<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Suspicion of hijacked accounts]]></title><description><![CDATA[<h1>Suspicion of hijacked accounts</h1>
<p dir="auto">Our <a href="https://faforever.com/rules" rel="nofollow ugc">rules (see section 4: account management)</a> prohibit the sharing of accounts. Our moderators have recently received an unusually high number of appeals from players claiming they never shared their account. However, our data indicates that these accounts were accessed by another party. We suspect that their credentials may have been exposed and one or more malicious actors may haven taken advantage of that. Unfortunately, such unintentionally shared accounts are often abused to disrupt the community. For example, by crashing or invalidating in-game lobbies.</p>
<p dir="auto">We strongly encourage everyone to never share account credentials and to always use a unique password for each service. Especially when you can not (or did not) setup 2FA. If you are currently using the same password for FAForever and another service or fork of FAForever then please take a moment to update your password:</p>
<ul>
<li>
<ol>
<li>Navigate to <a href="https://www.faforever.com" rel="nofollow ugc">https://www.faforever.com</a></li>
</ol>
</li>
<li>
<ol start="2">
<li>Login to your account.</li>
</ol>
</li>
<li>
<ol start="3">
<li>Navigate to <a href="https://www.faforever.com/account/changePassword" rel="nofollow ugc">https://www.faforever.com/account/changePassword</a></li>
</ol>
</li>
<li>
<ol start="4">
<li>Fill in the form to update your password.</li>
</ol>
</li>
</ul>
<p dir="auto">You are responsible for what happens with your account. By taking this step you help protect your account from being compromised through credentials leaked by other services. This happens more often then it should. To get a sense of how often this happens, you can review whether the email address you use for FAForever has been exposed in known data breaches via <a href="https://haveibeenpwned.com/" rel="nofollow ugc">Have I Been Pwned</a>.</p>
<p dir="auto">As a personal example: one of my old email addresses is part of up to 10 data breaches. Out of those 10, 4 involved a breached password that was stored in plain text. With this type of data breach it becomes very simple to hijack an account when the same password is used across different services.</p>
<p dir="auto">With kind regards,</p>
<p dir="auto">Jip<br />
President of the FAForever association</p>
]]></description><link>https://forum.faforever.com/topic/9485/suspicion-of-hijacked-accounts</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 12:42:06 GMT</lastBuildDate><atom:link href="https://forum.faforever.com/topic/9485.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 10 Sep 2025 18:05:43 GMT</pubDate><ttl>60</ttl></channel></rss>