Critical PlayStation Security Vulnerability Makes It Incredibly Easy To Hack Accounts Even With 2FA

Expert Verified By

Story Highlight
  • A journalist has shared how his account was hacked twice in a few hours through a simple conversation with PlayStation Support.
  • Since the agents only ask for a username and a past invoice transaction number, bypassing 2FA and passkeys is incredibly easy.
  • PlayStation must address this vulnerability as quickly as possible.

PlayStation’s infamous hack happened nearly two decades ago, and since then, the gaming giant has certainly stepped up its network security. Today, millions use the PS4 and PS5 consoles, spending thousands of dollars on digital game purchases, DLC, and more.

However, a new report highlights that users should remain vigilant against potential attacks on PSN accounts. Indeed, a new report has discovered that Sony’s security measures make it all too easy for hackers to hijack accounts, even when 2FA is enabled.

Why it matters: This discovery raises questions regarding the implications of Sony’s poor security measures.

psn gift card
PSN Is Home To Over 120 Million Monthly Active Users.

According to journalist Nicolas Lellouche, his PlayStation account was hacked twice in a span of mere hours despite having security measures like 2 Factor Authorization in place and a passkey.

When the account was initially hacked, around $10 was charged on the user’s PayPal account to change the PSN ID. Of course, the hacker had also altered the passkey that was already in place.

After contacting PlayStation support, Nicolas Lellouche regained his account, and the process was surprisingly easy. He only had to share his PSN username and a transaction number from a past invoice.

This is where the problem lay, however, and even though the account was temporarily restored, it was hacked again within an hour. The journalist was then able to contact the hacker by messaging him on his PlayStation account, who confirmed how the hack was executed.

As per the hacker, an old invoice transaction number was the key to the breach. Nicolas Lellouche had previously publicly posted his PlayStation transactions on Twitter, which allowed the hacker to share the account’s username and an old transaction number with PlayStation support to regain access to the account.

The big vulnerability, therefore, lies within the process of PlayStation’s verification itself. Customer support clearly does a poor job of verifying the individual accessing an account, so there is no real way of 100% securing an account in such an instance.

PSN Down Over 18 Hours
PSN Is No Stranger To Outages And Vulnerabilities.

The bad news is that Nicolas Lellouche still does not have access to his account yet. Being a physical games buyer, the journalist was fortunate that his account wasn’t valued as highly as some others.

Digital gaming is bigger than ever today, so the damage could have been a lot worse.

Needless to say, Sony must immediately look into the matter and implement stricter verification. What do you think about this entire incident? Let’s discuss in the comments and on the Tech4Gamers Forums.

Was our article helpful? 👨‍💻

Thank you! Please share your positive feedback. 🔋

How could we improve this post? Please Help us. 😔

Gear Up For Latest News

Get exclusive gaming & tech news before it drops. Sign up today!

Join Our Community

Still having issues? Join the Tech4Gamers Forum for expert help and community support!

Latest News

Join Our Community

104,000FansLike
32,122FollowersFollow

Trending

PlayStation Used Its New AI Animation Tool To Remaster Horizon Zero Dawn

SIE CEO has revealed that PlayStation used its AI animation tool to remaster Horizon Zero Dawn, with more studios adopting it as well.

Guerilla Co-Founder Is Making A New Game Engine With AI-Integration To Rival Unreal Engine

Former Epic dev Arjan Brussee has revealed that he is building a new game engine that can rival Unreal Engine thanks to native AI agents.

New Resident Evil Requiem DLC Faces Mixed Reception From Players

The new Leon Must Die Forever mode has seen mixed reception by players online, with many fans left wishing for the classic Mercenaries mode.

Despite Laying Off 1,000 Devs, Epic Says AI Isn’t Killing Jobs And Is Making Them More Efficient

An Epic Games dev has stated that even though the company recently fired 1,000 employees, it isn't using AI to make jobs redundant.

Sony Now Actively Inviting PS4 Players To Upgrade To PS5 For GTA 6 Release

Sony has started a new marketing campaign in an attempt to convince PS4 users to finally switch over to PS5 to prepare for GTA 6 release.