Security
By opsec
August 26, 2026
Protecting your account from theft & phishing
Most “hacked” gaming accounts were not hacked at all – the owner was tricked into handing over access. Knowing the trick is the best defence.
How phishing works
- Fake login pages. A link (“free cape”, “vote for our server”, “your account will be deleted”) leads to a page that looks exactly like a real login. Whatever you type goes straight to the attacker.
- Fake giveaways and staff. Someone messages you as “staff” or a “giveaway bot” and asks you to log in, scan a QR code, or authorise an app. Real staff never ask for your password or a login QR code.
- Malicious OAuth / QR logins. Scanning a stranger's login QR or approving an app can hand them your session without a password.
Protect yourself
- Turn on two-factor authentication (2FA) everywhere – Microsoft account, email, Discord.
- Check the address bar before typing a password. If the domain is not exactly right, leave.
- No real service, server or staff member will ever ask for your password or a login code.
- Use a password manager – it refuses to autofill on a look-alike domain, which quietly catches most phishing.