Compromised Account Vulnerability

After new information has been discovered about enforcement bans, I decided to make a new post.

Not only does it have information and feedback about enforcement bans, but it also shows my history with my account and tickets.

You can check out my previous post here:
Roblox Improving Their Support (General, Enforcement Bans)


Somebody messaged me on Discord, claiming we were both linked to the same account. We were both terminated on the same day, reinstated our accounts, then terminated again on the same day, for the same reason, and with the same first two characters of the username.

What did we find?
Here are the similarities between the other user who contacted me and me:

  • Accounts compromised in June 2022
  • Compromised by the same person, but a different Roblox account
  • Accounts reinstated with original email, limiteds, and unauthorized charges
  • Unauthorized charges were noted so they would not be disputed

We went through every terminated mutual friend/following of the accounts used to trade, and that is how we found out the person linked.

Why is this an issue?
Roblox does not take note of this association as a history of the account being compromised from that time period. Due to this, accounts, along with the associated alts, might be stacked on the compromised user’s account even if it was reinstated. The problem doesn’t just become “solved” through appealing; it requires the root issue to be separated from both people.

Why not send an MIDR?
As stated before, the root issue will not be solved. Even if you send one, you are spending money to eventually be terminated again because the root of the issue is not resolved, which I could be wrong about here. I would be spending money on certified mail every time my account is terminated because of this, since Roblox support instantly rejects my tickets.

As Roblox continues to ignore my requests about this issue, at least it feels like it, I continue to worry about similar instances like these happening to others, and my appeal window has already closed about a week ago.

So, if your account was compromised in the past, you would be vulnerable to having your account enforcement banned, even if it happened years ago.

Compromised Account Proof For sammikyu

This occurs on June 8, 2022.

[1] Screenshot 1: User DMs me “sammikyu” that I have supposedly taken somebody’s account. This is a common scam where fraudulent messages are used to worry the user.

[2] The user will be instructed to join a Discord server that has the vanity URL of the real server, but it is entirely fake. Then, the user will end up falling for this, and these people will eventually have access to your account. I am unsure whether this was through a link or not, since it was some time ago.

[3] Screenshot 2: My limiteds are taken from me, and I am signed out of the account. This is an old screenshot from a ticket.

Kumalaluh (3603278327) is the user who stole my limiteds, which kept getting traded off by their accounts, which were all later terminated.

[4] Screenshot 3: Proof that the limiteds were also taken through a Rolimons graph.

Here is also the UAID of the Vans x The North Face item from Screenshot 2.
https://www.rolimons.com/uaid/150909334529

[5] Screenshot 4: The UAID of Vans x The North Face users.

It is very clear that the users speedraceronaktm (3597809196 ) → Kumalalauh have traded before the incident. This is very important for later.

[6] Screenshot 5: My limiteds were restored to my account.

[7] Screenshot 6: I went through the entire process of changing my birthdate back because they changed it to 2015.

[8] Screenshot 7 & 8: I told them there was a fraudulent purchase of Roblox premium on my account, which they later noted that it was during the account being compromised.


Compromised Account Proof For acksuh

This occurs on June 11(?) 2022.

[1] Screenshot 1: This is the same scam seen from sammikyu’s account being compromised, which is from the same person as seen in both screenshots that are occurring around the same time.

[2] Screenshot 2: This is proof of a group chat that was created by that person, where eventually, they’ll have access to acksuh’s account.

[3] Screenshot 3: speedraceronaktm takes acksuh’s limiteds.

[4] Screenshot 4: acksuh gets his limiteds restored to his account.

Compromised Account Proof Kumalaluh & speedraceronaktm

This is proof that both Kumalaluh & speedraceronaktm are connected, which is directly shown in both the compromised account proof for both sammikyu and acksuh.

[1] Screenshot 1: Both users are trading limited items that were later used for this trade before both accounts were compromised.

The UAID is: https://www.rolimons.com/uaid/2389617836

You can check all users terminated through June 2022 trades with:
sammikyu (victim): sammikyu | Roblox Player Profile - Rolimon's
acksuh (victim): acksuh | Roblox Player Profile - Rolimon's
speedraceronaktm (hacker): speedraceronaktm | Roblox Player Profile - Rolimon's
Kumalaluh (hacker): Kumalaluh | Roblox Player Profile - Rolimon's

With these proofs, we will now show both accounts being terminated at the same time.

Account Termination Proof For acksuh & sammikyu

[1] Screenshot 1: sammikyu gets terminated in October of 2025, despite the date stating September.

[2] Screeenshot 2: acksuh gets terminated in October of 2025, despite the date stating September.

[3] Screenshot 3: sammikyu gets her account reinstated.

[4] Screenshot 4: acksuh gets his account reinstated.

[5] Screenshot 5: sammikyu gets her account terminated again in March 2026.

[6] Screenshot 6: acksuh gets his account terminated again in March 2026.

What exactly would be a rightful solution?
Do I just send an MIDR after each termination (after contacting support, of course)?
Do I wait for the root cause of the issue to be fixed?

Relevant Posts:
Email Not Valid For Account Termination Appeal
Concern: Impact of Account Compromise On Enforcement Actions
Boyfriend Still Linked To Hacker’s Account After Account Being Compromised

26 Likes

Bumping this, it is an issue that needs investigation because even after a successful appeal, it will happen again until the root of the cause is resolved.

4 Likes

When you get a successful appeal and then get rebanned, is the linked account the same user or a different one? If it’s different that’s a “stack ban” where there’s multiple accounts with severe violations linked to yours.

2 Likes

The initial termination in October of 2025 did not include any indication of who the linked account belonged to. It wasn’t until after, I believe in February, that they changed it to include the first two characters of the username. I would be unable to confirm, but the accounts we saw were last online, which are all terminated, ranging from 2022 to 2024. The only account that did not have a confirmed “Last Online” date was the one currently connected.

The only people who can really confirm this would be a staff member if they investigate it. We already have a list of usernames that comes from my and the other user’s accounts that were used to trade the limiteds off during the accounts being compromised. Those usernames and the incident itself made it feel more than just a coincidence.

Even after being unbanned, it wouldn’t make much sense for a user to be terminated again for the same account that was already confirmed not to be linked. This is Roblox, and anything could happen, so we shall wait and see.

4 Likes

I added the reports to my original post. There is still nothing happening so far.

2 Likes

it wouldn’t make much sense for a user to be terminated again for the same account that was already confirmed not to be linked

Being unbanned by a human moderator makes it so that’s a possibility, they don’t remove the flag.

2 Likes

Would that be true if it happened for one user or would it have to be both?

2 Likes

UPDATE: I added screenshots of the accounts being compromised and some more evidence through there. The only thing I am not adding are ticket numbers, since those can be sent privately.

2 Likes

I just checked the screenshots and that’s really odd, it might not be the case. I’m guessing it has to be a different account with a similar username to the one that originally banned you in October of 2025.

2 Likes

Thank you for the reply, it really is an odd situation overall. I am still hoping that a staff member will investigate this because as said before, it is much more than a strange coincidence.

EDIT: I also changed some language to “maybe” than something more definitive since only a staff member can truly be certain.

3 Likes

Bumping this, is there any way this could be investigated, please?

Accounts should not be facing penalties after post-recovery from compromises that happened almost 4 years ago. I would hate to see others in the same position as myself and Axa.

3 Likes

This is the most INFURIATING thing ever. I am so frustrated, upset, and stressed out more than ever. What was the entire point of this ticket? What was the point of it? I can’t even stay calm because of this, because it is all false hope at this point.

I have sent EVERYTHING from this thread to them to prove there is a link between compromised accounts and enforcement bans. Would you think I would be unterminated right? Wrong.

What does it take for Roblox to see this and see that users being simutaneously being terminated is an issue? How is anybody meant to contact Roblox Support when the most engaging conversations are with inanimate objects?

Screenshots:




5 Likes

For the sake of documentation, which I wish I had included in my initial post, I decided to add some inconsistencies here:

Email Not Verified

I am told my email is not verified, even though it is what I use for DevEx and previous appeals.

Appeal Window Closed Prematurely

I was told my appeal window was already closed, even though I had days left.

This is the termination notice:

Poor Redirection Follow-Up

This is a single ticket where I am told to recreate an appeal ticket, even though it was correctly filled out.


Here is my reply to their message:
image


3 Likes

Just going to add on to this.

I sent an appeals ticket on April 15, 2026, which included me mentioning my Devforum post for them to look at, not that it was moderated.

Here is the response:

I replied immediately right after on April 20, 2026. It wasn’t until today I received a reply.

The fact that I have even received this message 26 days after my initial reply is ridiculous, and just keep in mind the appeal window is 30 days.

3 Likes

UPDATE:

SURELY I GET UNBANNED RIGHT?

3 Likes

Oh, you still have the letter you wrote to get this? Could you please share all the letters that ultimately led you to this response, as I haven’t received a single similar letter in nearly 200 appeals for the same type of ban as yours!

I don’t have the text that I sent the ticket with, but they thought my Devforum post was moderated because of mentioning it.

Email Exchange:

After 26 days they replied saying this:

I said this:

image

They said this:

I said this:

They said this:

I said this:

3 Likes

Hello,

You managed to recover your account. I’m having trouble with mine because of AI moderation, and I’m already tired of dealing with support.

I did not manage to recover my account because I am still terminated. I am still in the same boat as everybody else.

1 Like

Did you send the physical midr to Roblox headquarters yet? How long has the account been terminated?