Critical PlayStation Security Vulnerability Makes It Incredibly Easy To Hack Accounts Even With 2FA

Expert Verified By

Story Highlight
  • A journalist has shared how his account was hacked twice in a few hours through a simple conversation with PlayStation Support.
  • Since the agents only ask for a username and a past invoice transaction number, bypassing 2FA and passkeys is incredibly easy.
  • PlayStation must address this vulnerability as quickly as possible.

PlayStation’s infamous hack happened nearly two decades ago, and since then, the gaming giant has certainly stepped up its network security. Today, millions use the PS4 and PS5 consoles, spending thousands of dollars on digital game purchases, DLC, and more.

However, a new report highlights that users should remain vigilant against potential attacks on PSN accounts. Indeed, a new report has discovered that Sony’s security measures make it all too easy for hackers to hijack accounts, even when 2FA is enabled.

Why it matters: This discovery raises questions regarding the implications of Sony’s poor security measures.

psn gift card
PSN Is Home To Over 120 Million Monthly Active Users.

According to journalist Nicolas Lellouche, his PlayStation account was hacked twice in a span of mere hours despite having security measures like 2 Factor Authorization in place and a passkey.

When the account was initially hacked, around $10 was charged on the user’s PayPal account to change the PSN ID. Of course, the hacker had also altered the passkey that was already in place.

After contacting PlayStation support, Nicolas Lellouche regained his account, and the process was surprisingly easy. He only had to share his PSN username and a transaction number from a past invoice.

This is where the problem lay, however, and even though the account was temporarily restored, it was hacked again within an hour. The journalist was then able to contact the hacker by messaging him on his PlayStation account, who confirmed how the hack was executed.

As per the hacker, an old invoice transaction number was the key to the breach. Nicolas Lellouche had previously publicly posted his PlayStation transactions on Twitter, which allowed the hacker to share the account’s username and an old transaction number with PlayStation support to regain access to the account.

The big vulnerability, therefore, lies within the process of PlayStation’s verification itself. Customer support clearly does a poor job of verifying the individual accessing an account, so there is no real way of 100% securing an account in such an instance.

PSN Down Over 18 Hours
PSN Is No Stranger To Outages And Vulnerabilities.

The bad news is that Nicolas Lellouche still does not have access to his account yet. Being a physical games buyer, the journalist was fortunate that his account wasn’t valued as highly as some others.

Digital gaming is bigger than ever today, so the damage could have been a lot worse.

Needless to say, Sony must immediately look into the matter and implement stricter verification. What do you think about this entire incident? Let’s discuss in the comments and on the Tech4Gamers Forums.

Was our article helpful? 👨‍💻

Thank you! Please share your positive feedback. 🔋

How could we improve this post? Please Help us. 😔

Gear Up For Latest News

Get exclusive gaming & tech news before it drops. Sign up today!

Join Our Community

Still having issues? Join the Tech4Gamers Forum for expert help and community support!

Latest News

Join Our Community

104,000FansLike
32,122FollowersFollow

Trending

Detroit: Become Human Reaches Peak Player Count Almost a Decade After Launch

Detroit: Become Human reached its highest player count ever on Steam, 8 years after the game's initial launch.

Larian Says It Won’t Use Gen AI For Divinity Art, But Doesn’t Rule Out Using The Tech For Development

Larian CEO has confirmed that the Divinity concept art won't be made using gen AI; however, they will explore it to expedite development.

In a Volatile Memory Market, ASRock’s Dual DDR4/DDR5 Board Just Makes Sense

In an era where RAM prices have soared beyond reason, ASRock's H610M offers both DDR5/DDR4 slots, highlighting a customer-first approach.

Upcoming Xbox Developer Direct Will Feature A Currently Unannounced 4th Game

A reliable insider suggests that Xbox has an unannounced 4th game announcement at the Developer Direct, which is set for Januray 22, 2026.

Crimson Desert’s World Will Be Twice As Big As Skyrim And RDR 2’s Map

Pearl Abyss revealed that Crimson Desert's open world will be twice as big as Skyrim's and will be even bigger than Red Dead Redemption 2.