• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

My PSN was hacked 3 weeks ago, so Sony disabled access to every game I own on PS4.

dock

Member
My PSN account was hacked three weeks ago.
It had a unique password but it did not have two-factor-authentication.

The hacked enabled TFA after stealing the account and used this to gain full control. The hacker was even able to phone support and claim to be the account owner and switch all the details back to himself, and the hacker was bragging about this by trying to contact me through social media and offering to sell my PSN account.

After many hours of phonecalls with PS Support I was able to get the account suspended and I was assured the case would be escalated, but it has been three weeks and Sony are being useless. I have had to send my passport photo to them four times and one time they even asked me to send an ID with 'a correct date of birth'... as though I have several different passports handy?

The hacker was also able to steal my Twitter account because this was connected to my PSN account, allowing me to tweet screenshots. I have since been able to regain access to my Twitter account, with a long process of sending passport photos and lots of other info.

Has anyone here been hacked on PSN before? How bad was the process of it being fixed? Did you ever regain access, or should I just sell my PS4 and give up on thousands of pounds of PS software over the last decade?
 
It had a unique password but it did not have two-factor-authentication.
Why why why why why

Every week it seems like there is a thread like this because people didn't activate 2 step.
This guy is an asshole for activating it and taking all your details open, I hope Sony can help you in the end.
 
I have since been able to regain access to my Twitter account, with a long process of sending passport photos and lots of other info.

It's sad that twitter (where you don't spend money) have better support than PSN.., I hope everything ends well, and don't fucking give up OP!
Call sony again and again and again until someone helps you.
 
Rule # 1: If your account gets hacked and you ask Sony to do something, they'll kill the account.

Rule # 2: If your account had yours or someone else's credit card and you or they ask for chargeback, they'll kill the account.

Rule # 3: ALWAYS USE TWO FACTOR AUTHENTICATION, PEOPLE!!!!! IF THE HACKER IS SMART ENOUGH TO DO IT, THEN YOU SHOULD BE TOO.
 

dock

Member
I honestly did not know there was two-factor authentication on PSN.

I'm surprised that the attitude here is so much of 'serves you right'.
 

test_account

XP-39C²
Since you had to send your passport phone 4 times, it sounds like someone isnt taking the case further. I would call and demand talking to a manager, explain the whole case and say that you're taking the case to the newspaper/media if something doesnt happen.

My mother had a similar case with another company where a double payment had been made, but the 2nd payment wasnt refunded. I contacted them several of times and were told that they would look at it, nothing happened. The my mom called and the CEO got to hear it, then it was fixed within a day.

Also, about birthdate, are you sure you wrote your real birthdate when registering? I dont think i did and i cant remember what i typed.


Rule # 1: If your account gets hacked and you ask Sony to do something, they'll kill the account.

Rule # 2: If your account had yours or someone else's credit card and you or they ask for chargeback, they'll kill the account.

Rule # 3: ALWAYS USE TWO FACTOR AUTHENTICATION, PEOPLE!!!!! IF THE HACKER IS SMART ENOUGH TO DO IT, THEN YOU SHOULD BE TOO.
Rule number one is not true. People shouldnt avoid contacting Sony if they account gets compromized. Theres several of cases here on NeoGAF where users have gotten their cases sorted out quickly without any problem.
 

stryke

Member
People are less inclined to talk about it but I've yet to hear a good story of regaining a hacked psn account.
 
Because each week we have similar thread and each time the op didn't use tfa

It was the first thing i did when the firmware update was launched.
People are so careless with their personal data and pictures. Probably why i don't like facebook and all sorts…
 

Persona7

Banned
I honestly did not know there was two-factor authentication on PSN.

I'm surprised that the attitude here is so much of 'serves you right'.

A vast majority of these account take overs happen because people re-use passwords, a poorly secured website has a password database leak and people check the database against other high value websites because they know people re-use passwords.

It's either that, malware logging passwords or someone is targeting you directly with social engineering.
 

Dunkley

Member

Actually not possible since they need to contain a number and need to be 8 characters long.

Thus, my guess is on AUnique1

edits:

Honestly however, not sure what to tell you. My guess is that unless they managed to exploit a security hole in PSN itself, the issue would lie instead with the fact that it wasn't just your PSN that got hacked and the hacker in question managed to obtain your account through that. I mean you did say regaining your twitter was an enduring process so the hack did not just limit itself to that, right? Otherwise you'd be just able to toss out the authenticated device and put a stop to the person being able to tweet on your account.

Regaining your account is going to be pretty tough from what I could tell from other threads, sucks that you didn't know 2 factor authorization was a thing but especially given the hacker in question was able to identify themselves as you, you're going to be struggling. Best you can try is getting through support no matter how long it takes and potentially being able to prove something to them that's gonna link the account's identity to you, otherwise it's gonna be pretty tough for you to identify yourself as the account holder rather than someone who is trying to steal an account. They have their information on your account now and that serves Sony as the best point of reference for who the account belongs to, and you need to think of something to prove that you do in fact possess that account since with the passport stuff and ID stuff in place right now they're probably just seeing that it belongs to someone else if they are telling you the birth date is off.
 

angelic

Banned
unique.png
 

Macrotus

Member
The op says he/she used a unique password.
When seeing these type of posts from time to time,
I wonder how hackers obtain peoples passwords, if they're unique.

I could only think of, logging on to PSN via PC and a key logger was installed on that PC (without the user knowing)
or
maybe it was an easy password to guess?

Anyways, putting the OP not having two-factor authentication aside,
I still feel 3 weeks is a bit long, since the op has sent a copy of his passport many times.

Personally,
if I didn't have two-factor authentication and was hacked and needed my account restored,
I don't mind paying a fee to Sony to restore my account ASAP (within a week).
Since it does require manpower and it would be my fault for not having two-factor authentication. If I had it enabled, that would be another story.
 

Rellik

Member
I honestly did not know there was two-factor authentication on PSN.

I'm surprised that the attitude here is so much of 'serves you right'.

It's nothing personal. If you didn't know then you didn't know.

I think it's because we see these threads all the time and every single one is someone who didn't activate 2FA. And in every one of these threads its a million replies of ACTIVATE 2FA.

I'm surprised at Sony making you send your passport that much, though. When I locked myself out of my own account because of 2FA and me having a new phone number, I had to send them my drivers license and proof of phone number. They deactivated my 2FA a couple of weeks later without issue (Apart from having to wait a ridiculous 2 weeks)
 

Vuze

Member
Hah, same here, Never seen a prompt, advert or incentive to get me to enable it before.
Me neither. Wouldn't know it existed if I didn't frequent Gaming side. Every other service urges you to re-verify or configure 2FA every once in a while. PSN? Nahhh. The percentage of users taking advantage of 2FA on PSN must be miniscule.
The system was also bugged for a long(?) time if you had a Sony forum account associated with your PSN mail.
 

Mendrox

Member
Rule # 1: If your account gets hacked and you ask Sony to do something, they'll kill the account.

Rule # 2: If your account had yours or someone else's credit card and you or they ask for chargeback, they'll kill the account.

Rule # 3: ALWAYS USE TWO FACTOR AUTHENTICATION, PEOPLE!!!!! IF THE HACKER IS SMART ENOUGH TO DO IT, THEN YOU SHOULD BE TOO.

Rule # 4: Always use your REAL DATA with important accounts like this or you won't be able to get everything back with your passport
 

Rellik

Member
LOL right? Is there a bigger monetary incentive than not losing all your games?

Seriously. When I was locked out my account, I could have cried when I realised how many games I had on that account. My brand new Pro sat there for 2 weeks like an expensive paperweight.

Protect your account, people.
 

BigEmil

Junior Member
The op says he/she used a unique password.
When seeing these type of posts from time to time,
I wonder how hackers obtain peoples passwords, if they're unique.

I could only think of, logging on to PSN via PC and a key logger was installed on that PC (without the user knowing)
or
maybe it was an easy password to guess?

Anyways, putting the OP not having two-factor authentication aside,
I still feel 3 weeks is a bit long, since the op has sent a copy of his passport many times.

Personally,
if I didn't have two-factor authentication and was hacked and needed my account restored,
I don't mind paying a fee to Sony to restore my account ASAP (within a week).
Since it does require manpower and it would be my fault for not having two-factor authentication. If I had it enabled, that would be another story.
Maybe they entered their login details on a phishing fake website impersonating a real one?
 
Good luck Sony has the worst customer service in the business. Even escalations landed me nowhere. If you don't like the victim blaming here, don't worry Sony is even worse. I got hacked before two factor even existed (I use a password manager w all unique passwords) and they deactivated my hardware. Sony would not let me reactivate my own hardware for 6 mos which is the standard time frame to use the nuclear deactivate process even though it was not me who used it.

Have cancelled PS+ and removed all payment info. Not worth it for me to keep my financial info with a company that doesn't give a shit.
 

Rellik

Member
Yeah, chances are everyone is "pwned" according to this. It says i have 5 breaches. One of them is some forum from 10 years ago i was a subscriber to was breached. But that only reveals my email address, not the email password.

Also, stop using your main email address for PSN. If you're on Gmail then put something like '+psn' just before the @gmail.com part and then no one will know your login email and the emails will still get to you from Sony.
 

RoadHazard

Gold Member
It had a unique password.

Are you SURE? Is it a strong unique password? If it's "password123" it doesn't really matter if it's unique. It need to be unique and strong. Doesn't seem likely that anyone would be able to "hack" your account if it is. I don't believe we've had any confirmed cases of actually hacked PSN accounts, it's always people using the same password elsewhere, it being leaked from there, and then used to access the PSN account.
 

DrDamn

Member
I think it's possible your email account associated with your PSN account (and Twitter) was what was compromised and the person gained access to the other stuff through that. Are you sure that is secure and have you changed your password there too?
 

dock

Member
Good luck Sony has the worst customer service in the business. Even escalations landed me nowhere. If you don't like the victim blaming here, don't worry Sony is even worse. I got hacked before two factor even existed (I use a password manager w all unique passwords) and they deactivated my hardware. Sony would not let me reactivate my own hardware for 6 mos which is the standard time frame to use the nuclear deactivate process even though it was not me who used it.

Have cancelled PS+ and removed all payment info. Not worth it for me to keep my financial info with a company that doesn't give a shit.

Holy shit. :( I'm really sorry to hear this. I've been told that my case has been escalated twice, whatever this means.

Even my shitty hack is making me want to abandon my PS4 entirely, which was until one month ago my favourite platform. I've even provided lots of details about the hacker in question, as I got a lot of name and IP info about him, and even the names of some of the other accounts he was using, but they just don't want to help.
 
Top Bottom