[Help] Someone is using my account

It sounds like someone else has access to your account, either by somehow obtaining a copy of your data048.bin, or by being able to access your google/icloud account and restoring a backup of the app. I'm ruling out physical access to your phone, as you mentioned that this happened while you were actually playing the game and nobody has touched your phone. Here's how to fix both situations:

  1. First, you're going to need to figure out a way to detect if they have access to your google/icloud account. I believe google has a login history that you can use to see if anyone else signed into your account, whereas I think you can contact Apple to check if anyone else accessed your icloud account. Either way, you're going to want to change the password and security question immediately for whichever service you use, along with implementing any additional two-step verification options that you can (such as google's two-step authentication)

  2. If they have a copy of your data048.bin, then they have the login information for your PAD account directly and the only way to stop them is to issue a device transfer code and move your account. You don't have to actually switch devices to do this; you can simply issue a device transfer code, write it down, delete/reinstall your PAD app, and then import the data into the new pad installation. This still counts as transferring it over, which creates a new data048.bin and makes any previous copies obsolete. Make sure you do this after ensuring your google/icloud account is secure.

Also, try to figure out how this happened; if your google/icloud service was compromised, you'll want to figure out what security issue caused it. If they weren't touched at all and you think it was the data048.bin, then you have a significant issue on your hands because you need to figure out how anyone managed to get access to this. Either someone has remote access to your device or you uploaded this and gave it away (watch out for any service/website online that requests your data048.bin). If it was a website or service that compromised your account, make sure to warn the community to ensure that other people are aware of it.

Lastly, make sure that whatever you do, you keep a clear record of what you did on your pad account along with your secret ID and any receipts of IAP transactions. Best-case scenario, the other user is non-malicious and either doesn't care about PAD or won't bother once you reset your info. Worst-case scenario, the other user is malicious and will attempt to initiate a data restoration through gungho while pretending to be you in order to take over your account. Seeing as they didn't device transfer the account away the moment they got access to it, I'm assuming it's the former but you always want to cover every possible base when dealing with a hacked account.

/r/PuzzleAndDragons Thread