Josh Wrote:Phishing, yeah that could be same with an exploit. But brute forcing, I don't think so, I am sure that Blizzard would have a system in place to tell them when someone was trying to check their password a few hundred times in a minute.
Brute forcing has yet to happen. Keyloggers actually happen quite often in regards to WoW mods.
Phishing is the most likely culprit. There are several emails going around right now claiming the be Blizzard offering people Beta invites for Cataclysm or account maintenance or something, and link you to a fake site to log in to activate. They'll have a name like "worldofvarcraft.com" or similar. Also, there's an armory scam going on right now where people have managed to get a bad google link into the google search that if you go google armory (instead of using the standard URL that most bookmark or memorize), let's say by mistyping the URL and then it loads up the list of "Did you mean?" and you just click the first one and go into it, thinking its the real thing. It looks the same, the URL seems close enough, and you just go to log into your account on it to see your armory. In reality, you just sent some dude your name and password and never knew it.
EDIT: Just logged my account, that I haven't been updating on mods for quite a few patches. Everything is as it should be, and I don't have an authenticator.

