{"id":8425,"date":"2023-08-07T12:00:00","date_gmt":"2023-08-07T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/2023\/08\/07\/time-is-money-and-online-game-scammers-have-lots-of-it\/"},"modified":"2023-08-07T12:00:00","modified_gmt":"2023-08-07T09:00:00","slug":"time-is-money-and-online-game-scammers-have-lots-of-it","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2023\/08\/07\/time-is-money-and-online-game-scammers-have-lots-of-it\/","title":{"rendered":"Time is money, and online game scammers have lots of it"},"content":{"rendered":"<\/p>\n<p><span lang=\"EN-US\">One of the more worrying trends of the past few years within the gaming sphere has been the introduction of <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.xfire.com\/10-most-expensive-microtransactions-dlc\/\"><span>microtransactions<\/span><\/a><\/span><span lang=\"EN-US\">, which ask you to provide your money in case you want to fast-track an in-game event or buy better equipment, or additional skins for your character, for example. Nowadays, this can ring true both for multiplayer and single-player games; hence there are many more opportunities for malicious actors to take advantage of you.<\/span><\/p>\n<p><span lang=\"EN-US\">The ubiquity of scams within online gaming enables a degree of interaction between players through in-game chat or voice services. Most often, these places represent the first contact points between scammers and their victims, which can impact not only adults but also kids due to the nature of these games.<\/span><\/p>\n<\/p>\n<h2><span lang=\"EN-US\">Fishing for money<\/span><\/h2>\n<p><span lang=\"EN-US\">Cybercriminals exploit online games as a means of earning income, either by stealing and selling user data or by tricking them into giving up their bank account information. With that, <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/stealthy-seroxen-rat-malware-increasingly-used-to-target-gamers\/\"><span>ransomware, viruses, and trojans<\/span><\/a><\/span><span lang=\"EN-US\"> are also used to target players and try to siphon money from them.<\/span><\/p>\n<p><span lang=\"EN-US\">The most significant opportunity in this regard is virtual currencies, skins, weapons, and similar, as many game developers sell these for various amounts of money, with some skins costing <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.pcgamer.com\/counter-strike-skin-sells-for-dollar400k-probably-the-most-expensive-gun-in-videogame-history\/\"><span>hundreds of dollars or more due to their rarity<\/span><\/a><\/span><span lang=\"EN-US\">.<\/span><\/p>\n<p><span lang=\"EN-US\">A <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.theguardian.com\/money\/2021\/oct\/17\/from-fortnite-to-fifa-online-video-game-players-warned-of-rise-in\"><span>scammer<\/span><\/a><\/span><span lang=\"EN-US\"> can easily create an account for an online game and then use stolen credit card details to purchase said things, and once the account is fully stocked, it can be sold off for tidy sums. Some <\/span><span lang=\"EN-US\">accounts can sell for thousands<\/span><span lang=\"EN-US\">, exchanging virtual objects for real-world currency. <\/span><\/p>\n<h2><span lang=\"EN-US\">Sanctuary under attack<\/span><\/h2>\n<p><span lang=\"EN-US\">Of course, online games do employ various levels of protection to secure the users\u2019 accounts; however, account hijacks still happen, as the data within these accounts can have tremendous value, either because of the player\u2019s accumulated in-game wealth or the various <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-steal-steam-accounts-in-new-browser-in-the-browser-attacks\/\"><span>licenses they might own on online game stores<\/span><\/a><\/span><span lang=\"EN-US\">, as well as their personally identifiable information, like phone numbers, address, emails, and financial information.<\/span><\/p>\n<p><span lang=\"EN-US\">All it takes is one <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.welivesecurity.com\/2023\/01\/02\/most-common-passwords-what-do-if-yours-list\/\"><span>weak password<\/span><\/a><\/span><span lang=\"EN-US\">, and your account might fall out of your hands entirely, especially when people tend to still use the same weak passwords as always, instead of opting for stronger ones or, even better, use a <\/span><span lang=\"EN-US\"><a href=\"https:\/\/help.eset.com\/password_manager\/3\/en-US\/index.html\"><span>secure password managers<\/span><\/a><\/span><span lang=\"EN-US\">. <\/span><\/p>\n<p><span lang=\"EN-US\">An added problem also is that many game services lack additional authentication methods, or the provider could <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/2k-games-warns-users-their-stolen-data-is-now-up-for-sale-online\/\"><span>suffer a data breach exposing passwords<\/span><\/a><\/span><span lang=\"EN-US\">. In a way, it is like the various wars between the Horde and the Alliance in Warcraft; one gains, the other loses.<\/span><\/p>\n<blockquote>\n<p><span lang=\"EN-US\">Related reading: <a href=\"https:\/\/www.welivesecurity.com\/2022\/01\/05\/5-ways-hackers-steal-passwords-how-stop-them\/\">5 ways hackers steal passwords (and how to stop them)<\/a><\/span><\/p>\n<\/blockquote>\n<h2><span lang=\"EN-US\">Friendly fraud<\/span><\/h2>\n<p><span lang=\"EN-US\">One of the perhaps lesser-known scams within the online world is <\/span><span lang=\"EN-US\"><a href=\"https:\/\/technext24.com\/2023\/03\/06\/friendly-fraud-prevent-it\/\"><span>Friendly Fraud<\/span><\/a><\/span><span lang=\"EN-US\">. <span><br \/>\n<\/span>Despite that, it is monumental, as just in the United States, eCommerce merchants report as much as <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.cbsnews.com\/news\/friendly-fraud-an-enemy-to-everyone-in-the-e-commerce-chain\/\"><span>$11.8 billion in losses<\/span><\/a><\/span><span lang=\"EN-US\">. This has become an increasing issue due to microtransactions. How it happens is that a child could overcharge their parents\u2019 credit cards by making in-app purchases to get some special skin\/in-game currency, for example. A parent might not know about this and dispute the charges on their bank account with their bank or the game company.<\/span><\/p>\n<p><span lang=\"EN-US\">While maybe unintended, these disputes can still overwhelm the bank and gaming company or make the parents look like scammers. Why? Well, intentional Friendly Fraud also exists, in which case gamers, or people pretending to be gamers, purchase a game\/currency and then dispute the charges on their credit card bill to receive a refund. It\u2019s like buying a shirt, wearing it for a day or two, and then returning it to the store to get your money back.<\/span><\/p>\n<h2><span lang=\"EN-US\">Summoner\u2019s fault (mostly)<\/span><\/h2>\n<p><span lang=\"EN-US\">Apart from the previously mentioned tricks, malicious actors also like to extract credentials through fake promotional material, like free exclusive items and game-time promotions on social media, leading you to a fake login website to extract your personal information and maybe even provide you with malware for free! How exciting, right?<\/span><\/p>\n<p><span lang=\"EN-US\">Even in-game trade can be dangerous, as the transactions can happen outside the game\u2019s limits <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.paypal.com\/us\/cshelp\/article\/what-are-common-scams-and-how-do-i-spot-them-help201\"><span>through PayPal<\/span><\/a><\/span><span lang=\"EN-US\">, for example, after which the fraudster disputes the payments, leaving you without the desired item and a monetary loss. Notice how many of these scams rely on user error, which is just the reality, as human error is still the <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252522226\/SANS-Institute-Human-error-remains-the-top-security-issue\"><span>leading cybersecurity issue<\/span><\/a><\/span><span lang=\"EN-US\">.<\/span><\/p>\n<h2><span lang=\"EN-US\">What can a gamer do to protect themselves?<\/span><\/h2>\n<p><span lang=\"EN-US\">Thankfully, there are certain security tips a gamer can utilize to protect their precious accounts and game-time from malicious actors. Here\u2019s a few:<\/span><\/p>\n<ul>\n<li><strong><span lang=\"EN-US\">Use a strong password<\/span><\/strong><span lang=\"EN-US\"> \u2013 This advice sadly needs to be repeated. Try to stay away from simple word + number combinations and mix it up with special characters, capital letters, or try <\/span><a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/05\/forget-about-passwords-you-need-a-passphrase\/\"><span>passphrases<\/span><\/a><span lang=\"EN-US\">, which are more complex and yet a more memorable alternative.<\/span><\/li>\n<li><strong><span lang=\"EN-US\">Use multi-factor authentication <\/span><\/strong><span lang=\"EN-US\">\u2013 An additional authentication method, best done by using a one-time code generating app like <\/span><a href=\"https:\/\/www.pcmag.com\/how-to\/turn-microsoft-authenticator-into-your-password-manager\"><span>Microsoft Authenticator<\/span><\/a><span lang=\"EN-US\"> or <\/span><a href=\"https:\/\/authy.com\/\"><span>Authy<\/span><\/a><span lang=\"EN-US\"> is a must when properly securing any account. <\/span><\/li>\n<li><strong><span lang=\"EN-US\">Try to purchase game content in-house <\/span><\/strong><span lang=\"EN-US\">\u2013Try to make your purchases inside the game\u2019s own store, or through an official reseller, not providing your financial details to scammers.<\/span><\/li>\n<li><strong><span lang=\"EN-US\">Don\u2019t fall for giveaways <\/span><\/strong><span lang=\"EN-US\">\u2013 Some games can have free giveaways of in-game content, but there can be cases when those asking for your account details are fraudulent \u2013 always verify whether the giveaway is done by an officially approved source.<\/span><\/li>\n<li><strong><span lang=\"EN-US\">Never provide account info to others <\/span><\/strong><span lang=\"EN-US\">&#8211; This advice gets often repeated in World of Warcraft especially \u2013 a game admin or developer would never ask for your credit card number or bank details, especially not inside an online game. <\/span><\/li>\n<\/ul>\n<p><span lang=\"EN-US\">And in case your account got hacked for one reason or another, on Steam, for example, there are ways you can deal with it to reach a <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.welivesecurity.com\/2022\/10\/10\/steam-account-stolen-how-get-back\/\"><span>successful recovery<\/span><\/a><\/span><span lang=\"EN-US\">. This does not mean that gamers should not stay vigilant. As the lucrative world of gaming will always be under the threat of shady moneymakers and hackers. Stay safe and watch out for any dangers lurking in the shadows.<\/span><\/p>\n<blockquote>\n<p><span lang=\"EN-US\">Before you go: <a href=\"https:\/\/www.welivesecurity.com\/2022\/10\/10\/steam-account-stolen-how-get-back\/\">Steam account hacked? Here\u2019s how to get it back<\/a><\/span><\/p>\n<\/blockquote>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/scams\/time-is-money-and-online-game-scammers-have-lots-of-it\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gamers and cybersecurity professionals have something in common \u2013 the ever-terrible presence of hacking, scams, and data theft \u2013 but how and why would anyone want to target gamers?<\/p>\n","protected":false},"author":5,"featured_media":8426,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[147],"tags":[],"class_list":["post-8425","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybercrime"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8425"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8425\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8426"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}