• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

My PSN account just got hacked

I hope you're not getting any consoles except a Wii U then. I don't think I've recalled any breaches on their system
I haven't bought anything off of PSN yet, but is there a PIN system to prevent access to your credit card in the case of such a breach?
 
I haven't bought anything off of PSN yet, but is there a PIN system to prevent access to your credit card in the case of such a breach?

If you have a card directly tied to your account, then sadly not. It's why I prefer to never save my card details when purchasing from PSN.
 
I'm not sure how "hacked" comes into this, it looks like someone got a hold of your email and password somewhere and simply logged in and then did all this. The question is where did they get their info.

This is why after some thought I'm not going PS4 next gen....

I honestly don't know why people trust and love Sony so much on this board. After all they were responsible for the biggest security breach this generation and PSN was down for 2 months...

Biggest security breach that led to nothing at all happening, yes it sucked in general and that PSN was down for a while, and it shouldn't have happened in the first place. But as far as I know nothing at all came out of the breach besides the fact that Sony sorted out their security and we all got free games.

These Fifa problems that keep happening have done more damage to peoples bank accounts than the PSN breach did to anyones but Sonys. If you are so concerned I would consider moving to a platform that isn't Sony's or Microsofts at this point.
 
This is why after some thought I'm not going PS4 next gen....

I honestly don't know why people trust and love Sony so much on this board. After all they were responsible for the biggest security breach this generation and PSN was down for 2 months...

Best avoid all consoles , the only time this has happened to me was with Fifa on XBL.
 
He should've received an email confirming the password change. Not change the password and then send the email.
Yeah, Shaneus replied to it earlier in the thread, thanks for the answer anyway :) He said that he got this when he changed the password back, so i wonder why it wasnt given in the first place, unless there is some difference in how the passwords are changed. Maybe a mail isnt sent if the password is changed when doing it on the console itself, but i dont know.
 
Sony should allow link your account with your mobile phone number and send you a SMS code to confirm the action, the same MS or Google does.
This way I notice someone tried to recover my Live account password a month ago.
 
If you have a card directly tied to your account, then sadly not. It's why I prefer to never save my card details when purchasing from PSN.
The last two times I logged in my account on another PS3, I had to re-enter my credit card or I wasn't able to use it. If I failed at entering it, it would be deleted from the account.
 
Luckily they've changed it so you need to input your cc info on the "new" ps3 and if they don't your cc gets wiped from your account. It sucks someone hacked your account though.
 
This is why after some thought I'm not going PS4 next gen....

I honestly don't know why people trust and love Sony so much on this board. After all they were responsible for the biggest security breach this generation and PSN was down for 2 months...


Totally unaware of the FIFA hacks on Xbox, I see.




I'm going back to PES after all of this, #northlondonfc
 
OP, I still don't understand how this person activated multiple systems in your account. That shouldn't be possible. Have you asked Sony about this? Do you have a pic of the page showing the authenticated systems?
 
That's a pain in the ass if I ever change my password.

How? My email is open in a pinned tab at all times. Change password, switch to tab click link in email, done.

In this case the hacker would need access to both your PSN account and your email. If he has access to both, you're pretty much fucked anyways.
 
Hope you get this sorted out & get your money back, i have never used a CC on Live, PSN or eSHOP, i would not either, i simply do not trust Sony, MS or Nintendo to look after my data i just use the scratch off cards for funding my consoles & i never keep a lot in there, i only put funds in if i am going to buy something, i probably have about ÂŁ15 in each account thats just left over credits though.

I have still not forgiven Sony for my data when they got hacked, ok everyone can get hacked but Sony lied to everyone for weeks over what had happened, i no longer have my real address tied to my PSN account either now.

Keep us all posted on how you get on.
 
Do you have any idea just how prevasive the FIFA hacks are on the 360?

And worse, when it happens you are locked out of your account for weeks while MS investigates, which is terrible.

I suggest you go Nintendo-only, if this is your main concern.

Yup happened to me....Nearly twice. The first time I got FIFA'ed They drained my MS points, and then went to my credit card and drained it of $175 worth of FIFA packs.

After 3 months I got my points and money back and finally my account a while later. Changed my info and thought I was done with it. The tip off is that while It was happening I would get signed out of LIVE and kicked to the dashboard because my account was being accessed by another XBOX. It happened again while I Was playing with a friend so a couple months later, so I immediately changed my account and password settings a third time to counteract it before something happened.

The worst part is that MS holds your credit card info hostage. You cant just take it down, you have to call MS support and request it to be taken down, and even then I was hassled by their department to leave it or told they cant do it because of "LIVE". So I just left it and cancelled the card on file.
 
Weird that they went for FIFA 13 points, with 14 out last week?

There's a lot of hackings involving FIFA because Ultimate Team coins sell for around ÂŁ10 per 100k on various sites around the web.

It's actually a decent way to make money if you can earn those coins in a legit way, through trading, buying low and selling high, or simply playing an awful lot.

EA/Sony/Microsoft need to make things a bit more secure.
 
Hope you get this sorted out & get your money back, i have never used a CC on Live, PSN or eSHOP, i would not either, i simply do not trust Sony, MS or Nintendo to look after my data i just use the scratch off cards for funding my consoles & i never keep a lot in there, i only put funds in if i am going to buy something, i probably have about ÂŁ15 in each account thats just left over credits though.

I have still not forgiven Sony for my data when they got hacked, ok everyone can get hacked but Sony lied to everyone for weeks over what had happened, i no longer have my real address tied to my PSN account either now.

Keep us all posted on how you get on.
Credit card information on 3DS and Wii U afaik are stored on the actual console behind PIN access. There's no global account system yet (and 3DS has no NNID), so the worst that could happen for your Wii U is that hackers could log into your Miiverse account on the browser. And yes, Nintendo is this far behind the rest.
 
Just on seeing the OP I should mention a friend noticed his account password had changed suddenly. His problem is he no longer has access to his log on email address (don't ask).

I'll tell him to contact Sony directly.

Edit: this happened within the last two days.
 
Well since the PSN hacks and many hacks I got on my old hotmail and MMO accounts, I decided to make unique passwords everywhere and write them down on a paper. Also, if available, i'm using smartphone activators or SMS codes as second layer. I'm gonna do a complete password change soon and rewrite them on a paper somewhere again.

My new Email account has been spam-less for a year now and I'm very careful about giving my email address.
 
Just on seeing the OP I should mention a friend noticed his account password had changed suddenly. His problem is he no longer has access to his log on email address (don't ask).

I'll tell him to contact Sony directly.

Edit: this happened within the last two days.

Can you change your sign in ID via the SEN site or do you have to call Sony?
 
These FIFA hacks have been a lot more rapid on Xbox 360, at least if previous thread on NeoGAF about it is anything to go by. I wouldnt get a Xbox One either if that is a concern.

I wouldn't touch FIFA with a 10-foot barge pole is the lesson to be learned. Even the demos open you up to password crackers for your EA.com password.
 
At this point I would not associate anything financial with a EA account.


In fact ive decided to open a new email for everything related to money and shopping online.
 
Is your credit card information stored on your PSN account, or is the credit card information stored locally (In a cookie.), so it'll only work if you log in from whatever computer you first used to write in the information on?

Storing the credit card information on the account should not be necessary at all in this case - I mean, you can't wait til you get home on your Playstation 3 or computer to buy a game?

In any case, it certainly shouldn't be the default -- a toggle in the options should be good enough, in my opinion.
 
This isnt a Sony thing, It Fifa and EA. These hacks happen, for the most part, on 360. Number one reason I dont touch Ultimate team.
 
This is why after some thought I'm not going PS4 next gen....

I honestly don't know why people trust and love Sony so much on this board. After all they were responsible for the biggest security breach this generation and PSN was down for 2 months...

So it's not the fact that your entire post history is about the 360 and 3DS... it's your lack of trust in their network, even though the 360 gets FIFA'd at an alarming rate?


Something doesn't add up here...
 
This is why after some thought I'm not going PS4 next gen....

I honestly don't know why people trust and love Sony so much on this board. After all they were responsible for the biggest security breach this generation and PSN was down for 2 months...

Honestly, in this day and age, unless you don't use the internet for anything you're going to end up getting an account compromised some day. Unless every site out there makes you use some sort of authenticator (which I know I don't want to have to do) it's just a matter of time before someone compromises your account. I can guarantee you that his PSN account being compromised was not because a hacker broke into Sony and got it from Sony, they've probably had his password for months now, and probably got it the same way they got the password to his Origin account

I do think they should block any logins from a weird IP, however. Google and ArenaNet do this in which they send you an email to confirm if it really is you. I think I've gotten like 4 emails from ArenaNet saying someone from China is trying to log in to my Guild Wars 2 account that I don't play anymore.
 
I think I've gotten like 4 emails from ArenaNet saying someone from China is trying to log in to my Guild Wars 2 account that I don't play anymore.

Those are probably phishing emails. I get them for Starcraft/Diablo 2/3 times a week. "Verify your account details or else we're shutting it down! (insert phishing/fake website login here)"

They get sent directly to my spam folder.
 
Those are probably phishing emails. I get them for Starcraft/Diablo 2/3 times a week. "Verify your account details or else we're shutting it down! (insert phishing/fake website login here)"

They get sent directly to my spam folder.

Well here's what they look like:

A log-in attempt from the following location is currently awaiting your authorization.

Address: 124.73.9.131
City: Hefei
Region: 01
Country: CN

This location is approximated based on information provided by your Internet Service Provider. If in doubt, deny the request and try again.

If you are certain this log-in attempt was not made by you, then someone else knows your log-in credentials and you should change your password immediately via Account Management.

For security purposes, we alert you each time your account is accessed from an unrecognized location. To authenticate this log-in attempt, please click the link below:

<link>

Need help or have questions about your Guild Wars account? Visit our support site: http://en.support.guildwars2.com/
Thanks!
--The ArenaNet Team

It doesn't look like a phishing email since it doesn't ask me to verify any account details, it wants me to only do something if I am indeed trying to log in from China.
 
Is your credit card information stored on your PSN account, or is the credit card information stored locally (In a cookie.), so it'll only work if you log in from whatever computer you first used to write in the information on?

Storing the credit card information on the account should not be necessary at all in this case - I mean, you can't wait til you get home on your Playstation 3 or computer to buy a game?

In any case, it certainly shouldn't be the default -- a toggle in the options should be good enough, in my opinion.

Details are stored online as far as I am aware, which is why you can buy stuff straight from the SEN web store. But yes, I would like to be able to buy stuff wherever I am, like pretty much any other online store these days.

The advantage being along with PS+ I can buy something on the web store and set it to download on any of my PS devices. When my PS3 turns on automatically to check for updates it then downloads and installs whatever I have bought, same for Vita. While others might be fine having to do this through the actual device, I think this is a real advantage as I don't have to wait to play the game when I get home.

Both new next-gen consoles will also have this functionality out of the box, we're moving to a more online world, details will continue to be stored in the "cloud" for access wherever you are. I'd much rather these companies sort out their security and educate users on being careful with such things as passwords than limit functionality. But sure, choices is always good, I don't have a problem with more options to keep ourselves protected, but not as long as one replaces the other.
 
Details are stored online as far as I am aware, which is why you can buy stuff straight from the SEN web store. But yes, I would like to be able to buy stuff wherever I am, like pretty much any other online store these days.

I can't remember how the web store is handled, but the information stored there is separate from the console stores. The console stores store the information on the system itself, so someone can't just add your account on their system and hope to spend all of your money.

Money stored in the wallet is a different situation altogether which is what happened to the OP.
 
This is why after some thought I'm not going PS4 next gen....

I honestly don't know why people trust and love Sony so much on this board. After all they were responsible for the biggest security breach this generation and PSN was down for 2 months...

dont wanna rain on your parade,but this happens everywhere,not just psn,im sure i have read more fifa hacks to people of xbox live than on psn
 
Is this quite common then? Just bought FIFA for the first time in years, and would want to hook it up to origin to transfer data to the PS4 version. But this makes me wary.

I could create a new origin account with different email as login, but it is already tied to my PSN - can you unlink them?
 
Figured I'd put this out there, see if anyone else copped the same: Noticed that a few hours ago, I received an email from Sony saying my password had successfully been changed, not unlike what I experienced with Origin a short while ago:
kYJ3g5R.png

(Tops work, Sony. If I didn't request a change, why give me a contact address after the fact?)

Two hours after, this:
wGyXhDe.png


Then a short time after, this:
K35yYee.png


I don't know that if I hadn't changed my password if I prevented any further purchases (not with $1.44 now left in my PSN wallet) but I'm damn glad I didn't have my credit card details associated with my account... otherwise I would've been fucked.

Anyone else had this happen recently (or ever)?

Edit: BTW I noticed that some extra consoles had been "authorised" on my account as well. I've gone and disabled everything associated with my account just to be safe. And yes, obviously I've raised a support case, but I'm not expecting much considering it's 1am and I couldn't contact any other support area other than the Australian one.

I got hacked like this also. Before getting hack I noticed I kept getting kicked off psn when I tried to play GTA5 (the only time I'd want to use a console at the moment), I felt something fishy was going on so I changed my password. Then a day later or so I couldn't log in, my password wasn't working. I couldn't understand how the new password was all of a sudden not working. Like you I found a confirmation that the password was changed after my old password change request so it was a different instance, and during a time I wasn't even at home and my PS3/pc wasn't even on (last week at around 3pm cst).

I have my PSN on a hotmail account and figured it got hacked and they tried requesting a new password via just the hotmail. I got my account back via sony live chat, and all my information was changed to some guy in New York (No wonder my birthday and name was wrong which prevented me from requesting a password change).

Now I use a hex password generator app and store different passwords on that. I'm going to change my PSN email from the hotmail account today. The Sony guy couldn't do it so I figured I was stuck on it.

Also I was getting random friend requests before the hack. I ignored them all but I looked at them. I thought maybe GTA5 was showing my PSN and somehow people were seeing my name. My PSN Flist is massacred now. Only 5 people on it remaining. When I was getting hacked and got my account back there was a lot of "Luosotwww, Ssoeisss, Nuwwrrr" type names on it, and they still send me friend requests. I always take my billing information off of my PSN after I buy something. Lately I have just been ordering PSN codes just to be safe. Good thing I did.

 
Totally unaware of the FIFA hacks on Xbox, I see.




I'm going back to PES after all of this, #northlondonfc
That's an issue with customer service reps giving out information that they shouldn't be giving, not a complete breach of network security. Hackers obtain partial information relating to an account through other website breaches, they call up customer service getting different representatives obtaining bits and pieces of information until they have enough information to get a customer service representative to reset the password on the account. Requires no access to the email address or the Xbox Live account. It's purely social engineering. Likely what happened with the OP's account here, as well. I'd recommend OP make a new email that isn't associated with anything else specifically for his PSN account.
 
Mostly hacks can be done via social engineering... no need for actual server hacking :(

I use a password manager to create unique 20+ length passwords to each service I use. People should get a really nice password manager to secure your passwords. I recommend Lastpass ( https://lastpass.com ) . it's free
 
After the PSN fiasco are there people that really still leave a CC or cash on their PSN account?

Since the worst case scenario would be having to cancel my current credit card which I only use for Amazon and PSN? Yeah, why not? I could understand if you don't want to do that if you use your credit card a lot though.

And like people before me said, CC information was secure.

(I didn't have a credit card yet when the PSN hack occurred though.)
 
Top Bottom