Aller au contenu

Photo

Spam to EA email & unable to use EA support


  • Veuillez vous connecter pour répondre
17 réponses à ce sujet

#1
vometia

vometia
  • Members
  • 2 721 messages
I've noticed I've started getting quite a lot of spam being sent to my EA Games email address over the past couple of days, which is a worry since I only use it to login to my EA Games accounts.  This does suggest a rather worrying security breach in terms of confidentiality, games codes and potentially compromised credit card information; anybody know anything about it?

I was going to raise a support ticket on the support.ea.com site but since I updated my address I can no longer login; there's no error as there is when I use my old address, it just goes straight back to the login screen.  Anybody know what's up with that?  I thought it might be because my address was unverified, but it still does the same after verification.

#2
KarmaInferno

KarmaInferno
  • Members
  • 1 messages
I'm getting the same issue - I have a unique e-mail address for the Bioware social network, only used to access the network and never ever anywhere else. Yet over the past week or so, multiple spam mails are arriving at that address.

#3
Parahexavoctal

Parahexavoctal
  • Members
  • 81 messages
Exactly the same issue here; a unique email account used only for my bioware account, and lately it's been receiving spam.

I too am curious if my contact information has been shared with 3rd parties, if there's been a breach or there's an exploit of this website in progress.

#4
ElofValant

ElofValant
  • Members
  • 105 messages
Same here - started to receive spam to my EA/DA e-mail address. Same spam that others are also getting..

Also of note is I recently got a call from my CC company about possible fraudulent charges being made against a CC I have.. a card that I only use with certain automatic charges.. and also recently used to purchase bio points to by the Exiled Prince DLC.

Just seems suspicious and worrisome that I start getting spam e-mails.. and also have to cancel a CC (and get it re-issued.. and the fun of having to re-configure all automatic transactions as well) at around the same time as all the spam happens because of possible fraudulent use (a card that I know exactly what gets charged to it and when it gets used, for everyday/other CC use I have another card I use).

#5
Desyndra

Desyndra
  • Members
  • 45 messages
Today I also received a spam message to my EA master account email. It is a unique disposable address (I'm using unique disposable e-mail addresses so I can identify where it is likely that my personal data is getting compromised) that I do not use anywhere else except to log in to EA master account, both through the website and the games that require online access.

My computer is protected by a firewall/virus scanner/anti-adware/anti-spam solution. I ran a full system scan on both the system drive and the game folders. No infection.

Modifié par Desyndra, 02 avril 2011 - 10:28 .


#6
flexxdk

flexxdk
  • Members
  • 1 791 messages
No spam here.

Perhaps you should run extra checks on your filter? It could be letting some stuff through...

#7
Parahexavoctal

Parahexavoctal
  • Members
  • 81 messages
This is not really about filters. An email address that only Bioware/EA and me are supposed to know exists should receive no spam at all.

The spam does in fact get caught in my filter, but I worry that it was even sent in the first place, because it could signify that my information has been compromised or shared with 3rd parties without my consent.

Granted, there are other ways the address could have gotten into the hands of the spammers (assuming they aren't just spamming addresses at random and managed to hit it). But since it is currently the only address being spammed among many such similar addresses created for the sole purpose of signing up for a specific service.. I believe I have cause to worry a little on the state of matters at Bioware/EA's end.

#8
vometia

vometia
  • Members
  • 2 721 messages
I've mentioned it elsewhere, but for the record, I registered a new email address with EA and terminated the old one, but within a couple of days the new address also started getting spammed, so it seems that the security breach still hasn't been fixed (or hadn't as of about mid week).

These email addresses were also unique to EA, and the newest one was created only a few days ago.

#9
Shonk1

Shonk1
  • Members
  • 5 messages
I have received 3 casino e-mail's in the last week
too 3 unique e-mail addresses that ea have

ea-address1@mydomain.com
xbox-account1@mydomain.com
xbox-account2@mydomain.com

ea's e-mail database has been dumped
at first i thought it was microsoft that was dumped
but then a few hours later an address that only ea have came

if you havnt guessed it already when you play any ea game on the xbox
ea get your e-mail address tied to the profile

Modifié par Shonk1, 04 avril 2011 - 03:59 .


#10
Shonk1

Shonk1
  • Members
  • 5 messages
I wont include the e-mail contents
but here's the headers with my address edited out

Delivered-To: ea-address@edited
Received: by 10.220.95.205 with SMTP id e13cs215535vcn;
Fri, 1 Apr 2011 15:27:06 -0700 (PDT)
Received: by 10.216.80.25 with SMTP id j25mr4469266wee.35.1301696826087;
Fri, 01 Apr 2011 15:27:06 -0700 (PDT)
Return-Path: <chatterjeeqvv.morrisfra208@hotmail.com>
Received: from dub0-omc1-s19.dub0.hotmail.com (dub0-omc1-s19.dub0.hotmail.com [157.55.0.218])
by mx.google.com with ESMTP id m31si5464099wei.66.2011.04.01.15.27.05;
Fri, 01 Apr 2011 15:27:06 -0700 (PDT)
Received-SPF: pass (google.com: domain of chatterjeeqvv.morrisfra208@hotmail.com designates 157.55.0.218 as permitted sender) client-ip=157.55.0.218;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of chatterjeeqvv.morrisfra208@hotmail.com designates 157.55.0.218 as permitted sender) smtp.mail=chatterjeeqvv.morrisfra208@hotmail.com
Received: from DUB103-W37 ([157.55.0.237]) by dub0-omc1-s19.dub0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
Fri, 1 Apr 2011 15:27:05 -0700
Message-ID: <DUB103-w374312E30833F3E3294602D0BE0@phx.gbl>
Return-Path: chatterjeeqvv.morrisfra208@hotmail.com
Content-Type: multipart/alternative;
boundary="_28324102-bc13-4784-a32a-1bf7d697d9cf_"
X-Originating-IP: [190.212.134.142]
From: Morris Chatterjee <Chatterjeeqvv.Morrisfra208@hotmail.com>
To: <ea@wasnt-my-address-but-edited-incase-it-was-someones>
Subject: Re:BestPlayCasino?Now
Date: Fri, 1 Apr 2011 22:27:05 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 01 Apr 2011 22:27:05.0268 (UTC) FILETIME=[EDFF6740:01CBF0BB]

Modifié par Shonk1, 04 avril 2011 - 04:07 .


#11
Shonk1

Shonk1
  • Members
  • 5 messages
Headers from xbox profile 1

Delivered-To: xbox-profile1@edited
Received: by 10.220.95.205 with SMTP id e13cs222512vcn;
Fri, 1 Apr 2011 22:54:19 -0700 (PDT)
Received: by 10.150.65.9 with SMTP id n9mr5077407yba.177.1301723658946;
Fri, 01 Apr 2011 22:54:18 -0700 (PDT)
Return-Path: <elsiebw_mochu217@hotmail.com>
Received: from snt0-omc1-s42.snt0.hotmail.com (snt0-omc1-s42.snt0.hotmail.com [65.54.61.79])
by mx.google.com with ESMTP id f13si7423880ybi.1.2011.04.01.22.54.18;
Fri, 01 Apr 2011 22:54:18 -0700 (PDT)
Received-SPF: pass (google.com: domain of elsiebw_mochu217@hotmail.com designates 65.54.61.79 as permitted sender) client-ip=65.54.61.79;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of elsiebw_mochu217@hotmail.com designates 65.54.61.79 as permitted sender) smtp.mail=elsiebw_mochu217@hotmail.com
Received: from SNT104-W15 ([65.55.90.8]) by snt0-omc1-s42.snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
Fri, 1 Apr 2011 22:54:18 -0700
Message-ID: <SNT104-W15E4CF4100A233930E08FBBBA10@phx.gbl>
Return-Path: elsiebw_mochu217@hotmail.com
Content-Type: multipart/alternative;
boundary="_d8fe4e13-ac22-4b69-a189-4d614b9ab826_"
X-Originating-IP: [182.71.11.92]
From: Elsie Moch <Elsiebw_Mochu217@hotmail.com>
To: <edited@wasnt-my-address-but-edited-incase-it-was-someones>
Subject: Re:Good%Casino!Get
Date: Sat, 2 Apr 2011 05:54:18 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 02 Apr 2011 05:54:18.0406 (UTC) FILETIME=[67CB5460:01CBF0FA]

#12
Shonk1

Shonk1
  • Members
  • 5 messages
Headers from xbox profile 2

Delivered-To: xbox-profile2@edited
Received: by 10.220.95.205 with SMTP id e13cs222519vcn;
Fri, 1 Apr 2011 22:55:02 -0700 (PDT)
Received: by 10.224.200.65 with SMTP id ev1mr3984749qab.338.1301723702623;
Fri, 01 Apr 2011 22:55:02 -0700 (PDT)
Return-Path: <batzlik_louisewr678@hotmail.com>
Received: from blu0-omc1-s37.blu0.hotmail.com (blu0-omc1-s37.blu0.hotmail.com [65.55.116.48])
by mx.google.com with ESMTP id bb9si6401183qcb.71.2011.04.01.22.55.02;
Fri, 01 Apr 2011 22:55:02 -0700 (PDT)
Received-SPF: pass (google.com: domain of batzlik_louisewr678@hotmail.com designates 65.55.116.48 as permitted sender) client-ip=65.55.116.48;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of batzlik_louisewr678@hotmail.com designates 65.55.116.48 as permitted sender) smtp.mail=batzlik_louisewr678@hotmail.com
Received: from BLU150-W7 ([65.55.116.8]) by blu0-omc1-s37.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
Fri, 1 Apr 2011 22:55:02 -0700
Message-ID: <BLU150-w7D3AD8031F87A7A44E096C6A10@phx.gbl>
Return-Path: batzlik_louisewr678@hotmail.com
Content-Type: multipart/alternative;
boundary="_cc10093b-2381-4a57-a57d-c5568ddd7eff_"
X-Originating-IP: [113.169.84.65]
From: Louise Batzli <Batzlik_Louisewr678@hotmail.com>
To: <edited@wasnt-my-address-but-edited-incase-it-was-someones>
Subject: Re:Good~EuropeCasino?Get
Date: Sat, 2 Apr 2011 05:55:02 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 02 Apr 2011 05:55:02.0209 (UTC) FILETIME=[81E72310:01CBF0FA]

#13
Squirrelly

Squirrelly
  • Members
  • 5 messages
Here too, getting spam to my BioWare-only email address.  Looks like in the news that a lot of sites are having their emails hacked into recently.  Would be nice if BioWare would inform us of this.

Here are some headers from mine for reference too, if helps track it for others or BioWare, minus my email/server info:

Return-path: <stacyzmcasstevensti657@hotmail.com>
Envelope-to: mybiowareaddress@domain.com
Delivery-date: Fri, 01 Apr 2011 17:03:33 -0400
Received: from col0-omc3-s16.col0.hotmail.com ([65.55.34.154])
    by myserver.domain.com with esmtp (Exim 4.69)
    (envelope-from <stacyzmcasstevensti657@hotmail.com>)
    id 1Q5lUy-0001OK-9H
    for mybiowareaddress@domain.com; Fri, 01 Apr 2011 17:03:29 -0400
Received: from COL108-W41 ([65.55.34.135]) by col0-omc3-s16.col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
     Fri, 1 Apr 2011 14:02:09 -0700
Message-ID: <COL108-W412A4E77A67AC0E4CFC10E90BE0@phx.gbl>
Content-Type: multipart/alternative;
    boundary="_fe64815a-79d6-466f-84de-69529c1a88d7_"
X-Originating-IP: [189.194.239.134]
From: Stacy Casstevens <StacyzmCasstevensti657@hotmail.com>
To: <someoneelses@domain.com>
Subject: Re:Best>Casino?Check
Date: Fri, 1 Apr 2011 21:02:09 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 01 Apr 2011 21:02:09.0749 (UTC) FILETIME=[10D4E850:01CBF0B0]
X-Spam-Status: No, score=4.1
X-Spam-Score: 41
X-Spam-Bar: ++++
X-Ham-Report: Spam detection software, running on the system "myserver.domain.com", has
    identified this incoming email as possible spam.  The original message
    has been attached to this so you can view it (if it isn't spam) or label
    similar future email.  If you have any questions, see
    the administrator of that system for details.
    Content preview:  23:26) is HiS DEmand. The mor~e p$r^ec^Ious CHrIst Is to
    *us, the more %delight dOes He have in us. 5. , An (indiv!idual who iS pR&ofIted
    From the ScriPtures has An IncreasIng cONfiDE~nce in C!hr$is&t. [...]
    Content analysis details:   (4.1 points, 5.0 required)
    pts rule name              description
    ---- ---------------------- --------------------------------------------------
    -0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at http://www.dnswl.org/, low
    trust
    [65.55.34.154 listed in list.dnswl.org]
    1.7 URIBL_BLACK            Contains an URL listed in the URIBL blacklist
    [URIs: kore.us]
    0.0 FREEMAIL_FROM          Sender email is freemail
    (stacyzmcasstevensti657[at]hotmail.com)
    -0.0 T_RP_MATCHES_RCVD      Envelope sender domain matches handover relay
    domain
    1.6 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
    digit (stacyzmcasstevensti657[at]hotmail.com)
    0.0 HTML_MESSAGE           BODY: HTML included in message
    0.8 BAYES_50               BODY: Bayes spam probability is 40 to 60%
    [score: 0.4997]
    0.0 RFC_ABUSE_POST         Both abuse and postmaster missing on sender domain
X-Spam-Flag: NO


 23:26) is HiS DEmand.  The mor~e p$r^ec^Ious CHrIst Is to *us=2C the more =
%delight dOes He have in us.
 =20

http://@yoUtube.c%o^M/SgGcr2

  5. =2C An (indiv!idual who iS pR&ofIted From the ScriPtures has An Increa=
sIng cONfiDE~nce in C!hr$is&t.

#14
Squirrelly

Squirrelly
  • Members
  • 5 messages
And ah, I found a more complete Email Address Leak post about this, but I can't post to it because it's a DA2 only forum (I have DAO).  Might be nice to move that to a more general forum like this one.  That post does at least have an official acknowledgement from BioWare (though no answer yet), and mentions the Epsilon email issue too.

#15
Shonk1

Shonk1
  • Members
  • 5 messages
they are making another spam run

Delivered-To: eaaddress@edited
Received: by 10.220.95.205 with SMTP id e13cs30574vcn;
Wed, 6 Apr 2011 21:20:30 -0700 (PDT)
Received: by 10.90.6.37 with SMTP id 37mr357339agf.30.1302150030090;
Wed, 06 Apr 2011 21:20:30 -0700 (PDT)
Return-Path: <patelfvvr@hotmail.com>
Received: from col0-omc4-s19.col0.hotmail.com (col0-omc4-s19.col0.hotmail.com [65.55.34.221])
by mx.google.com with ESMTP id w32si3242046ana.200.2011.04.06.21.20.29;
Wed, 06 Apr 2011 21:20:30 -0700 (PDT)
Received-SPF: pass (google.com: domain of patelfvvr@hotmail.com designates 65.55.34.221 as permitted sender) client-ip=65.55.34.221;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of patelfvvr@hotmail.com designates 65.55.34.221 as permitted sender) smtp.mail=patelfvvr@hotmail.com
Received: from COL111-W24 ([65.55.34.200]) by col0-omc4-s19.col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
Wed, 6 Apr 2011 21:20:29 -0700
Message-ID: <COL111-W24946857FA5C703152A9E9B7A40@phx.gbl>
Return-Path: patelfvvr@hotmail.com
Content-Type: multipart/alternative;
boundary="_afd24c03-93bb-4ab3-b5fe-48423cf3a6a1_"
X-Originating-IP: [186.11.52.210]
From: Steve Patel <patelfvvr@hotmail.com>
To: <notme@edtied out>
Subject: Re:Best-Casino=Check
Date: Thu, 7 Apr 2011 04:20:29 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 07 Apr 2011 04:20:29.0489 (UTC) FILETIME=[20C38210:01CBF4DB]

#16
Squirrelly

Squirrelly
  • Members
  • 5 messages
Ditto.

Subject: Re:Best+CasinoPlay}Click
Date: Wed, 6 Apr 2011 23:13:58 +0000

Problem is, once they have your address, no fix can take it back. Well, unless that fix includes reverse hacking back into the hackers' computers and deleting the email lists. :-)

#17
vometia

vometia
  • Members
  • 2 721 messages
You can create a new email address and change your login credentials: once you're sure everything is working, just disable your old email address (assuming you're not using it anywhere else) and the spams will bounce. If you weren't previously using a unique email, now is a good time to start! If nothing else, it helps determine where problems originated.

Beware, though: as the title says, I haven't been able to use support.ea.com since changing my email.

Oh, and a possible erratum: it's looking increasingly likely that the second email address being "spammed" was actually a false positive from a legit EA email: seems it had malformed headers and triggered my spam filter and subsequently appeared in my spam analysis. So it looks like it was just a single batch of emails that were lifted, possibly via the now well-documented Epsilon (email marketing/distribution company) breach.

#18
Squirrelly

Squirrelly
  • Members
  • 5 messages
Yes, when I was checking for what all spam I was getting to my email address from here, I found the legit email alerts from here were being caught as spam. Apparently they are formatted or verified worse than the casino spam that is getting through. Go figure. :-)