GameSpot may receive revenue from affiliate and advertising partnerships for sharing this content and from purchases through links.

Microsoft, Fix Your Security Problems

While not a security breach in name, Xbox Live's recent spat of security woes makes it hard to tell the difference.

146 Comments

Late last week, the ongoing Xbox Live FIFA Ultimate Team scams bubbled up in the news cycle again when a particularly compelling customer service horror story was recounted on the Hacked on Xbox Tumblr blog. In the blog, a woman referring to herself as Susan T described her struggles with Microsoft as an outside party logged into her Xbox Live account and racked up charges on her credit card--even after Microsoft said it had blocked access to the profile while an investigation was conducted.

There's much more to her story, and it's well worth reading the entire saddening, frustrating account. The problem is that her story is by no means unique among Xbox Live gamers. While 2011 was the year Sony lost the personal information of some 100 million customers with hacks to the PlayStation Network and Sony Online Entertainment databases, anecdotal evidence about which platform endured the most troublesome identity theft was weighted heavily toward the Xbox 360. For Microsoft's part, the company insists that Xbox Live security hasn't been compromised, as in the following statement issued after Susan T's blog got traction in the news cycle:

No Caption Provided
FIFA 12's Ultimate Team mode has inspired a wealth of online hooliganism.

"Microsoft can confirm that there has been no breach to the security of our Xbox LIVE service. In recent cases, some Xbox LIVE members appear to have been victims of malicious scams. Unfortunately this is something that affects many Internet based services. The online safety of Xbox LIVE members remains of the utmost importance, which is why we consistently take measures to protect Xbox LIVE against ever-changing threats. However, we are aware that a handful of customers have experienced problems getting their accounts restored once they've reported an issue. We are working directly with those customers to restore their accounts as soon as possible and are reviewing our processes to ensure a positive customer support experience."

I believe Microsoft when it says Xbox Live hasn't suffered a security breach. But that doesn't mean Xbox Live isn't suffering from a security problem. The problem is that Microsoft seems content to merely reassure people whose accounts have been compromised that the company wasn't the weak point in the security chain. That's fine from a legal liability standpoint, but it's pretty shortsighted for a company to tell victimized customers, "Don't blame me; I didn't lose your info," and carry on as if nothing happened. Instead, Microsoft should be doing a better job of taking away a crook's incentive and ability to cheat its user base.

I believe Microsoft when it says Xbox Live hasn't suffered a security breach. But that doesn't mean Xbox Live isn't suffering from a security problem.

Take the FIFA scam, for example. There are a number of variations on it, but the basics are that a scammer gets hold of an Xbox Live member's user name and password and logs into that account. If the account is already linked to a credit card, the crook stocks up on Microsoft points and uses them to buy FIFA Ultimate Team card packs. The cards from those packs are then sold online outside of Xbox Live, and once buyers have been found, the transaction is completed in-game by trading the card directly to the purchaser's gamertag.

The solution here is simple, and it is one borne out of Microsoft's hold on the Xbox experience. Because the Xbox 360 is a closed system, Microsoft ultimately has control over what happens on its console and in its games. That level of control means Microsoft can impose the rules by which publishers must play, and it can forbid such direct transfer of any paid downloadable content from one gamertag to another. An illicit secondhand market for these cards can't really exist if a would-be seller can't ensure those pilfered wares wind up in the hands of the proper buyers.

Obviously, this would be bad for business to an extent. Without the ability to trade cards directly, the Ultimate Team-playing community may not thrive in the same way. And EA would no doubt be unhappy at having its options for how to structure its business model limited. But the question is whether or not Microsoft and its third-party partners see protecting their consumers from rampant fraud to be more valuable than the incremental revenues they reap by having a system open for continued abuse. Or in more pragmatic terms, whether or not they are willing to put up with how scummy it looks to have these stories circulating online while EA executives brag to investors that, "We see people spending $500, $600, $700 on digital card packs to play Ultimate Team simulation mode."

In another, more narrowly defined instance of Xbox Live fraud, one gamer conveyed to GameSpot a tale of scammers attempting to steal the gamertags of himself and his friend. Both were members of the original Xbox Live beta, and so they had simple handles that were free of superfluous numbers, characters, or "xXX-XXx" prefixes and suffixes. They were the sort of gamertags that would have been not at all out of place if used as nicknames for American Gladiators. When his friend's account was hacked, American Gladiator 1 (we'll call him "Gemini," though that wasn't his real gamertag) messaged his friend's account (let's go with "Turbo") to see what the thief would say. Perhaps surprisingly, the squatter acknowledged what he'd done and explained that he was planning to sell the handle online. While Xbox Live users can't actually give their handle to another gamer, they can coordinate name changes. When one account uses Microsoft's gamertag name change feature, it instantly frees up the old gamertag for a second account to come in and claim it.

No Caption Provided
Gamertags can be an in-demand commodity just like FIFA Ultimate Team cards.

Although this isn't the most widespread problem, it's still one Microsoft could almost entirely eliminate by placing old gamertags in quarantine for an unspecified period after each name change. That would not only reduce the likelihood of a scammer being able to reregister an account with the desired gamertag, but it would also give the original user an opportunity to notice the name change and lodge a complaint with Microsoft before someone new begins squatting on the old gamertag.

The thing is that the Xbox Live security problem has grown to the point where it's impacting customers who haven't had a dime stolen from them. After reading through the Hacked on Xbox account, I finally decided to remove my credit card information from my Xbox Live account and use nothing but Microsoft points cards going forward. But when I logged onto my account on Xbox.com to make that change, it wouldn't let me delete my credit card, saying it was being used for an active service. Because I had paid for my Xbox Live Gold account with a credit card, the system would not allow me to remove that card until the subscription had lapsed, which is a piece of information I was only able to get after using Microsoft's online tech support chat. The tech support person was friendly enough but could not simply remove the card from the account without cancelling my Xbox Live subscription because it had been less than 30 days since it was renewed. So it was suggested that I try back in a few weeks after that window has passed and see about having the card information removed then.

When I went to remove my credit card info from my PlayStation Network account, it was a straightforward process finished in under a minute through the PlayStation 3 itself. Come on, Microsoft. When you can look to Sony as a model of how to handle a customer's sensitive personal information, it's time to take a long, hard look at how you operate and make some changes.

Got a news tip or want to contact us directly? Email news@gamespot.com

Join the conversation
There are 146 comments about this story
146 Comments  RefreshSorted By 
GameSpot has a zero tolerance policy when it comes to toxic conduct in comments. Any abusive, racist, sexist, threatening, bullying, vulgar, and otherwise objectionable behavior will result in moderation and/or account termination. Please keep your discussion civil.

Avatar image for megakick
megakick

1931

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By megakick

Sounds like An EA problem. MS should just block EA.

Upvote • 
Avatar image for Jahames1
Jahames1

31

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Jahames1

PS3 ftw.

Upvote • 
Avatar image for RAGEofSTUNTS
RAGEofSTUNTS

733

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By RAGEofSTUNTS

Is it too hard to drive or walk to the store and get a microsoft points card?

Upvote • 
Avatar image for Twin-Blade
Twin-Blade

6806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Twin-Blade

@XeonForce Touche. I probably should have done my homework before my original comment.

Upvote • 
Avatar image for XeonForce
XeonForce

702

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By XeonForce

@Twin-Blade -- The ironic part was you're unfounded accusations and questioning of the integrity of GameSpot, not you're console orientation. Your previous comment was very ironic in nature, especially given the response you received from Giancarlo. Also, Galugon is just very analytical; he means no harm, really. :P

Upvote • 
Avatar image for Twin-Blade
Twin-Blade

6806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Twin-Blade

@Gelugon_baat What's wrong with sheep? They play a big part in the economy and in improving the quality of life of people like you and me with their wool. If you were more appreciative of these amazing creatures you would have seen my immitation as a compliment.

Upvote • 
Avatar image for Twin-Blade
Twin-Blade

6806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Twin-Blade

@Gelugon_baat No need to curse. Why do they need to save the skins when "stuff" like this happens? If anything, it should be the Governments from around the world taking the blame. Poor education systems resulting in more stupid people who can't protect their passwords.

Upvote • 
Avatar image for Twin-Blade
Twin-Blade

6806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Twin-Blade

@Gelugon_baat I'm a sensitive guy that appreciates the feelings of others.

Upvote • 
Avatar image for TheRedDash
TheRedDash

2490

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By TheRedDash

@VegetaMaelstrom Uh! no lol I am not one of the dumb asses on this planet. Why don't you do me a favor and make another username with a dragon ball z character. ha

Upvote • 
Avatar image for Twin-Blade
Twin-Blade

6806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Twin-Blade

Whoa dudes, all this hate.. I love the PS3, don't thumbs-down me bro! @XeonForce - I own and love my PS3. I feel it is a much more core orientated console than the 360 and that Sony is trying the hardest to accomodate core gamers. So no, it isn't ironic. @Gelugon_baat - Wow. Strong words there, pal. Is this Brendan guy a close friend of yours or something, you seem to be jumping at everyone who goes against his opinion that you seem to eat up. Baaaa. Anyway, I didn't/don't expect him to read my comment and it was never intended to insult him, so calm your farm. The last thing I need is the thought that my comments are making some guy tear up and post hot-headed replies on a gaming website. I like your enthusiasm though. Edit: I like how people are calling for a lawsuit against Microsoft. I think Microsoft should be able to sue stupid people for defamation; getting scammed because you can't protect your passwords and accounts and blaming Microsoft isn't the way to go.

Upvote • 
Avatar image for VegetaMaelstrom
VegetaMaelstrom

1083

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By VegetaMaelstrom

@TheRedDash Then I guess you're next!

Upvote • 
Avatar image for TheRedDash
TheRedDash

2490

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By TheRedDash

Stupid people get hacked Simple :)

Upvote • 
Avatar image for m4a5
m4a5

3289

Forum Posts

0

Wiki Points

0

Followers

Reviews: 8

User Lists: 0

Edited By m4a5

Ha, it sounds like XBL has a lot of people that fall for phishing scams. Yeah, sure MS should care about it, but to care much more than they do would be in vain. This is what happens when something becomes too popular; people start to abuse and scam others. Sure things can be tweaked, but its more of a live and learn scenario (and with how big this is, you can't just change things on a whim)... I personally haven't had any problems with XBL and know no one that has had problems, so it's not as common as some people think...

Upvote • 
Avatar image for blackwingzero
blackwingzero

1683

Forum Posts

0

Wiki Points

0

Followers

Reviews: 117

User Lists: 0

Edited By blackwingzero

Holy cow. I hate to say but I think Brendan is right. Sounds to me like Microsoft has a serious issue with its Xbox Live security system. So much so that it could potentialy warrent a third party to come in and investigate just wtf is going on. Security issues like these are never nice no matter which side of the console wars your on.

Upvote • 
Avatar image for XeonForce
XeonForce

702

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By XeonForce

@cipo89 -- It's the effort that counts, at least in any respectable person's book. Also, I'm glad you have a sense of humor, you're edit made me laugh and thumbs it up. :P

Upvote • 
Avatar image for MJ12-Conspiracy
MJ12-Conspiracy

2984

Forum Posts

0

Wiki Points

0

Followers

Reviews: 12

User Lists: 1

Edited By MJ12-Conspiracy

None of this would ever affect me, I never use factual info for my bio, I don't use a credit card even in real life and I'm not stupid enough to fall for those ads the appear on XBOX Live. If someone were to contact me with one of these scams I wouldn't bite and I've had it happen a couple times and each time they were for games I don't play or own...... Interesting read though and eye opening.....

Upvote • 
Avatar image for jocool1
jocool1

212

Forum Posts

0

Wiki Points

0

Followers

Reviews: 5

User Lists: 0

Edited By jocool1

I'm very sure the issue is more rampart then they are letting on, it's not just a phishing scam, sure some of it may be but after reporting my points disappearing for Gold Membership purchases, my account was also locked for investigation. The shocker to me was when the customer service rep said it would take 3 - 4 weeks to resolve... He could hear the shock in my voice and proceeded to say that timeframe is an improvement from the month or more it has taken in the past. So I'm thinking their investigation group is overwhelmed right now. And the rep wasn't very knowledgeable on how the gamer tag works because he said I'd still get my achievements and be able to play games, but every game I have progressed in has save files associated with my gamertag so u less I want to start over on Skyrim, Forza, Battlefield, etc. then I can't really do anything, even Netflix.

Upvote • 
Avatar image for cipo89
cipo89

539

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By cipo89

@Gelugon_baat Well even if I were to say something along the lines of "I love PS3 and Xbox, but PC is my favorite" I would still end up with some form of critique or hate on this website. So what's the point of changing my phrase around to be nicer to people when they're gonna be d*cks to my views on gaming anyways?

Upvote • 
Avatar image for toddx77
toddx77

3395

Forum Posts

0

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

Edited By toddx77

Good now that every major console and steam have been hacked no one can say their service is better than another.

Upvote • 
Avatar image for cipo89
cipo89

539

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By cipo89

@XeonForce Look back at it, I fixed it. And I wasn't purposely trolling, otherwise I would do something more along the line of PC>>>>>>>>>>>>>>>>>>>>>>>>PS3=Xbox. Actually now that I think of it maybe I should of worded it.

Upvote • 
Avatar image for XeonForce
XeonForce

702

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By XeonForce

@cipo89 -- "PC>PS3=XBOX" - I wouldn't call that an "expression of love"; it's more akin to trolling, even spam. I think Gelugon_baat has every right to critique such a remark. Also, it should be irrelevant, but I thought you should know I am saying this as a heavy PC gamer.

Upvote • 
Avatar image for cipo89
cipo89

539

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By cipo89

@SergioMX I never mentioned anything about hacking...

Upvote • 
Avatar image for DemonGuy23
DemonGuy23

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By DemonGuy23

Now time to sue microsoft for these problems, like what happened to sony and the PS3.

Upvote • 
Avatar image for SergioMX
SergioMX

123

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By SergioMX

@cipo89 PC gets hacked more than Xbox 360 and PS3, so that wouldn't really be a good argument lol. PC is better on a technical level though, but that's not even a question. Consoles are just easier to attain.

Upvote • 
Avatar image for cipo89
cipo89

539

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By cipo89

@Gelugon_baat Unless a die-hard fan of 360 or PS3 comes along, I don't think my opinion of consoles will insult or offend anyone. Its too bad these days you can't even express your love for something without being critiqued.

Upvote • 
Avatar image for JohnIndigo
JohnIndigo

40

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By JohnIndigo

I used to say that one console was better than the other, but then I realized they all have their pros and cons. No, I wasn't going to say I took an arrow to the knee. My knee is quite healthy.

Upvote • 
Avatar image for XeonForce
XeonForce

702

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By XeonForce

@Twin-Blade -- "your bias is showing." How ironic.

Upvote • 
Avatar image for rocksteam
rocksteam

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By rocksteam

The problem here is to use common sense its like common phishing scam or spam , people dont use common sense, and use those services compromising their own data, in other words is like you give the thief the key of your house and blame the police about that. PSN issue was different, it was a real hack into their servers. and about the bans this article wants dont depend on MS only is an EA Sports Game

Upvote • 
Avatar image for cipo89
cipo89

539

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By cipo89

@Gelugon_baat I love all consoles, but I just personally perfer the PC. Don't make me look like a criminal for it.

Upvote • 
Avatar image for cipo89
cipo89

539

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Edited By cipo89

PC>PS3=XBOX with love.

Upvote • 
Avatar image for deadruler08
deadruler08

838

Forum Posts

0

Wiki Points

0

Followers

Reviews: 8

User Lists: 0

Edited By deadruler08

Can't say I know what they're talking about

Upvote • 
Avatar image for MrFacepunch
MrFacepunch

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By MrFacepunch

The real crime here is that people are still playing Fifa

Upvote • 
Avatar image for AwsomeZ101
AwsomeZ101

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By AwsomeZ101

Makes no sense in some points but seriously i dont remember sony being bashed this much for a much worse thing! And i remember hackers using the internet to get info. so its each induviduals own fault for getting hacked as it has no MS to look after him/her with thier info. however MS should put more care involved into its faithful customers and try to do something about it. and honestly i already see SONY guys coming in to write...see that window to your left, that right there is sunlight and grass, you should try it sometime instead of searching the web to thro complaints at componies.

Upvote • 
Avatar image for valdarez
valdarez

2174

Forum Posts

0

Wiki Points

0

Followers

Reviews: 14

User Lists: 0

Edited By valdarez

@Gelugon_baat Yup. Microsoft has never put it's customers first. The XBox 360 failures showed that, the horrible dashboard updates showed it, and the lack of help/support on stolen accounts continues the trend.

Upvote • 
Avatar image for ncc74656
ncc74656

37

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 0

Edited By ncc74656

I'm glad I'm not Xbox live anymore playstation network is better and cheaper

Upvote • 
Avatar image for MikeLirette
MikeLirette

4697

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 0

Edited By MikeLirette

@Twin-Blade There was tons of them! Every second day there was an article about Sony and PSN being hacked. There is no BIAS here AT ALL. Your crazy.

Upvote • 
Avatar image for Giancarlo
Giancarlo

859

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By Giancarlo

@Twin-Blade You mean PSN articles like this one http://www.gamespot.com/features/reality-check-psn-welcome-back-program-thanks-but-no-thanks-6314381/?tag=result%3Btitle%3B3

Upvote • 
Avatar image for Vari3ty
Vari3ty

11111

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Vari3ty

@Twin-Blade Bias? Really? When the PSN hack was occurring articles about it were plastered all over the site. Now we have one article criticizing XBL (and XBL is far from being a perfect service), and you call out bias? Give me a break.

Upvote • 
Avatar image for K0rRupTi0n
K0rRupTi0n

171

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By K0rRupTi0n

microsoft cant fix their security problems hasnt windows taught us that?

Upvote • 
Avatar image for SpiderLuke
SpiderLuke

719

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By SpiderLuke

This is exactly why I don't add my credit card to any of my game systems. I'm fine using points.

Upvote • 
Avatar image for Twin-Blade
Twin-Blade

6806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Twin-Blade

Wow.. Just.. Wow.. "Microsoft, Fix Your Security Problems". Where was the scathing articles here at Gamespot when PSN was straight up hacked. Yet here we are trying to use scams to say Microsoft has security issues. Sure, Microsoft make every action involving removing payment information a real pain, but that doesn't warrant an article such as this. Come on Gamespot, your bias is showing.

Upvote • 
Avatar image for gc88
gc88

713

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By gc88

PS3 > XBOX 360

Upvote • 
Avatar image for ahpuck
ahpuck

3641

Forum Posts

0

Wiki Points

0

Followers

Reviews: 100

User Lists: 0

Edited By ahpuck

xbox lemmings to the rescue!!

Upvote • 
Avatar image for Doolz2024
Doolz2024

9623

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

Edited By Doolz2024

Yeah, blame Microsoft for people using the same email/password combo on both EA.com and their XBL account. Totally Microsoft's fault. :|

Upvote • 
Avatar image for garyperson
garyperson

43

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By garyperson

I just read the same thing on IGN stop copying Gamespot & if you give out your own information its not hacking, 2012 come on people!

Upvote • 
Avatar image for mothboy
mothboy

186

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By mothboy

haters gonna hate.

Upvote •