I got my ironman recovered by hackers and lost 2b worth of items.

I have a post about this on the other OSRS reddit that is more informed for those who are curious with the actual problem, I'll copy paste it here though:


Jagex has probably one of the worst recovery systems in terms of account security out of any popular game.

When recovering an account through the recovery form, Jagex asks for our "1st ever recovery question answers". But the majority of us set these when we were kids (so they are most likely not very secure).

If somebody went inactive from playing runescape for a few months & they don't have recovery questions set, you can go on a VPN near their geolocation, know some basic information about them (through social engineering) & have a high chance to recover their account.


The questions I want answered:

  • Why can't we set recovery questions anymore? What is wrong with having an extra layer of account security to protect my account?

  • Why can't I change my 10 year old login name to an email username? If my login name wasn't known by anybody but myself then how can I possibly get hacked?

  • If somebody recovers my account from a fault on your end (you accept their recovery request) then am I entitled to a refund? You're the ones who messed up not me so why should I suffer?

Bring back recovery questions & give us the chance to change our login names after a certain year threshold.

I don't like the idea that somebody can recover my account based off Geolocation, Previous Passwords (easy to obtain if previously hacked) and recovery questions I set when I was 10 years old (that obviously contain easy to obtain personal information).

If you get hacked just once by a virus then you are stuck in an infinite loop where your account can be recovered at any given time. It's bullshit & jagex need to stop ignoring it and give us more security options

/r/2007scape Thread