Just got this in an email from Blizzard (noreply@blizzard.com). It appears to be 100% legit, but…
Due to suspicious activity, the Battle.net account [/email] has been locked. To restore access to this account, please follow these steps:
Step 1: Secure Your Computer
In the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.
Step 2: Secure Your E-mail Account
After you have secured your computer, please create a new password for your e-mail account since it may also be compromised. Be sure to check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit this Support page.
Step 3: Choose a New Password
You must change your password in order to resume using this Battle.net account. Please click this link to choose a new password:
https://us.battle.net/account/support/password-reset.html
*Note that your former password no longer grants access to Battle.net account management, World of Warcraft, or any other login-protected Battle.net account service.
If you still have questions or concerns after following the steps above, feel free to contact Customer Support at http://us.blizzard.com/support/article.xml?locale=en_US&articleId=20606.
Sincerely,
The Battle.net Account Team
Online Privacy Policy
Okay, seriously, I have an authenticator, there’s practically speaking no way my account could reasonably have been compromised other than a just-in-time active attack via keylogger.
But more importantly, doesn’t everyone ever tell you to never click on links in an email? And here is Blizzard being all “We expect you to click on these links, because your normal account-management page won’t even log in, derp herp.”
Thoughts? This is legitimate, right? I can’t see how going to a us.battle.net subpage would end up with my account hacked, especially when it’s HTTPS. But I’m still fucking paranoid.