It's Thanksgiving Day so with some much needed downtime, I decided to login to my fire mage and play a little WoW (World of Warcraft). No sooner had I done so that I was greeted with the following message:
"Blizzor: Hello, Christmas is approaching. Blizzard released Christmas gifts players can receive free of charge. Please login: wwww.Blizz-Christmas.com."
Now, Blizzard does actually give free Christmas gifts to players - but it's done in-game, with all major cities sporting a huge tree and lots of presents to open. But the Blizzor message is a scam, www.Blizz-Christmas.com is a phishing site that masquerades as a Battle.net lookalike. The intent is to steal your game login credentials. The site uses all Blizzard links in its source code - except for the actual login button. This could trick some naive gamers into believing it's legit. But it's not. Logging in via Blizz-Christmas.com won't net you free gifts - but it will give the attackers your account for free.
The domain currently resolves to 210.72.225.118, an IP hosted in China.
Phishing scams can be difficult to stop. But it seems to me that Blizzard should simply ban any toon names with "Blizzard", "Blizz" or any similar derivative to reduce the likelihood of anyone falling for the scam.


Mary’s not lying one bit. Last night I had been playing for awhile and just got out of a dungeon. I saw a post that said “Blizz: Hello, Christmas is approaching. Blizzard released Christmas gifts players can receive free of charge. Please login: http://www.christmas-USbattle.com.” I had entered my info like a dummy. I mean I had just started playing only 3 weeks ago. Well they left a message saying that I will hear something back in 3 days or so. Hmmmm….that is odd….considering you would get it now…I got booted from my account 30 mins later and couldn’t log back in. Lucky BLIZZARD caught the action as odd and sent me an email asking me if I had sent the password change. I replied with an email explaining and lucky for me, they let me fix the problem. My account was locked out for 24 hours for my safety but I’m just glad I caught it as quickly as I did. If not I would have probably lost my level 50….wow talk about sick!!!
Very glad to hear that you got your account back quickly!