Original Post — Direct link

Guys I’ve got a hacker on my account right now, he’s talking to my friend and said he has 40mins until the bank pin timer expires and he’s in…it’s been 3 days since I put in a support ticket! Please help!!

External link →
about 23 hours ago - /u/JagexTwisted - Direct link

I've taken some steps to secure your account for you. You will need to take a look at the security tips article here, including the first sentence on how to recover a hijacked account. Here is a direct link for account recovery, to make it easier to locate.

I'd heavily recommend that you read through the entire article as it will assist in removing any potential e-mail forwarding rules and other dodgy social links that can help a hijacker regain control once they lose access.

On a side-note, do make sure you upgrade to a Jagex account as other users have mentioned. I'd go as far as saying that once you've done that, you should also change the authentication method from e-mail to a mobile authentication app such as Authy or Google Authenticator. That's personal preference, of course.

about 22 hours ago - /u/JagexTwisted - Direct link

Originally posted by RawGuap

Hey Jagex Twisted, i am feeling even saltier now seeing this post, as i had a hacker compromise my account on november 3rd, i sent in 5 support tickets (daily) and eventually after 9 days got a response, the worst part is i did get my account back but logging in, to see i had a bank completly wiped out, ironman 1.7b in items, and am told "nothing you guys can do" however looking at your lost items page, i see human error due to jagex staff as a reason you guys would revert this. And a 9 day response time on a 7 day maximum bank pin option is completely ridiculous... whats the point of even having a bank pin if the support team takes longer then the max allowed bank pin time???? I can provide jagex ticket # if needed

I'm not a member of player support, I just happened to browsing. From what I recall, for an account to be imported onto a Jagex account they require your login and password. If the account has an authenticator, it prompts the user for an authenticator code to continue the transfer.

If a legitimate player wanted to merge an account onto a Jagex account, they are able to disable the authenticator to continue the process by clicking a text link at the bottom of the authenticator prompt which sends an e-mail confirming that they wish to remove their authenticator. I tried this very quickly with a legacy account I own and can confirm I was prompted to check my inbox if I wanted to remove my authenticator and continue.

Unless I read incorrectly, it appears as though you gave someone permission to log into your account? It'd be fairly simple to sit on account import screen and wait for a username, password and authenticator code and merge it onto whatever account I want if that was the case.

At the end of the day, while I massively sympathize with anyone that is hijacked on any game or platform, account security is the responsibility of the player.