• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

My PSN Account Was Hacked!

Come on guys and girls, stop leaving your bank details on unsecured sites. Use PSN/Live/Eshop codes for purchases.
 
My girlfriend has been receiving emails asking her to confirm the change of her password on PSN. We didn't even remember she had an account !
She never put her credit card details on it though but still, it's worrying.

Have you checked to see if they're phishing emails?
 
Have you ever shared your login details with anyone or typed in your login details unencrypted somewhere?

Or maybe keylogged from an infected device where you entered it, i wonder how these hacks happen.

Sony should do an option where every 6 months it prompts the user to change the password.
 
Don't have your financials (credit card, Paypal, etc...) tied to PSN. Yes Sony needs two-factor authentication but this problem is so frequent, you only have yourself to blame if you still choose to do it anyway.
 
OP literally said that his password was complex and exclusive to his PSN account... He doesn't use it anywhere else

Complexity doesn't matter but if it's truly a unique password then Sony has been comprised and this is a huge issue. We could really use some press trying to get Sony to be straightforward about security because this is ridiculous.
 
Sorry to hear OP.

These topics always scare me but sometimes I'm left wondering if we get the whole story (not necessarily aimed at you OP). I just don't get how an account with a unique password gets compromised unless that password is saved somewhere.

It's always either because of sharing details with other people (game sharing), same password used elsewhere, a weak password (8 characters of any complexity is useless) or because of phishing. Sony hasn't been compromised.

Also:

Also if anyone hasn't already, up vote this: http://share.blog.us.playstation.com/ideas/2014/05/21/two-step-verification/

It's currently languishing on page 7.

Do it people.
 
A complex password is no help unfortunately (although it doesn't hurt). All passwords are cached somewhere on the server and hackers gain access to that cache to "extract" batches of passwords from them. They then use simple macro programs to test which passwords actually work. Don't use anything but prepaid cards to make purchases, change your password as regularly as possible, and deactive your devices via web once every 6 months (so that the hacker cannot deactive your devices remotely). That's all we can do until Sony enables 2-step verification.

This will not cause any issues with my saves/licenses etc etc on my hardware?
 
Sony's reaction:

h6a3a1d8f-jpeg.1060027
 
Is it possible for sony to upgrade this awful system to a new one? like add all the features that xbox live has or make a new system that would absorb the current PSN?

I cant believe its not possible to change regions or username in 2016
 
Had my account hacked last month. Had my debit card info on my account and they spent ÂŁ100.

It was a massive pain in the arse getting it sorted. Sony acknowledged that my account had been compromised and that the purchases were made on a console that wasn't mine.
Still took them weeks to get back to me about a refund. But by that point I'd already contacted my bank.
Sony really need to do something, this seems to happen way too often.
 
Complexity doesn't matter but if it's truly a unique password then Sony has been comprised and this is a huge issue.

Well, it's not necessarily certain that Sony was compromised. It could also be a keylogger or someone using social engineering to get a Sony rep to reset the password.

Keyloggers can be diagnosed by the enduser but all of the other causes have to be admitted by Sony and they *really* don't like talking about this.
 
Well, it's not necessarily certain that Sony was compromised. It could also be a keylogger or someone using social engineering to get a Sony rep to reset the password.

Surely if the password was reset it would send an email to the OP asking for confirmation?

I was certain Sony asked you to click a link to confirm password reset?
 
Have you ever shared your login details with anyone or typed in your login details unencrypted somewhere?

Or maybe keylogged from an infected device where you entered it, i wonder how these hacks happen.

Sony should do an option where every 6 months it prompts the user to change the password.

Forced password changes make people less secure, not more. They tend to start using simpler passwords, so they can remember them.
 
Back during the PSN hack of 2011 I decided I would never store payment details online as much as possible. I've used vouchers for most things, PayPal for online retail and in the case where Cards are required, I've never saved the info and removed it straight away. I think tbe only places that have my card are Amazon and Paypal and both have 2 factor authentication.

Sony really need to get it ready. It's annoying they don't have it.
 
Is it possible for sony to upgrade this awful system to a new one? like add all the features that xbox live has or make a new system that would absorb the current PSN?

I cant believe its not possible to change regions or username in 2016

PSN is held together with duct tape.
 
I swear we're getting more and more of these on here now :(

Good luck mate
that is exactly the same thing i thought when i saw the thread. i'm like, wait, is this a bump from a few days ago or a new one?

not a good look, yo. not at all. if this starts to become public knowledge then it could seriously hurt the playstation brand
 
Well this was all easier than expected. Spoke to the rep who worked quickly on getting everything done with no hesitation. I guess he changed the account email back to mines and allowed me to reset my password as well as refunded me on the money the hacker spent. All the other threads show that it's a hassle when talking to reps luckily it wasn't today.
 
Well this was all easier than expected. Spoke to the rep who worked quickly on getting everything done with no hesitation. I guess he changed the account email back to mines and allowed me to reset my password as well as refunded me on the money the hacker spent. All the other threads show that it's a hassle when talking to reps luckily it wasn't today.

well hopefully now you dont get banned for chargeback or some dumb shit because the rep was incompetent and didnt know about it
 
Well this was all easier than expected. Spoke to the rep who worked quickly on getting everything done with no hesitation. I guess he changed the account email back to mines and allowed me to reset my password as well as refunded me on the money the hacker spent. All the other threads show that it's a hassle when talking to reps luckily it wasn't today.

Were you calm and collected when talking to the Sony representatives?
 
Well this was all easier than expected. Spoke to the rep who worked quickly on getting everything done with no hesitation. I guess he changed the account email back to mines and allowed me to reset my password as well as refunded me on the money the hacker spent. All the other threads show that it's a hassle when talking to reps luckily it wasn't today.

You didn't do a chargeback first, which a lot of other people do, which tends to cause issues when talking with the reps.

Did you get any emails about an email change to your account? Those do (are supposed to) get sent out if someone changes the email on your PSN.

well hopefully now you dont get banned for chargeback or some dumb shit because the rep was incompetent and didnt know about it

The chargeback would be bad if he had Paypal do the chargeback. If Sony did it, it should be fine.
 
I just tweeted Jim Sterling this thread, maybe he'll bring some attention to this. Can't believe how often this has been happening. Sony needs to sort their shit out.
 
Do not trust Sony with your banking information. They have demonstrated for years that they do not take security seriously, and they do not care if you get upset or ripped off. There is little recourse because it's not like you can dispute the charges with your bank without getting your account banned. You have to just hope they will be cooperative, which they are not paid to do. I only buy prepaid codes, as much as I need. I get 5 points per dollar on Amazon, too.
 
A new thread every day yet some people on here blame the users.

Isn't it better to have a megathread? So we know who has been affected.
 
Good luck. Sony REALLY needs two step verification. I would highly recommend everyone delink their Paypal accounts and credit cards in the meantime. Just buy point cards, its so much safer. Its what I've been doing since the major PSN hack of 2011 and its served me well so far.
 
Well this was all easier than expected. Spoke to the rep who worked quickly on getting everything done with no hesitation. I guess he changed the account email back to mines and allowed me to reset my password as well as refunded me on the money the hacker spent. All the other threads show that it's a hassle when talking to reps luckily it wasn't today.
Check you activated hardware too. Manually deactivate/activate your hardware just in case.
 
people get hacked every single day on every service ever made, especially massive ones like PSN, XBL and Steam.

not sure why people are surprised

even if we get one "i'm hacked" thread every day that's still nothing.
 
There's like a thread on this weekly. And listening to gaming podcasts, it happens a lot.

Sony's lack of 2FA is embarrassing at this point.

I had someone gain access to my account, buy overwatch, and Sony only begrudgingly offered a refund as a "one time courtesy". This is after a decade or so of having a pan account, spending thousands of dollars on games, and never once having an issue.

It was infuriating. I wish the collective nerd outrage of the internet could be focused on pressuring Sony to offer 2FA. :(
 
people get hacked every single day on every service ever made, especially massive ones like PSN, XBL and Steam.

not sure why people are surprised

The bigger surprise is at Sony not having 2 step authentication when nearly every other respectable service does.
 
people get hacked every single day on every service ever made, especially massive ones like PSN, XBL and Steam.

not sure why people are surprised

How many steam or Xbox live hacking threads have we seen in the last month?

And yes it is something. Stop trying to downplay this.
 
What can hackers even get with someone elses PSN account? Can they buy credit and send it to a different account?

That's a good question, hey OP, what exactly did they spend $75 on?

Everyone keeps making these threads saying they've been hacked, and money spent, but we don't usually hear what exactly the money is spent on.
 
Do not trust Sony with your banking information. They have demonstrated for years that they do not take security seriously, and they do not care if you get upset or ripped off. There is little recourse because it's not like you can dispute the charges with your bank without getting your account banned. You have to just hope they will be cooperative, which they are not paid to do. I only buy prepaid codes, as much as I need. I get 5 points per dollar on Amazon, too.
How do you know that? Did you work for the PSN customer service? Honest question. Saying that they arent payed to be cooperative isnt true, otherwise the OP wouldnt have had his case solved this fast. Problem with customer service in general is that some persons might be more helpful than others based on daily mood etc..
 
people get hacked every single day on every service ever made, especially massive ones like PSN, XBL and Steam.

not sure why people are surprised

Really? Where are the Steam/ Battle.net/ Origin/ GOG/ live equivalent of these threads then?
 
Same thing just happened this morning to me as well though that is because I've been using an old password and never bothered to change it.

Just got my account back and was advised to not dispute the charges through PayPal as it could get my account banned, which i find ridiculous as hell but they are working on getting me a refund so let's hope that goes through.
 
That's a good question, hey OP, what exactly did they spend $75 on?

Everyone keeps making these threads saying they've been hacked, and money spent, but we don't usually hear what exactly the money is spent on.

Some game currency probably. FIFA points, MMO gold or something. This is then traded in game and then sold for real money on a "gold farmers site".

Think

Gain access to your account, buy coins, send coins to their own characters, sell said coins on for real money. Depending on the game they might need to do some in game conversions along the way, buts its relatively easy in most games to filter currency to a buying player.

There's no need to spend hours farming gold these days when MTs are rampant in games and they can just steal accounts and buy the currency upfront, and then sell it on.
 
I had someone gain access to my account, buy overwatch, and Sony only begrudgingly offered a refund as a "one time courtesy". This is after a decade or so of having a pan account, spending thousands of dollars on games, and never once having an issue.

It was infuriating. I wish the collective nerd outrage of the internet could be focused on pressuring Sony to offer 2FA. :(

That's what I'm hoping for too. But NMS seems to be more important at this moment. :P

Has there been any word from Sony, about improving security?
 
That's a good question, hey OP, what exactly did they spend $75 on?

Everyone keeps making these threads saying they've been hacked, and money spent, but we don't usually hear what exactly the money is spent on.

Yeah we do, they buy neve winter or Fifa ultimate team points, buy cards, transfer to their account, sell them for money
 
Were you calm and collected when talking to the Sony representatives?

I'm always calm and collected when speaking to representatives. Easiest way to get things done. Expressing anger towards reps have never been helpful from what I've seen.

You didn't do a chargeback first, which a lot of other people do, which tends to cause issues when talking with the reps.

Did you get any emails about an email change to your account? Those do (are supposed to) get sent out if someone changes the email on your PSN.



The chargeback would be bad if he had Paypal do the chargeback. If Sony did it, it should be fine.

Yes that email is what prompted me to run to my PC along with the emails from paypal saying they charged my account.
 
maybe ps4 os 4.0 will enable 2fa

I hope so, or at least whatever the next firmware version is. The sooner this is done, the better.

Do you use a password manager OP?

Also if anyone hasn't already, up vote this: http://share.blog.us.playstation.com/ideas/2014/05/21/two-step-verification/

It's currently languishing on page 7.

Done.

It would be good for anyone here who is a PSN member to do this. It should only take a few seconds of your time. While we can't be sure this will speed up or otherwise influence the process, at least it is on Sony's own site, so perhaps it will raise awareness of the issue within their organization.
 
People need to unlink their payment options from PSN, so no CC and no Paypal until Sony put in 2FA. Yes buying cards or manually input your payment details isn't as easy as just click and buy, but dealing with refunds on PSN is even more of a hassle.

So

1. Use a unique password
2. Password with minimal 10 character length
3. Either a random string of characters or a longer passphrase
4. Unlink payment details from your PSN account atleast until 2FA
 
A complex password is no help unfortunately (although it doesn't hurt). All passwords are cached somewhere on the server and hackers gain access to that cache to "extract" batches of passwords from them. They then use simple macro programs to test which passwords actually work. Don't use anything but prepaid cards to make purchases, change your password as regularly as possible, and deactive your devices via web once every 6 months (so that the hacker cannot deactive your devices remotely). That's all we can do until Sony enables 2-step verification.

I believe if you enter your CC information once it'll be stored in the server so "removing your CC Information from the system" is useless in case of a server hack.

Best solution is prepaid card with small amount. For new accounts/new customers anyway.
 
Top Bottom