Lucent Works

An independent reference on desktop naval war games, published for readers in Australia.

Accounts, access and recovery

Creating a game account, and keeping control of it

An account created in ninety seconds can take weeks to recover. The difference is almost entirely made by three decisions taken at registration, before there is anything in the account worth stealing.

Quick answer

Use a unique password from a password manager, switch on multi-factor authentication during registration rather than later, complete the activation email, and keep the registration address reachable for as long as you keep the account. Report account theft to Scamwatch and, where a crime is involved, through the reporting service run by the Australian Cyber Security Centre.

What registration actually involves

For an online naval title, registration typically asks for an email address, a password, a display name and an acknowledgement of the account terms. The account is then activated by following a link sent to that address. Until activation completes, the account often exists in a partial state: it may log in, but recovery options and some services can be unavailable. The advertising programme behind our links describes the relevant action for World of Warships as registration, download, and creating and activating an account — activation is part of it, not an optional extra.

A launcher usually arrives with the client. It authenticates, patches and starts the game, and it stores a session so the password is not typed each time. That stored session is convenient and it is also the thing a person sitting at your unlocked computer inherits, which is why the physical machine is part of account security rather than separate from it.

The display name deserves a moment of thought, because it is public and frequently permanent. Using an identifiable name, a name reused on other services, or anything derived from a real name gives strangers a thread to pull. A name unconnected to your other accounts costs nothing and closes that off.

Setting one up properly

  1. Choose the email address deliberately. An address you will still control in five years, protected by its own strong password and its own second factor. If the email falls, the game account follows.
  2. Generate the password rather than inventing one. A password manager produces a long random string and remembers it. Reuse is the single most exploited weakness in game accounts, because credentials exposed in an unrelated breach get tried everywhere.
  3. Turn on multi-factor authentication in the same sitting. Registration is the moment you are already in the settings; later is a moment that often does not arrive.
  4. Complete the activation email immediately. Then keep that email, because it records the date the account was created, which is useful evidence in a recovery dispute.
  5. Record the account details somewhere durable. The email used, the display name, the creation date and the region. A recovery form asks for exactly these.
  6. Review the launcher's settings. Whether it starts with the computer, whether it stores a payment method, and whether it stays signed in on a shared machine.

Passwords and second factors

A second factor means a code or a prompt in addition to the password, so a stolen password alone is not enough. Where a game offers a choice, an authenticator application on a phone is generally preferred to a code sent by SMS, because SMS can be intercepted through number porting. The Australian Cyber Security Centre publishes plain guidance on passphrases and multi-factor authentication for individuals, and it is the reference this site points to rather than restating rules of thumb.

Recovery codes are issued when a second factor is set up, and they are the part most often lost. Print them or store them in the password manager, and treat them as equal in value to the password itself. An account with a second factor and no recovery codes can be harder to recover than one with neither, because the support process has more to verify and you have less to show.

Preparing for recovery before you need it

Recovery processes ask you to prove a connection to the account that a stranger could not fake. Preparation means keeping the answers available.

What a recovery process typically asks for, and where to keep it
Asked forWhy it is askedWhere to keep it
Original registration email addressTies the request to the account's creationPassword manager note
Approximate creation dateA detail an attacker rarely hasThe activation email, kept
Purchase receiptsStrong evidence of ownershipA folder in your email, plus a local copy
Previous display namesShows continuity of usePassword manager note
Server regionDirects the request to the right teamPassword manager note

If an account is lost, change the email password first, then request recovery. Reversing that order lets whoever holds the account undo each step you take.

Scams aimed at players

Game accounts attract a specific family of approaches, and they are effective because they arrive in the middle of playing rather than in an inbox you are scrutinising.

What to watch out for

  • Support impersonation. A message claiming a violation and asking you to confirm credentials. Legitimate support does not ask for a password or a second-factor code.
  • Bonus code pages. Sites offering codes in exchange for a login. A code is entered inside the game or on the publisher's own site, never on a third-party page, and an expired code — like the one described on our game page — simply fails rather than needing a workaround.
  • Trade and gift offers. A stranger offering items in return for account access, or a link to a "trading" site with a lookalike domain.
  • Cheap currency sellers. Purchases outside the publisher's shop commonly breach the account terms; the account bears the consequence, not the seller.
  • Fake tournament or beta invitations. A sign-in page reached from a chat link, styled to look like the publisher's.

Two services in Australia take reports. Scamwatch, run by the National Anti-Scam Centre, collects scam reports and publishes warnings. The Australian Cyber Security Centre operates the national reporting route for cybercrime, including account compromise, and publishes recovery guidance. Where the incident involves abuse or harassment rather than fraud, the eSafety Commissioner is the statutory office that handles it.

What the account knows about you

A game account holds an email address, a payment history if you have spent anything, an IP address history, a device fingerprint of some kind, and a record of play. That is ordinary for the category, and it is worth knowing because it is the material at risk in a breach and the material covered by privacy law.

The Australian Privacy Principles set out how organisations covered by the Privacy Act 1988 (Cth) must handle personal information, including access and correction rights; they are published by the Office of the Australian Information Commissioner at oaic.gov.au. Whether a particular overseas publisher is covered depends on its circumstances, which is a question for the publisher's own privacy policy in the first instance and for the OAIC if an answer is unsatisfactory. This site's own handling of personal information is described in our privacy policy, and it is short, because we collect nothing.

The account checklist