The latest wave isn’t some shadowy data breach. It is social engineering that turns your buddy list against you. One player gets compromised, often through an earlier mod download or reused password. The attacker then slides into DMs from that trusted account, drops a link to what looks like a harmless Minecraft client tweak or modpack, and the cycle continues.

A post from @lumosterris on October 6 showed their Microsoft account hijacked with the only visible change being the Minecraft skin switched to Peter Griffin. Other users replied with similar stories, including one noting the attacker immediately pivoted to asking for more downloads from fresh contacts.

The method echoes earlier WeedHack-style campaigns but feels more personal because it comes from people you actually play with. One X user with 30-plus likes laid it out plainly: the scammer controls the hacked account, pretends to be the owner, asks you to download a Minecraft mod, steals your tokens, then repeats. Reporting the account rarely stops the chain fast enough.
Players are also seeing hacked accounts used to push Discord invites or “test this modpack” calls that lead to JAR files packed with stealers. The advice circulating is simple and repeated: verify out-of-band before downloading anything suggested by a friend in-game or in chat, and lock down your Microsoft login with app-based 2FA instead of SMS.
- Verify unexpected mod or client links with a separate call or message, even from friends
- Never run JAR files from untrusted sources, even if they claim to be popular clients like Meteor or Wurst
- Check your Minecraft skin and recent logins regularly; sudden changes are the first red flag
- Use a dedicated Microsoft account for Minecraft with strong unique password and 2FA
Yall need to start using 2fa on everything. Everyone getting hacked recently it seems.
The pattern is not new, but the volume of fresh complaints in the last two days suggests the current batch of operators is active and scaling through existing friend networks. Mojang has not issued a specific statement on this latest surge, but the community response is clear: treat every unsolicited mod link like malware until proven otherwise.





