and my home address.



Replied to your support ticket.
The Wise Wizard
100929 cr points
Send Message: Send PM GB Post
56 / M / U.S.A. (mid-south)
Offline
Posted 11/15/15

yennster wrote:

I never even received an email from CR letting me know that my email was successfully changed, that's just bad account security!

I agree with this.

I don't see how changing the current system from only sending an e-mail to the new address to sending one to both the new and old e-mail address would be difficult to implement.

Surprisingly, it seems CR may not be alone in having this flaw. I saw a message recently over on the Funimation forum that indicated they also apparently fail to send an e-mail to the old e-mail address.


A better system would be to also include a link in the e-mail sent the old address that would allow reverting the change if it wasn't authorized, but that would require a more substantial change to the code.

2994 cr points
Send Message: Send PM GB Post
Offline
Posted 5/14/16
Someone please tell me at least this much is implemented by now 0.0 I don't have a spare account handy to check...
You must be logged in to post.