Reports of a “Security Alert” Phishing Scam

I don’t think it makes sense for them to be targeting random Robloxians.

I also saw this on a seperate related article.

It would make the most sense for them to be targeting developers.

2 Likes

I’ve created an email just for Roblox, and have never used it in any other website, and I got one of the scam emails.
There must have been a databreach on Roblox’s end that hasn’t been disclosed.

5 Likes

My friend who has never attended RDC received the phishing email. It’s not only targeting the RDC data breach emails, there must be something else too.

We might get some scam emails from this domains soon maybe

2 Likes

My friend had the same issue around 2-3 months ago; not only you. Frustrating that Roblox isn’t open about stuff like that.

to check if you got a fake roblox email, you need to check the domain of the email, if it’s

no-reply@roblox.com then it is a official email by roblox. But if it’s like no-reply-en@roblox.com then it’s a fake email, which roblox did not sended. I recommend also everyone, to install an anti virus, in case that you accidentally downloaded a virus through the fake email link. Change your password, email address and enable 2 step authentication so the hackers can’t go into your account and change stuff.

also, Roblox should not removed the PIN feature, as it was very useful, you remove it then you still alert us with this stuff. It’s better if you guys added the PIN feature back.

1 Like

Aslong it says that it got verified for roblox.com then it should be good:
image

Can confirm, I just received this email today, though I have no idea what that account is. It certainly made me panic for a second before realizing it was sent from a non-Roblox email.

Edit to add: I’ve never been to RDC, I’m not sure where they got my email, but it’s not the RDC breach.

2 Likes

I have got another one from inforoblox@startmail.com.

Edit: link from that mail is already flagged on Google and I reported it to the Polish CERT.

I feel really bad for people who used this website, this year, many Roblox Accounts got hacked, many poeople still get scammed, as today, many Devices from United States,Russia and others hacks many Roblox Accounts by using a Cookie Method, this year, i lost my Roblox Account ( Fortunately i got it back ) i am very sad for the people who used the website again.

Also I reported that mail, directly to the mail provider.

Just as I suspected, apparently there’s a new leak/dump. 900,000+ users affected. Here’s a news article about it: https://cybernews.com/security/massive-roblox-account-leak-hackers/ It doesn’t show up on haveibeenpwned yet but I’m sure it will soon.

Hopefully a statement by Roblox is put out soon too! Enable 2FA folks!

3 Likes

Any update on the 900k+ account leaks?

image

image

2 Likes

I have enabled 2FA on all my accounts, stay safe!

1 Like

I got one from a different startmail email. I’ll be reporting that one to them as well.

2 Likes

I am getting these emails as well and have never participated in RDC. I concur with those who said Roblox has experienced some sort of data breach they have not commented on yet. It would be nice to get an update if what @TheReal4Cedar123 has posted is true

2 Likes

Is this situation with fake security alerts related to an ongoing bug where people’s emails are being disconnected from their accounts when trying to reset their passwords when given a security notification?

issue with security notification feature email removal and account lockout

my roblox account’s email address is glitched out