• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Psn Account hijacked! (Update: 6 months later, a winner is you!)

IISANDERII

Member
I twittered AskPlaystation and they told me to contact support. Support told me to change my psn password. I updated my password ok(logged in successfully on ps4), but i'm still able to use my Playstation apps on my tablet and my phone and it hasn't booted me out to ask for my new password.

That don't seem right, does it?
 

Facism

Member
I got an email from Sony to change my password and go to a link. But i never requested a password change.

Does Sony ask you to change passwords proactively?

i got an email like that. I thought it was scam until i started up the PS4 and it requested a password change.

this was the email address:

sony@email.sonyentertainmentnetwork.com

I've just changed my password via PS4 again and got an update about it from the same email address. People are saying it's a scam email address but that would mean they're intercepting passwords changed via the console itself? Such a fucking headache, should of just stuck with PC.
 

duessano

Member
I twittered AskPlaystation and they told me to contact support. Support told me to change my psn password. I updated my password ok(logged in successfully on ps4), but i'm still able to use my Playstation apps on my tablet and my phone and it hasn't booted me out to ask for my new password.

That don't seem right, does it?

That's normal, once you log in on the app, it won't make you login until you log off, even if you change your password.
 

IISANDERII

Member
i got an email like that. I thought it was scam until i started up the PS4 and it requested a password change.
Yeah Sometimes PSN will automatically prompt a password change if it detects fishy activity. The rep thought that this was the same situation. It wasn't; somebody tried to change my password and it didn't raise any alarms like that.

That's normal, once you log in on the app, it won't make you login until you log off, even if you change your password.
Phew! Thanks.
 

IISANDERII

Member
Bump.

It just happened again.

Same email, from Sony to change my password. The email address is sony@email.sonyentertainmentnetwork.com

The email itself looks very legit, i dont think it's fake.

Also, the other day i got an attempted scam call from "Windows Support", didnt give him any info at all, but he already knew my name.

Am i already fried?

Edit: going to install a virus checker on my Android tablet. Could that be it?
 

rainy_day

Member
Always use the prepaid cards!
I buy all mine at target to get the extra 5% off them.

I should probably change my password anyways, didn't they get hacked a week or so ago?
 

IISANDERII

Member
I actually had $50 sitting in my account from refunding Club Drive weeks ago and it was untouched(today i used it to preorder Witch Killer 3 or whatever it's called).
 

hodgy100

Member
quick bump... sony asked for console serial numbers on thursday i phoned saturday to see what's taking so long and they said they are still working on my case. These refunds are really taking the piss to sort out :/

Bump.

It just happened again.

Same email, from Sony to change my password. The email address is sony@email.sonyentertainmentnetwork.com

The email itself looks very legit, i dont think it's fake.

Also, the other day i got an attempted scam call from "Windows Support", didnt give him any info at all, but he already knew my name.

Am i already fried?

Edit: going to install a virus checker on my Android tablet. Could that be it?

that email doesn't look legit, and by the looks of it after a quick google, it isnt. you should be fine if they dont work out your password, but you can also change your sign in email yourself if you wish.
 

hodgy100

Member
Hi Hodgy,

Thanks for your recent contact regarding your Sony Entertainment Network (SEN) account.

I understand from our contact that you did not recognise some transactions on your account, and you reported these transactions as unauthorised. As these transactions were made via our online webstore, we're unable to take action against any consoles for processing this purchase. We will however investigate any devices involved where possible and take action where appropriate, however we will be unable to share details of this.

Unfortunately, as the account holder you are responsible for all use of your SEN account, including all purchases, and agree to pay for all orders placed using your SEN account. For this reason, we cannot offer a refund for these transactions - this is outlined in our Terms of Service.

As PlayStation Network has not been compromised, I can assure you that any information stored on our servers is secure. We would highly recommend that you change your account password to re-secure your account. The billing details have already been removed from your account.

For your reference, our Terms of Service can be found here.

I hope this helps, but if you have any other questions please contact PlayStation Support using the contact details below or by replying to this e-mail. Quote reference 141127-005538 and one of our team will be happy to help.

Thank you,

Called them up too guy said my only option is to get my bank to do a chargeback which will probably lead to my account being banned and maybe my consoles too.

Looks like I'm seeking legal action I cant let £598 slide :/
 

fedexpeon

Banned
sorry just bumbing this.

Has LegalGAF got any advice?

You do a chargeback with your bank, email back support with your case # and informing them that you did what they asked and the bank will contact Sony billing department for more information.
Heck, you can even tell your banker to contact the billing department for you, and have them just fax over the dispute form and get a supervisor/manager from Sony to sign off that you were hacked.
It is all about liability, and the bank will do anything to avoid using their fraud insurance and rather lets the credit/debit card issuer eats the charge for them instead.

Edit: Whoa...Dude, you need to do this quick.
The timetable can be very short, 30 days for example, you better hope that the bank allows chargeback within 90 days.
 

rezuth

Member
You do a chargeback with your bank, email back support with your case # and informing them that you did what they asked and the bank will contact Sony billing department for more information.
Heck, you can even tell your banker to contact the billing department for you, and have them just fax over the dispute form and get a supervisor/manager from Sony to sign off that you were hacked.
It is all about liability, and the bank will do anything to avoid using their fraud insurance and rather lets the credit/debit card issuer eats the charge for them instead.

Edit: Whoa...Dude, you need to do this quick.
The timetable can be very short, 30 days for example, you better hope that the bank allows chargeback within 90 days
.

Yeah, this is my main problem. You are going to have a hard time to contest something that happened more than a month ago.
 

hodgy100

Member
You still haven't dealt with this?

see my update in the OP and above.

You do a chargeback with your bank, email back support with your case # and informing them that you did what they asked and the bank will contact Sony billing department for more information.
Heck, you can even tell your banker to contact the billing department for you, and have them just fax over the dispute form and get a supervisor/manager from Sony to sign off that you were hacked.
It is all about liability, and the bank will do anything to avoid using their fraud insurance and rather lets the credit/debit card issuer eats the charge for them instead.

Edit: Whoa...Dude, you need to do this quick.
The timetable can be very short, 30 days for example, you better hope that the bank allows chargeback within 90 days.

Playstation support said If I do a chargeback they will ban my account and blacklist my consoles. My account is worth quite a bit more than the £600 i've lost. it's not really an option for me. I was considering taking them to small claims court.

How much stuff was on your PSN account, games dlc etc?

Alot. Ive had the account since 2006 and have been buying stuff on it since european launch. Plus with the threat of my consoles getting blacklisted too that would be my ps3,ps4 and vita out of action.
 
Sonys security sucks. I recently got hacked. Nothing bought, but the console was disabled as primary. So some guys somewhere can now enjoy my games for free. I instantly put a pin code on my cc info. But the console NEVER asks for this pin. Also my vita doesnt and the web store doesn't. So wth is up with that.
 

Faddy

Banned
Whenever something like this is brought up, I wish people would tell us what password they were using.

Was it actually long enough, randomly generated, consisting of letters/numbers/symbols?

I have a feeling the answer is "no" in most cases.

That is only part of it, multiple uses of the same password is more likely to be the cause of the problem. Even the worst company won't allow you to attempt to login with incorrect details repeatedly (or at least I hope they don't) so brute forcing someones password is very unlikely to happen.

Email and passwords obtained from leaks or hacks are more often the cause. In the past some sites have stored these in plain text, others hashed or salted and hashed. In the latter 2 cases weak passwords are more exploitable via Rainbow Tables and other techniques.

Sony have shocking policies with regard to their protection of their customers. They have no 2 factor authentication or security protocol. They also undercut consumer protection laws by banning your account if you dare to use your rights to get a refund. They have a robust licensing system for digital games, refunds and revoking rights should be simple.

It is a total sham of a system. Getting scammed £500 but fearing to use legal means to get your money back because they will ban the account potentially locking you out of your console and games which could be worth substantially more.
 

hodgy100

Member
That is only part of it, multiple uses of the same password is more likely to be the cause of the problem. Even the worst company won't allow you to attempt to login with incorrect details repeatedly (or at least I hope they don't) so brute forcing someones password is very unlikely to happen.

Email and passwords obtained from leaks or hacks are more often the cause. In the past some sites have stored these in plain text, others hashed or salted and hashed. In the latter 2 cases weak passwords are more exploitable via Rainbow Tables and other techniques.

Sony have shocking policies with regard to their protection of their customers. They have no 2 factor authentication or security protocol. They also undercut consumer protection laws by banning your account if you dare to use your rights to get a refund. They have a robust licensing system for digital games, refunds and revoking rights should be simple.

It is a total sham of a system. Getting scammed £500 but fearing to use legal means to get your money back because they will ban the account potentially locking you out of your console and games which could be worth substantially more.

It is indeed ridiculous. and unfortunately I was blind enough to think "it would never happen to me" I'm fairly certain if I go through the courts I can stipulate that sony aren't allowed to ban my account and if they did then further legal action could probably be taken. The annoying thing is, I don't want any of the games that were ordered on my account, they can revoke the licences. They have the ability to do that so why won't they?
 

Occam

Member
That is only part of it, multiple uses of the same password is more likely to be the cause of the problem. Even the worst company won't allow you to attempt to login with incorrect details repeatedly (or at least I hope they don't) so brute forcing someones password is very unlikely to happen.

Email and passwords obtained from leaks or hacks are more often the cause. In the past some sites have stored these in plain text, others hashed or salted and hashed. In the latter 2 cases weak passwords are more exploitable via Rainbow Tables and other techniques.

Good point, everybody should keep this in mind. Precisely for this reason I don't use the same (randomly generated) password in more than one place.
 

cyberheater

PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 Xbone PS4 PS4
I don't feel this is going to work out well for the OP.

Good luck OP.
 
Can't you disable that console through the SEN deactivation thing?

Once per 6 months. Problem is: for a year, the "hackers" have beaten me to it. Somehow changing my password doesn't work. They can always get in. It's really very weird since no one at home has access to my devices. And even then doesn't know my passwords. Which are randomly generated. And copy pasted. So no key logger nonsense. Sony doesn't want to help. They just say it's my fault for giving away my password even when I explicitly tell them I didnt. They don't want to deactivate the other console even if they can tell me in which city it is (Budapest, while I'm in Holland). Gets my blood boiling.
 

mocoworm

Member
I just removed my CC info from SONY account. Between this and the BoomerangRentals thread this morning, I just felt it was a required step.

Did someone say that you can pay on PSN with PayPal?
 

Bradach

Member
That sounds really bad OP. best of luck getting it resolved.

Thanks for this thread though. I've just deleted my CC details from my account. The minor inconvenience of entering the details each time I buy something is easily outweighed by avoiding what you're going through.
 

Rosur

Member
see my update in the OP and above.



Playstation support said If I do a chargeback they will ban my account and blacklist my consoles. My account is worth quite a bit more than the £600 i've lost. it's not really an option for me. I was considering taking them to small claims court.



Alot. Ive had the account since 2006 and have been buying stuff on it since european launch. Plus with the threat of my consoles getting blacklisted too that would be my ps3,ps4 and vita out of action.

I would like to see someone take this kinda of thing to court (especially when other companies do this as well).
 

cyberheater

PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 Xbone PS4 PS4
I'm fairly certain EU / UK law has me covered. :) I have hope!

I hope so mate.

I just don't understand why Sony can't revoke those games and issue a refund. Try phoning them again and state your will seek legal advice if they don't reimburse you.

I would in the first instance contact contact citizens advice:-

http://www.citizensadvice.org.uk

There phone number is:-

Wales call 03444 77 20 20
England call 03444 111 444
 

hodgy100

Member
The law has you covered regarding your £££ , but you will probably get an account and console ban from SONY when the £££ is clawed back.

I wander if there is a way to find out if this would be the case without being the guinea pig.

I hope so mate.

I just don't understand why Sony can't revoke those games and issue a refund. Try phoning them again and state your will seek legal advice if they don't reimburse you.

I would in the first instance contact contact citizens advice:-

http://www.citizensadvice.org.uk

There phone number is:-

Wales call 03444 77 20 20
England call 03444 111 444

Thanks I will give them a call when I get the chance.
 

Footos22

Member
I just removed my CC info from SONY account. Between this and the BoomerangRentals thread this morning, I just felt it was a required step.

Did someone say that you can pay on PSN with PayPal?

Yes you can pay with paypal. its the only way to be honest. Make sure you use a different email address and password for that though for extra security. Wouldnt keep your credit card on anything. I dont even risk it with xbox now after that fifa bs.
 

Shadders

Member
Take them to small claims court!

Initiate the proceedings today. It costs you about £60, but you get that back when you win. You just need to convince a judge that Sony didn't do enough to protect you (mention their history of shoddy security + lack of two-step authentication).

The judge then makes a decision based on law/common sense. You'd have a really strong case. And in all likelihood, Sony will just refund you when they receive the court papers because it will cost them more than £500 to arrange for one of their team to appear in court.

EDIT: It's small claims so your losses are limited to the £60 court fee, you don't have to pay Sony's expenses or anything if they win.
 

mocoworm

Member
I hope so mate.

I just don't understand why Sony can't revoke those games and issue a refund.

Can SONY not see the console or IP that these games have been dloaded to or charged from? Surely the fraudsters console has been tied to other accounts in the past, therefore leaving a trail to their true identity.

You would think they would employ ppl just to track these criminals.
 

hodgy100

Member
Take them to small claims court!

Initiate the proceedings today. It costs you about £60, but you get that back when you win. You just need to convince a judge that Sony didn't do enough to protect you (mention their history of shoddy security + lack of two-step authentication).

The judge then makes a decision based on law/common sense. You'd have a really strong case. And in all likelihood, Sony will just refund you when they receive the court papers because it will cost them more than £500 to arrange for one of their team to appear in court.

EDIT: It's small claims so your losses are limited to the £60 court fee, you don't have to pay Sony's expenses or anything if they win.

This is the plan. I am first going to send a strongly worded and detailed letter about my experience as a formal complaint threatening legal action if my issue isnt resolved.
 

cyberheater

PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 PS4 Xbone PS4 PS4
This is the plan. I am first going to send a strongly worded and detailed letter about my experience as a formal complaint threatening legal action if my issue isnt resolved.

Speak to Citizens advice first. No doubt they have had other folks in the same situation and will know the best way to go about it.
 
Top Bottom