I have done that, That is a pretty shady policy as far as restoration goes(very lazy)
If you don't like it, and since you are not very lazy like Nost devs, I suggest you start your own server and implement a policy of character restoration.
Alternatively, you can go play retail and pay Blizzard to restore your toons for you.
I had worked hard to gear I would be even more upset. Also account security is not only up to the user its up to the site itself especially when you saw brute forcing going on from at least the 18th of the month and didn't do anything to stop it. viewtopic.php?f=2&t=38394
Strange, I have been playing WoW 11 years now or so and I have never been hacked, which tells me that ppl who allow themselves to get hacked, suck.
what could you have done? Limited login attempts to 1-2 per account without the accounts password having to be reset...added google authenticator or some other authenticator to accounts....you added the ip region but it was not activated on my account by default I had to change it to my region when I reset my password(This is also easily bypassed by using a vpn so its kind of pointless).
All the above is not required since there are people who have been playing WoW for 11 years and never get hacked (see above)
You just need to L2AccountSecurity.
at the very least on the 18th when it was noticed a mass email should have went out to the users or a required password reset should have been triggered. Not everyone reads the forums to have saw it I didnt until after my account was hacked.
An e-mail cannot make lazy ppl and n00bs (aka scrubs & plebs) suddenly grow a brain. Around 3k n00bs got hacked yet on the other hand 10k other people more did not.
You just need to L2P.
I appreciate everything you guys do and I love your server but you have to take responsibility for your part too and I would for mine. NONE of my passwords for any other private server are the same but I would have changed it anyway had I got an email about the ongoing attacks the 18th which may have prevented me from losing my character. It doesn't matter what password we have if security measures are not in place to stop brute force attacks, the way cracking works is they load up a dictionary file of thousands of combo's of every possible combo imaginable into a program that can do sometimes up to thousands of attempts per second using sockets and proxies. So until you guys put more of a lockdown in place I suspect nothing is going to change.
You did not get hacked b/c of a brute force attack. you got hacked because you are lazy and/or a n00b. This cannot be helped.