Open Side Menu Go to the Top
Register
Compromised account on PokerStars Compromised account on PokerStars

06-26-2019 , 01:07 PM
Hello everybody.

A few days ago someone changed my password to the email I got to PokerStars, then immediately the password I had to sign up for PokerStars.

I wrote to support that somebody hacked me. I wanted to block all transactions. They requested ID card and other things and did not answer 8days.

After a week they wrote that someone hacked my account and my $ 5200 dropped to $ -110.

I had a PIN on the Stars after signing up. Of course, the stars say they don't take any responsibility for hacking.

Now I see a foreign card transaction in my account. Even though, according to the rules (at least in the Czech Republic) the card must have the same name as the account. The last transaction took place on the day when Stars wrote me about $ -110 balance.

In hand history I see HU cash game against the same player:


Hand 201367135873 in Zoom na PokerStars: Hold'em Limit (3 $/6 $) - 13.06.2019 20:19:23 ET
Table 'Tau Hydrae' 2-max place no.1 is button
place 1: Elennqwe (260.73 $ in chips)
Místo 2: sir_Hubinho (57.90 $ in chips)
Elennqwe: post small blind 1 $
sir_Hubinho: post big blind 3 $
*** own card ***
sir_Hubinho [5d 2d]
Elennqwe: raise 3 $ to 6 $
sir_Hubinho: raise 3 $ to 9 $
Elennqwe: raise 3 $ to 12 $
Bets are closed
sir_Hubinho: call 3 $
*** FLOP *** [3d 2h 9c]
sir_Hubinho: bet 3 $
Elennqwe: raise 3 $ to 6 $
sir_Hubinho: raise 3 $ to 9 $
Elennqwe: raise 3 $ to 12 $
Bets are closed
sir_Hubinho: call 3 $
*** TURN *** [3d 2h 9c] [5s]
sir_Hubinho: check
Elennqwe: bet 6 $
sir_Hubinho: fold
(6 $) se vrací Elennqwe
Elennqwe takes 47.50 $ of pot
Elennqwe: muck card
*** SUMMARY ***
Total pot 48 $ | Rake 0.50 $



Can anyone advise me if anything can be done?

Thank you very much for your advice ...

(Sorry for my english)
Compromised account on PokerStars Quote
06-26-2019 , 01:40 PM
Did you had any type 2 step authentication for email?

Consider everything on your computer/all devices and all online accounts being compromised.
Consider fully formatting your pc and reinstalling windows and changing passwords everywhere and adding 2 step auth everywhere where possible.

Other then that stars is not responsible that your account was hacked. Their security dep. is slow as **** recently but it different thing.
PIN does nothing if someone get your email account as they can just request it to email.

If you can get all hand history/financial info you can try figure out if someone was chip dumping to other account (like it seem to Elennqwe in hand history) but I would guess stars would do it also but sadly recently stars security dep is super slow to do anything for anyone.

Last edited by delfins; 06-26-2019 at 01:57 PM.
Compromised account on PokerStars Quote
06-26-2019 , 11:18 PM
oh and what happens next is that Star will now go after you for the negative balance on your account and try to make you pay that also witch of course you will refuse = your account will be banned and you will never be able to play on STARS again.
Compromised account on PokerStars Quote
06-27-2019 , 08:57 AM
OP,

1) You should report this crime to the police. You had someone steal $5200 from you. That is a serious crime. You should treat it as such. You should report it both to your local police, and to the police where the crime took place (presumably, the jurisdiction where the transactions took place on the poker site servers).

2) I proposed this idea almost 18 months ago, to massively reduce the harm caused by hacking here. That proposal was a very "cheap" way to reduce the harm caused. When I proposed it, sites were slow when they replied a couple of hours later. Now, sites are merely replying a couple of weeks later. It is sad and tragic and poor that no sites (to my knowledge) have made any meaningful improvements to improve account security like this in the intervening 18 months.
Compromised account on PokerStars Quote
06-28-2019 , 05:28 PM
Quote:
Originally Posted by Josem

2) I proposed this idea almost 18 months ago, to massively reduce the harm caused by hacking here. That proposal was a very "cheap" way to reduce the harm caused. When I proposed it, sites were slow when they replied a couple of hours later. Now, sites are merely replying a couple of weeks later. It is sad and tragic and poor that no sites (to my knowledge) have made any meaningful improvements to improve account security like this in the intervening 18 months.
In the OPs case, what you propose would have made no difference. In their case (and most cases) the email account is commandeered first, then the poker account.
Compromised account on PokerStars Quote
06-30-2019 , 08:32 PM
Quote:
Originally Posted by Hubinho89
Hello everybody.

A few days ago someone changed my password to the email I got to PokerStars, then immediately the password I had to sign up for PokerStars.

I wrote to support that somebody hacked me. I wanted to block all transactions. They requested ID card and other things and did not answer 8days.

After a week they wrote that someone hacked my account and my $ 5200 dropped to $ -110.i

I had a PIN on the Stars after signing up. Of course, the stars say they don't take any responsibility for hacking.

Now I see a foreign card transaction in my account. Even though, according to the rules (at least in the Czech Republic) the card must have the same name as the account. The last transaction took place on the day when Stars wrote me about $ -110 balance.

In hand history I see HU cash game against the same player:


Hand 201367135873 in Zoom na PokerStars: Hold'em Limit (3 $/6 $) - 13.06.2019 20:19:23 ET
Table 'Tau Hydrae' 2-max place no.1 is button
place 1: Elennqwe (260.73 $ in chips)
Místo 2: sir_Hubinho (57.90 $ in chips)
Elennqwe: post small blind 1 $
sir_Hubinho: post big blind 3 $
*** own card ***
sir_Hubinho [5d 2d]
Elennqwe: raise 3 $ to 6 $
sir_Hubinho: raise 3 $ to 9 $
Elennqwe: raise 3 $ to 12 $
Bets are closed
sir_Hubinho: call 3 $
*** FLOP *** [3d 2h 9c]
sir_Hubinho: bet 3 $
Elennqwe: raise 3 $ to 6 $
sir_Hubinho: raise 3 $ to 9 $
Elennqwe: raise 3 $ to 12 $
Bets are closed
sir_Hubinho: call 3 $
*** TURN *** [3d 2h 9c] [5s]
sir_Hubinho: check
Elennqwe: bet 6 $
sir_Hubinho: fold
(6 $) se vrací Elennqwe
Elennqwe takes 47.50 $ of pot
Elennqwe: muck card
*** SUMMARY ***
Total pot 48 $ | Rake 0.50 $



Can anyone advise me if anything can be done?

Thank you very much for your advice ...

(Sorry for my english)
The first two lines of the post. Someone hacked, changed password to your email and your password to your PS account. True? Yet you later were able to log in and view a foreign transaction and view your hand history of one hand. How? Your passwords were changed were they not? If you were able to log in then you could have changed your password and pin. Please tell me more.
Compromised account on PokerStars Quote
07-01-2019 , 01:01 PM
Quote:
Originally Posted by IAMMEUR
The first two lines of the post. Someone hacked, changed password to your email and your password to your PS account. True? Yet you later were able to log in and view a foreign transaction and view your hand history of one hand. How? Your passwords were changed were they not? If you were able to log in then you could have changed your password and pin. Please tell me more.
Yes, because I sent my ID card and other things to PokerStars for verification and I could reset password and change my email back.

Yet I later sent myself hand history from PS client. This is one example hand. And in transaction history I see several deposit and consecutive cancel.
Compromised account on PokerStars Quote
07-01-2019 , 02:14 PM
do you know how you got hacked? They had to get your pin number to right to hack you? You sure its not of your friends that saw your password or codes through team viewer? It sounds very odd you can just be hacked like that without you some how leaking your info out.
Compromised account on PokerStars Quote
07-01-2019 , 03:14 PM
Quote:
Originally Posted by iburydoscocaroaches
do you know how you got hacked? They had to get your pin number to right to hack you? You sure its not of your friends that saw your password or codes through team viewer? It sounds very odd you can just be hacked like that without you some how leaking your info out.
OP clearly says his email was compromised.
When someone have your email hacked both PIN and password is pretty useless.
Compromised account on PokerStars Quote
07-01-2019 , 05:10 PM
Quote:
Originally Posted by delfins
OP clearly says his email was compromised.
When someone have your email hacked both PIN and password is pretty useless.
The solution to this is the "SMS Validation".

It really should be promoted more actively; PokerStars promised to promote it more several years ago, but I don't know what they're doing these days. Perhaps they could share how they're improving account security?
Compromised account on PokerStars Quote
07-02-2019 , 07:03 AM
Pokerstars support has not responded for a week. They didn't answer why someone could deposit with foreign card. And why they don't solve, intentionally lost money in HU cash game.
Compromised account on PokerStars Quote
08-01-2019 , 05:36 PM
...a month later...

Hello Ondřej,

Fraudulent deposits with credit cards were made during the unauthorized access and we expect these to be disputed. In such case, you will be liable and fully responsible for any chargeback we might receive.

We would like to advise you that we will not be liable for funds lost on your Stars Account. We will not be held liable for any losses as a result of insufficient security measures to ensure that your personal details remain secure. This is in accordance with the sections of our Terms of Service which state your responsibilities as an account owner.

We highly recommend that you take necessary action in protecting your computer, email, and Stars Account, along with personal data stored in your computer. This includes, but not limited to; scanning your computer to ensure no harmful software are installed and changing the password in your registered email account and Stars Account as a precautionary measure.

To reinstate your account with a new password and Stars PIN, negative balance should be settled on your account.

We will respond to any legal action brought against The Stars Group in compliance with local legal requirements.

Let us know if you will have additional questions.
Regards,

Maksim K.
Stars Security
.......

No mention about intentionally lost money in HU cash game.
Compromised account on PokerStars Quote
08-02-2019 , 02:40 AM
like i said, they want you to pay the negativ balance and since you will refuse, your account will be banned and you will never be able to play on stars again.
Compromised account on PokerStars Quote
08-02-2019 , 04:55 AM
Quote:
Originally Posted by Josem
The solution to this is the "SMS Validation".

It really should be promoted more actively; PokerStars promised to promote it more several years ago, but I don't know what they're doing these days. Perhaps they could share how they're improving account security?
They should have a username that is never mentioned in emails. Additionally to the site itself, just your affiliate might ask it.

The PIN could be something that can't be changed so easily (phone needed). Now it helps when someone has your password but won't help if he has your nick and email account.

Emails should be secure, the email server account possibly not under your name, and the less you spread your important email addresses, the better, and not storing all emails.

SMS and so on, I use them at many places, including Stars, so when someone from somewhere else tries to login, including a mere another device, it needs to be verified with a phone or so.

When it is a 2-step login, there is a separate software (not as secure as your not-smart phone). Your phone need not be a smartphone only but isn't all important.

In all cases, they should not be on the same machine one uses for logins.

The police usually has no time for crimes done from other countries and the server isn't that place.
Compromised account on PokerStars Quote
08-02-2019 , 08:57 AM
Was reading 90% gmail users don't use 2 step authentification.
Password managers to not have same passwords anywhere seem absent still for regular users.

I mean poker room can't do much if your email is hacked because you used same password in your favorite porn website as your email and your pokerstars acc and don't use 2 step auth for your email plus connect to wifi named "FreeWifiIsBest".
Stars offer 2008 tech sending you by mail RSA token for 30$ but I mean my ****ing heartstone cards and colorful guns in steam is easier to protect then most poker rooms. It pretty sad that sites where millions of dollars change hands can't have google auth or private app auth in 2019 as basic security feature.

Last edited by delfins; 08-02-2019 at 09:05 AM.
Compromised account on PokerStars Quote
08-06-2019 , 07:02 AM
last conversation:

ME:

I am fully responsible for fraudulent deposits with credit cards ? Without my name ? Without verification ? Really ? And do you know czechs regulation and rules, which required by the Ministry of Finance of the Czech Republic?

And you don't care about game history? - deliberately lost money in HU cash game? Example from history below... (are you jokeing?)

Handa č. 201367135873 v Zoom na PokerStars: Hold'em Limit (3 $/6 $) - 13.06.2019 20:19:23 ET
.
.(hand, that I put upstairs)
.
.................................................. .................................................. ....

security@starsaccount.cz:

Hello Ondřej,

As we have explained, we cannot be responsible for a lack of security measures that were put in place on your account, which contributed to allowing the unauthorized access.

We would like to take this opportunity to advise you of our Terms of Service about your responsibility as an account owner. As stated in section 10 under 'SECURITY AND YOUR ACCOUNT':

"10.3 The User agrees that he/she is solely responsible for all use of the Service under his/her Login Credentials and that he/she shall not disclose the Login Credentials to any person whatsoever nor permit another person to use the Service via his/her User account.

10.4 The User is obliged to keep his/her Login Credentials secret and confidential at all times and to take all efforts to protect their secrecy and confidentiality. Any unauthorized use of the Login Credentials shall be the sole responsibility of the User and be deemed as his/her use. Any liability therefrom shall be that of the User."

Our full Terms of Service are available at:
http://www.pokerstars.cz/en/poker/room/tos/

Regards,

Arthur
Stars Security
.................................................. .................................................. ....

ME:
Your password and PIN code is it a lack of security measures ?

I would like to take this opportunity to advise you of your CZECH Terms, too:

10.5

„If a User is using a credit or debit card, the cardholder's name on such credit or debit card MUST be the same as the name used by such User upon registration with the Sites. Where this is not the case The Stars Group reserves the right to suspend the User's account. Upon the suspension by The Stars Group of an account under the circumstances described, you should contact Support for details of our verification process. Any withdrawals from a User account that are made by bank wire or cheque will only be payable to the name used in the registration process on the Sites for opening the User account”.

Dou you know this terms ?
Is this valid terms ?
.................................................. .................................................. ............................

security@starsaccount.cz:

Dobrý den Ondřej,

Please note this section in our Terms of Service:

10.4 The User is obliged to keep his/her Login Credentials secret and confidential at all times and to take all efforts to protect their secrecy and confidentiality. Any unauthorized use of the Login Credentials shall be the sole responsibility of the User and be deemed as his/her use. Any liability therefrom shall be that of the User."

Please let us know should you have any other questions or concerns.


S pozdravem
♣Crystal♣
Bezpečnostní oddělení Stars
.................................................. .................................................. ............................

ME:

Only this selection ? You choose only part of your terms and you are ignore next part ? That's very funny.

I understand that I only have to deal with this problem with the Ministry of Finance of the Czech Republic, which has granted you a license.

.................................................. .................................................. ............................

security@starsaccount.cz:

Dobrý den Ondřej,

Jak jste uvedli, hodláte proti nám podniknout právní kroky. Váš účet Stars byl proto nyní pozastaven. Nebudete mít přístup k chatu a možnost hrát hry. Jedná se o nezbytné opatření k ochraně práv všech stran proti případným nárokům nebo sporům, které mohou vzniknout.

Při otevření Vašeho Stars účtu jste souhlasili s našimi Provozními podmínkami, konkrétně:

V Provozních podmínkách, které jste se zavázali dodržovat, když jste si založili svůj účet Stars, konkrétně v sekci 3 pod pojmem 'PRAVOMOCI', je uvedeno:

„3.1 Stars Group si ponechává pravomoc ohledně zakládání, údržby a uzavírání Uživatelských účtů na Stránkách. Rozhodnutí managementu Stars Group s ohledem na jakýkoliv aspekt týkající se Uživatelského účtu, využití Služby nebo vydání rozhodnutí je konečné a nelze se proti němu žádným způsobem odvolat. Účet založený Uživatelem bude nadále znám jako účet Stars. Uživatelský účet Stars Uživatele poskytne přístup ke všem webovým stránkám, které Vám společnost Stars Group poskytne na základě podmínek této smlouvy a bude platit pro Vaši zeměpisnou polohu. Pojmy „Uživatelský účet“ nebo „účet“ v této smlouvě vždy znamenají Váš Stars účet.“

Naše úplné Provozní podmínky naleznete zde:
http://www.pokerstars.cz /poker/room/tos/

Budeme se držet veškerých právních kroků vůči nám v souladu s místními právními předpisy. Pokud máte zájem o kontaktní údaje na naše právní oddělení, pošlete žádost našemu týmu podpory a my Vám tyto informace poskytneme.
S pozdravem

Giovanni
Bezpečnostní oddělení Stars
Compromised account on PokerStars Quote
08-06-2019 , 10:07 PM
Quote:
Originally Posted by Hubinho89
lI had a PIN on the Stars after signing up. Of course, the stars say they don't take any responsibility for hacking.

Now I see a foreign card transaction in my account. Even though, according to the rules (at least in the Czech Republic) the card must have the same name as the account. The last transaction took place on the day when Stars wrote me about $ -110 balance.


Can someone explain me how the scammers/hackers can pull this out?

When we deposit into the site the money goes back to the same option we had previously deposited.

How can the scammer/hacker cashout without being detected and how is it even possible the balance goes negative, in this case OP is saying -110
Compromised account on PokerStars Quote
08-06-2019 , 11:43 PM
Quote:
Originally Posted by hypergeometry
Can someone explain me how the scammers/hackers can pull this out?

When we deposit into the site the money goes back to the same option we had previously deposited.

How can the scammer/hacker cashout without being detected and how is it even possible the balance goes negative, in this case OP is saying -110
They deposit with card, then dispute transaction.
Compromised account on PokerStars Quote
08-07-2019 , 04:36 AM
Quote:
Originally Posted by hypergeometry
Can someone explain me how the scammers/hackers can pull this out?

When we deposit into the site the money goes back to the same option we had previously deposited.

How can the scammer/hacker cashout without being detected and how is it even possible the balance goes negative, in this case OP is saying -110
a) the alleged hacker could use a deposit method (eg, a stolen/fake credit card) where the deposit is subsequently cancelled

b) the alleged hacker would then deliberately do as the OP alleges here:

Quote:
Originally Posted by Hubinho89
last conversation:

ME:

I am fully responsible for fraudulent deposits with credit cards ? Without my name ? Without verification ? Really ? And do you know czechs regulation and rules, which required by the Ministry of Finance of the Czech Republic?

And you don't care about game history? - deliberately lost money in HU cash game? Example from history below... (are you jokeing?)

Handa č. 201367135873 v Zoom na PokerStars: Hold'em Limit (3 $/6 $) - 13.06.2019 20:19:23 ET
.
.(hand, that I put upstairs)
.
(my bolding)
Compromised account on PokerStars Quote
08-09-2019 , 12:32 PM
the money is "lost" to an other account and cash-out is then made form that account and you are left "holding the bag" and have to pay the negative balance on your account, if you ever wants to play on Stars again + your own money is lost also.

So what you should properly do now, is look into how you can use the CZECH licens rules to your favor. Is there a CZECH goverment agency you can report this "misuse" to?

My guess is that if you are extremly lucky you may get your money back but you will never be allowed to play on stars anymore if you go after them.
Compromised account on PokerStars Quote
08-11-2019 , 11:16 PM
Quote:
Originally Posted by Josem
The solution to this is the "SMS Validation".

It really should be promoted more actively; PokerStars promised to promote it more several years ago, but I don't know what they're doing these days. Perhaps they could share how they're improving account security?
I turned on this security option after reading OP and this post.

Thanks.
Compromised account on PokerStars Quote
08-14-2019 , 05:28 PM
Quote:
Originally Posted by HanSoloDK

So what you should properly do now, is look into how you can use the CZECH licens rules to your favor. Is there a CZECH goverment agency you can report this "misuse" to?

My guess is that if you are extremly lucky you may get your money back but you will never be allowed to play on stars anymore if you go after them.
I am addressing this situation with the Ministry of Finance, which licensed pokerstars for the Czech Republic. They asked screenshots from the pokerstars client and other things. I'm curious about the solution.
Compromised account on PokerStars Quote
08-16-2019 , 02:25 AM
Quote:
Originally Posted by Hubinho89
I am addressing this situation with the Ministry of Finance, which licensed pokerstars for the Czech Republic. They asked screenshots from the pokerstars client and other things. I'm curious about the solution.
Well that sounds good. Make sure you send them all the proof and it's put in the correct timeline.

Looking forward for an update.
Compromised account on PokerStars Quote

      
m