Indie game storeFree gamesFun gamesHorror games
Game developmentAssetsComics
SalesBundles
Jobs
Tags

The itch.io site is used in latest Discord Phishing

A topic by aliofonzy created Jul 30, 2021 Views: 2,090 Replies: 6
Viewing posts 1 to 4
(2 edits)

Helping someone spread the word of how they had found themselves in phishing incident and the phisher used this site to distribute(screenshot shows of where user got phished and it started sending out said link to people. The phisher deleted their message but you can clearly see in convo that person tried to get the other to play game and it worked)

This is an insult to game developers and can only hurt those wanting to help playtest now that this occurred and the fact that Discord has yet to fix the phishing rampage is ridiculous. LINK TO THE DANGEROUS IO PAGE IS IN SCREENSHOT ON TWITTER POST! 

Link on Twitter: https://twitter.com/Samsterpiece2/status/1421172175453790210?s=20

Link on Reddit(with more detail and backstory provided):
https://www.reddit.com/r/discordapp/comments/ouo5wx/what_the_lack_of_security_in_discord_is_causing/


Other instances of Discord Phishing and hacking-- Popular game called Tower Unite got hacked:

https://twitter.com/search?q=tower%20unite%20discord%20hacked&src=typed_query

To help give more context: The person has always been careful and regularly visited this site to help friends who are game developers test stuff. Since link was itch.io and their familiarity with their site being nothing but a positive experience, they decided to help playtest like they usually do.

Now they lost one grand in nitro gifting due to the phish and they no longer are helping anyone with playtesting. And it hurts more that the dms and such came from a friend of theirs that even they aren't sure anymore if its their friend now or compromised, hence they blocked said user. Something needs to be done.

the game and the user are gone from itch.io so i couldn't run a test on any.run if you have the file you can upload it and test it for me. It will give screenshots and information of where it will it is going in the internet. Other than that this doesn't seem to be a problem with  itch.io but discord. Even if wasn't uploaded to itch.io the virus software should still work the same in another uploading site like Drive or Dropbox.

The person got hacked, you believed in the hacked person, you let Discord keep your paypal information, Discord fault for doing nothing or not fixing this fast and Paypal fault for not stopping the $1000 payment that happen within  minutes. The only way this scam works is if the criminal got hold of Discord users who download the Discord software and the user has the payment saved on Discord. They make Discord software do something on payment section of Discord code and Paypal believes it is you.

This is not itch.io fault it's Discord and Paypal, as well as you for  having a saved billing  option.

Admin (2 edits) (+6)

We are aware of this scammer creating pages, every page they have created has been suspended and taken down as soon as it has been detected. Additionally we’re updating and modifying internal rules to catch stuff like this before it happens. Sadly I can’t reveal more than that since it’s likely the scammer is reading this thread.

As a reminder, itch.io is a open publishing platform. Although we have many checks and systems in place to detect abuse and prevent abuse, no automated system is going to be 100% perfect. Just like any place where you would download software off the internet, approach it with a little (or a lot of) suspicion. If it looks fishy then don’t download it, and report it. You can find report links on the bottom of each page.

Thanks

would you be able to give official statement to help the person bringing awareness about said scam and how they’ve been phished? Cause they could lose discord and $1,000 as a result 

which isn’t fair at all . Of course they were cautious generally speaking but never expected a site they used for long time in development,

To be what blindsided them. 

also: there’s a discord user Id grabbed and such of said person who sent the phished site if that helps.