September 2014 - last edited February 2015
We know that it's important to keep your FIFA Ultimate Team account safe, so please read these important tips you can use to help keep your account safe and secure. For even more information, check out this article on How to Maintain Account Security.
TABLE OF CONTENTS
ASKING FOR YOUR INFORMATION
EA will never ask you for your login information
On the forums
On your console
PHISHING EMAILS, LINKS and WEBSITES
Fake emails and copycat websites
How can I tell the difference between a phishing site and the authentic EA one?
Misleading hyperlinks
Beware of redirects
Scare tactics
ADDITIONAL SECURITY
WHAT TO DO IF YOU’VE BEEN PHISHED
Overview
I received a phishing email
Report phishing sites to EA
ASKING FOR YOUR INFORMATION
EA will never ask for your login information:
There are no exceptions to this rule. Even if you receive an email that appears to be from EA, remember that if it asks for your account information it’s a scam.
Follow these four simple safety rules:
To help reduce the chance of your account of being compromised or “phished,” it’s always wise to follow these rules:
Create an Origin security question:
Setting up an Origin security question gives your FUT account an important extra layer of protection.
Make sure you keep your Origin account up to date. To maximize your account security, make sure you use a unique password for each service or site that requires a login.
Back to Top
On the forums:
If you ever receive a private message in the forums asking for your account information, it is fake. Scammers will even use names that sound legitimate, such as “EA Admin” or “FIFA Developer.” Again, EA will never ask you for your account info.
If you do receive a message like this, report it to one of the forum moderators. Those responsible for sending messages of this kind will suffer swift justice – justice that could affect more than just their forum privileges, up to and including a full console ban.
Back to Top
On your console:
If you ever receive a private message through Origin's online messaging system asking for your account information, it is fake. EA will never contact you through Origin’s messaging system for any reason. Do not give out your details. Make sure to report the details of this message using the built-in report tool.
Back to Top
PHISHING EMAILS, LINKS and WEBSITES
"Phishing" is the term used when an online scammer attempts to trick someone into giving up valuable information (like your login information and password) by sending you to a fake website and prompting you to enter your account details.
Fake emails and copycat websites:
You receive an email that appears to be from EA concerning an Ultimate Team (or other game) promotion. You click on the link in the email, go to what appears to be the Ultimate Team login page, and enter your account name and password. Two days later you discover all the gold players you’ve worked so hard for have disappeared.
Sound familiar? Hopefully not, as the scenario described above was a phishing scam. As the majority of phishing websites look identical to the real thing, most users don’t even realize they’ve been phished until it’s too late.
When browsing and regarding your account details, be sure to check the URL, as indicated below, to ensure you preserve your account's security.
NOTE: Be sure to also read this article about the risks from buying or selling FUT Coins from a third party service.
Back to Top
How can I tell the difference between a phishing site and the authentic EA site?
The official EA website uses the following URL: http://www.easports.com/.
You may also be contacted directly by EA or EA SPORTS via email containing one of more of the following official EA and EA SPORTS web links relating to EA SPORTS FIFA, FIFA Ultimate Team, EA SPORTS Football Club, or EA:
www.ea.com
www.futpromos.com
www.easportsfootball.com
www.easportsfootballclub.com
Any other similar-looking URL is not official and should not be clicked on.
Misleading hyperlinks:
The text of a hyperlink may contain a url that is not the url it actually links to. Roll your mouse over this link: www.ea.com/safe. Notice either in the bottom of your browser window or in a small text box over the link, the actual url does not match. Make sure any link you click on leads somewhere official.
Back to Top
Beware of redirects:
Redirecting is a technique where a scammer embeds something in a link that takes you to the real site to begin with, but then moves you to a fake page that looks identical. There are many examples of this, but one simple thing to look out for in your address bar would be: http://www.ea.com/redirect?url=http://fakesite.com
Note the “redirect?” part of the URL. This means you will actually go to a different site than the one you were trying to reach.
EA will never redirect you from http://www.ea.com/ to another site.
Back to Top
Scare tactics:
Another common tactic involves scaring you into thinking your account has been compromised when it actually hasn’t. You may receive a message saying something like: “Your account has been temporarily suspended due to suspicious activity. Please login here to see more information.” This is another attempt to get you to give up your username and password. As always, the end result its directing you to a site other than http://www.ea.com or http://www.easports.com/fifa.
EA will never send you emails claiming your account has been compromised. EA will never contact you via ANY means asking for your login information.
Back to Top
ADDITIONAL SECURITY
Here are some additional precautions you can take to ensure your information is protected.
WHAT TO DO IF YOU’VE BEEN PHISHED
Overview:
If you believe you’ve entered your login info into a phishing site by accident, change your password right away. It’s likely that your account has been compromised, but you may still have time to save it.
Then contact EA’s customer service team immediately at http://help.ea.com, providing as much detail and evidence as you can. In particular, our team will need accurate details of what items (if any) you have lost, plus the date and time that you lost them.
Back to Top
I received a phishing email:
If you receive a phishing email message, don’t panic. Your account has not been compromised. All the scammer has is your email address, which can be relatively easy to find. Scammers duplicate the images and text from an official EA email in the same way they copy websites. If you receive a suspicious-looking email, check who the sender is, as well as where the links in the email are taking you.
Some things to be aware of with phishing emails:
Report phishing sites to EA
We are continually taking action against phishing sites as we are made aware of them. We are also taking strong, prompt action against any users attempting to scam others using these sites or any other scams.
Please let us know about phishing sites by contacting us.
Back to Top
September 2014
Be sure to see this steps here, for a bit more extra tips (some of it is in the above post as well):
Online accounts are an inviting target for the hackers and phishers. Keeping your account information safe and secure is a top priority for us here at EA, but there are steps you can take to protect yourself as well.
TABLE OF CONTENTS
PASSWORD SECURITY
Password Overview
Resetting Your Password
Password Integrity
MALWARE/VIRUSES
Overview
AVOIDING PHISHING SCAMS OVERVIEW
Phishing Overview
Some simple rules to avoid phishing scams
ASKING FOR YOUR INFORMATION
EA will never ask you for your login information
On the Forums
On Your Console
PHISHING EMAILS, LINKS and WEBSITES
Fake emails and copycat websites
How can I tell the difference between a phishing site and the authentic EA one?
Misleading Hyperlinks
Beware of Redirects
Scare Tactics
ADDITIONAL SECURITY
Overview
WHAT TO DO IF YOU’VE BEEN PHISHED
Overview
I Received a Phishing Email
Report Phishing Sites to EA
PASSWORD SECURITY
Password Overview:
One of the ways someone may gain access to your account is if you have a weak password, making it easier to guess. As such, we have recently increased our password security requirements in order to better protect your account & reduce the risk of unauthorized access. Simple passwords, for example those that contain part of your email address, are no longer permitted.
We apologize for any inconvenience that this may cause, and wish to assure you that our efforts intend only to better protect your information and identity.
Back to Top
Resetting Your Password:
If you want to reset your password, please use the password retrieval page. Pogo users will need to follow the steps in this article.
Back to Top
Password Integrity:
Updating and maintaining your passwords is an important part of online security. One way others may be able to compromise your account is by successfully guessing your password.
Use the following suggestions to help develop a password that is harder to guess.
MALWARE/VIRUSES
Viruses and malware (malicious software) can be detrimental to your account security and can allow someone else to gain access to your account user names, passwords, and other important information. Most of the time, you won’t even know that you just allowed malware or a virus on to your computer.
With a little caution you can help protect yourself against malware and viruses:
AVOIDING PHISHING SCAMS
Phishing Overview:
"Phishing" is the practice of tricking users out of their account info and passwords for malicious purposes. Phishing scams typically work by fooling the player into thinking they are putting information into a legitimate website, when in fact they are providing info to another party. It is the player’s responsibility to avoid such scams and be vigilant against links and emails addresses that are not part of the official ea.com domain.
Back to Top
Some simple rules to avoid phishing scams:
ASKING FOR YOUR INFORMATION
EA will never ask you for your login information:
There are no exceptions to this rule. Even if you receive an email that looks like it’s coming from EA, if it asks for your account information it’s a scam.
Back to Top
On the forums:
If you ever receive a private message in the forums asking for your account information, it is fake. Scammers will even use names that sound legitimate, such as “EA Admin” or “FIFA Developer”. Again, EA will never ask you for your account info.
If you do receive a message like this, report it to one of the forum moderators. Those responsible for sending messages of this kind will suffer swift justice – justice that could affect more than just their forum privileges, up to and including a full console ban.
Back to Top
On your console:
If you ever receive a private message through your console’s online messaging system asking for your account information, it is fake. EA will never contact you through your console’s messaging system for any reason. Do not give out your details and report the details of this message using the built-in report tool.
Back to Top
PHISHING EMAILS, LINKS and WEBSITES
Fake emails and copycat websites:
Sometimes emails and websites can appear to be official emails or websites from EA, but they are actually from a third party.
For example: You receive an email that appears to be from EA concerning an Ultimate Team (or other game) promotion. You click on the link in the email, go to what appears to be the Ultimate Team login page, and enter your account name and password. Two days later you discover all the gold players you’ve worked so hard for have disappeared.
Sound familiar? Hopefully not, as the person above was just phished. Phishing is a way of tricking someone into giving up valuable information (like your account name and password) by landing on a fake website and entering in your account details. As the majority of phishing websites look identical to the real thing, most users don’t even realize they’ve been phished until it’s too late.
Back to Top
How can I tell the difference between a phishing site and the authentic EA one?
The official EA website uses the following URL: http://www.ea.com/. Be aware of any links that don't use “ea.com” as the domain name, even if they include "ea" somewhere in the url. For example, "ea.account.com” would not be an official EA site. However, “help.ea.com” is an official EA website.Always double check the sign-in URL starts with: http://www.ea.com
Back to Top
Misleading Hyperlinks:
The text of a hyperlink may contain a url that is not the url it actually links to. Roll your mouse over this link: www.ea.com/safe. Notice either in the bottom of your browser window or in a small text box over the link, the actual url does not match. Make sure any link you click on leads somewhere official.
Back to Top
Beware of Redirects:
Redirecting is a technique where a scammer embeds something in a link that takes you to the real site to begin with, but then moves you to a fake page that looks identical. There are many examples of this, but one simple thing to look out for in your address bar would be: http://www.ea.com/redirect?url=http://fakesite.com
Note the “redirect?” part of the URL. This means you go to a different site than official EA one.
EA will never redirect you from http://www.ea.com/ to another site.
Back to Top
Scare Tactics:
Another common tactic involves scaring you into thinking your account has been compromised when it actually hasn’t. You may receive a message saying something like: “Your account has been temporarily suspended due to suspicious activity. Please login here to see more information.” This is another attempt to get you to give up your username and password. As always, the end result its directing you to a site other than http://www.ea.com.
EA will never send you emails claiming your account has been compromised. EA will never contact you via ANY means asking for this information.
Back to Top
ADDITIONAL SECURITY
Here are some additional precautions you can take to ensure your information is protected.
WHAT TO DO IF YOU’VE BEEN PHISHED
Overview:
If you believe you’ve entered your login info into a phishing site by accident, change your password right away. It’s likely that your account has been compromised, but you may still have time to save it.
Then contact EA’s customer service team immediately at http://help.ea.com, providing as much detail and evidence as you can. In particular, our team will need accurate details of what items (if any) you have lost, plus the date and time that you lost them.
Back to Top
I Received a Phishing Email:
If you receive a phishing email message, don’t panic. Your account has not been compromised. All the scammer has is your email address, which can be relatively easy to find. Scammers duplicate the images and text from an official EA email in the same way they copy websites. If you receive a suspicious looking email, check who the sender is, as well as where the links in the email are taking you.
Some things to be aware of with phishing emails:
Report Phishing Sites to EA
We are continually taking action against phishing sites as we are made aware of them. We are also taking strong, prompt action against any users attempting to scam others using these sites or any other scams.
Please let us know about phishing sites by contacting us.
Back to Top
September 2014 - last edited January 2015
Be also sure to check this thread here: http://answers.ea.com/t5/FIFA-14/IMPORTANT-How-not-to-get-hacked-and-what-to-do-if-it-already/m-p/15... . For ultimate guide on how to protect your account and what to do if think you have been hacked.
Also see this thread here, on how to restor your account security, after you have been hacked/phished and your account has become compromised: http://answers.ea.com/t5/FIFA-15/IMPORTANT-Hacked-or-compromised-accounts-Start-here-to-restore/m-p/....
September 2014
If by any chance, you think you have been hacked, please follow the steps below:
The following process should be followed if you believe that your Origin (EA) Account has been hacked or compromised.
If you have been notified that your email address has been changed but have not requested a change of email address, suffered any other similarly suspicious activity, or have any other reason to doubt the security of your account, please follow the steps below to create a new account in order to request contact us for support.
Note, before contacting, be sure to have the following information available so that we may help you as quickly as possible:
Create a new Origin (EA) Account:
Contact Us from your New Account
For customers in North America:
For Customers outside of North America:
Please be aware that it is likely that the agent you speak to will need to confirm information on this account.