Always check the latest post for evolving guidelines on D2 Account Safety.
This has been updated to reflect a new attack vector described by scboi on a different website.
Recommended Actions:
1) 2 Factor Authenticate your bnet account. Don't reveal your CD key to anyone. Change your secret question/answer. Change your bnet account password.
2) Change your diablo 2 password, especially if you have had the same one for a long time (years). Make it different from any other one you use for any other account (jsp, gd, asguard, emails, etc). Password length is more important than complexity in regards to safety.
3) For your D2 Account Recovery Email: Make this different from your bnet account email. Enable 2FA on it. Ensure that your bnet account, recovery email, and d2Acc all have three distinct and unique passwords.
4) Minimize revealing your Diablo 2 in game identities, both on forums (forum name to d2 account linkage) and in the actual game (d2 account to d2 account linkage). When trading on jsp/gd, use a mule account with no valuable items. Move your existing high value items to a mule account not known to the public and that you do not duel on. Refrain from showing high value items to strangers in game. *NEW* This mule account that holds your high value items should be created by a secure CD-Key, meaning that the CD-Key has been kept secret, the bnet Account bound to that CD-Key is secured with 2FA, and you have never given access to any account created by that CD-Key to anyone.
5) If you were hacked, buy a new CD key pair from Blizzard and create a new bnet account secured with 2 Factor Authentication. Make your new D2 accounts using this new, secret CD key.
6) *NEW* Do not mule items for others. More generally, do not give anyone access to any account made by your CD-Key. If you have accidentally done so, move your valuable items to a secure mule account described in #4 and revoke access to those accounts by changing the password.
This post was edited by Taylor_Swift on Apr 2 2020 01:05pm