NES, SNES, N64, Gamecube, Wii
User avatar
bmoc
Next-Gen
 
Posts: 1452
Joined: Thu May 19, 2011 1:36 pm

Nintendo Account Breach April 2020

by bmoc Tue Apr 21, 2020 1:00 pm

Several people have recently had their Nintendo accounts compromised. I encourage everyone to enable two step authentication on your Nintendo account. Log into https://accounts.nintendo.com/ and click on "Sign-in and security settings". Nintendo will recommend the Google Authenticator app but Microsoft Authenticator works as well if you are already using that.

https://www.polygon.com/2020/4/21/21229 ... april-2020
User avatar
YoshiEgg25
Next-Gen
 
Posts: 4340
Joined: Tue Aug 24, 2010 10:26 pm
Location: Madison, WI

Re: Nintendo Account Breach April 2020

by YoshiEgg25 Tue Apr 21, 2020 5:33 pm

Yep, I had this happen to me a few days ago. I got an email from Nintendo that my account had been signed into from Germany and Belarus. Luckily I didn't have any card info stolen since I never keep that saved.
Gaming accomplishments:
Nibbler (marathon): 251,169,160 / Nibbler (one life): 5,263,360 (WR)
Donkey Kong: 423,100 [L12-1] (150th place as of 2019-01-15)
Super Smash Bros. (N64): Ranked top 5 in Wisconsin from Q1 2016 to Q2 2017
Shrek SuperSlam: won largest tournament in game's history (Shrekfest 2018)

Speedrun.com Profile (contains multiple WRs)
User avatar
Reprise
Next-Gen
 
Posts: 3628
Joined: Mon Mar 22, 2010 10:27 am
Location: Earth

Re: Nintendo Account Breach April 2020

by Reprise Thu Apr 23, 2020 5:12 am

Purely speculative, but a lot of people who had this happen to them say they had their Nintendo Network ID linked. If you do, it's possible to sign in with just the Network ID login details. So people are speculating a breach or vulnerability has occured with the old 3DS and Wii U Network ID system.

I really hope Nintendo are quick with their investigation and will communicate exactly what level of breach has occurred (as they are legally obligated to).

I didn't have any issues (yet...), but I do have my Nintendo Network ID linked to my account. I set up 2 step verification anyways and removed my card details.
Own: Sega Mega Drive, Sega Saturn, Sega Dreamcast, Playstation One, Playstation 2, Playstation 3, Playstation 4, PS Vita, Super Nintendo, Nintendo 64, Nintendo Gamecube, Nintendo Wii U, Nintendo 3DS, Nintendo Switch, OUYA.

My gaming blog: https://366gamestoplay.wordpress.com

PSN ID: Anesthetize666
Nintendo Switch ID: SW-8077-5145-0328
Twitter: https://twitter.com/366GamesToPlay
User avatar
Reprise
Next-Gen
 
Posts: 3628
Joined: Mon Mar 22, 2010 10:27 am
Location: Earth

Re: Nintendo Account Breach April 2020

by Reprise Fri Apr 24, 2020 11:10 am

So there we go. Nintendo confirms it is to do with the Nintendo Network ID. What isn't clear is if accounts were hacked and compromised or if they were accessed by people using login information from previous breaches.

That's what I hate about all these breaches, it's never clear if it's a hack and raw, unencrypted passwords were actually obtained and used or if it's just people using old leaked info, since Nintendo Network IDs have been around for like a decade so people might have set them up years ago with an old compromised password and forgotten all about it.

Come to think of it though, don't you get a unique code to login with a Nintendo Network ID? Hmm I don't like this.

https://www.nintendolife.com/news/2020/ ... ly_at_risk
Own: Sega Mega Drive, Sega Saturn, Sega Dreamcast, Playstation One, Playstation 2, Playstation 3, Playstation 4, PS Vita, Super Nintendo, Nintendo 64, Nintendo Gamecube, Nintendo Wii U, Nintendo 3DS, Nintendo Switch, OUYA.

My gaming blog: https://366gamestoplay.wordpress.com

PSN ID: Anesthetize666
Nintendo Switch ID: SW-8077-5145-0328
Twitter: https://twitter.com/366GamesToPlay
User avatar
marurun
Moderator
 
Posts: 9960
Joined: Sat May 06, 2006 8:51 am
Location: Cleveland, OH

Re: Nintendo Account Breach April 2020

by marurun Fri Apr 24, 2020 11:28 am

Ars Technica posited it was likely credential stuffing against those older accounts.
B/S/T thread
My Classic Games Collection
My Steam Profile
The PC Engine Software Bible Forum, with Shoutbox chat - the new Internet home for PC Engine fandom.
User avatar
prfsnl_gmr
Next-Gen
 
Posts: 10808
Joined: Mon Jun 01, 2009 10:26 pm
Location: Charlotte, North Carolina

Re: Nintendo Account Breach April 2020

by prfsnl_gmr Fri Apr 24, 2020 11:37 am

I logged out of my account from all devices, unlinked my credit card, changed my password, and set up two-factor authentication. Hopefully, that should do it...
User avatar
Reprise
Next-Gen
 
Posts: 3628
Joined: Mon Mar 22, 2010 10:27 am
Location: Earth

Re: Nintendo Account Breach April 2020

by Reprise Fri Apr 24, 2020 11:39 am

marurun wrote:Ars Technica posited it was likely credential stuffing against those older accounts.


If it's credential stuffing then it's not technically a hack, is it? It's just confusing when articles all open with the word "hack".
Own: Sega Mega Drive, Sega Saturn, Sega Dreamcast, Playstation One, Playstation 2, Playstation 3, Playstation 4, PS Vita, Super Nintendo, Nintendo 64, Nintendo Gamecube, Nintendo Wii U, Nintendo 3DS, Nintendo Switch, OUYA.

My gaming blog: https://366gamestoplay.wordpress.com

PSN ID: Anesthetize666
Nintendo Switch ID: SW-8077-5145-0328
Twitter: https://twitter.com/366GamesToPlay
User avatar
marurun
Moderator
 
Posts: 9960
Joined: Sat May 06, 2006 8:51 am
Location: Cleveland, OH

Re: Nintendo Account Breach April 2020

by marurun Fri Apr 24, 2020 11:41 am

Reprise wrote:
marurun wrote:Ars Technica posited it was likely credential stuffing against those older accounts.


If it's credential stuffing then it's not technically a hack, is it? It's just confusing when articles all open with the word "hack".


Hack has become, correctly or not, shorthand for unauthorized access or abuse.
B/S/T thread
My Classic Games Collection
My Steam Profile
The PC Engine Software Bible Forum, with Shoutbox chat - the new Internet home for PC Engine fandom.
User avatar
Reprise
Next-Gen
 
Posts: 3628
Joined: Mon Mar 22, 2010 10:27 am
Location: Earth

Re: Nintendo Account Breach April 2020

by Reprise Fri Apr 24, 2020 11:45 am

marurun wrote:
Reprise wrote:
marurun wrote:Ars Technica posited it was likely credential stuffing against those older accounts.


If it's credential stuffing then it's not technically a hack, is it? It's just confusing when articles all open with the word "hack".


Hack has become, correctly or not, shorthand for unauthorized access or abuse.


Yeah, that's true I guess. I just wish companies (although having read more I can see Nintendo have said there is no evidence any of their servers or databases have been hacked) and journalists were clearer on what has happened and whether personal information has been accessed.
Own: Sega Mega Drive, Sega Saturn, Sega Dreamcast, Playstation One, Playstation 2, Playstation 3, Playstation 4, PS Vita, Super Nintendo, Nintendo 64, Nintendo Gamecube, Nintendo Wii U, Nintendo 3DS, Nintendo Switch, OUYA.

My gaming blog: https://366gamestoplay.wordpress.com

PSN ID: Anesthetize666
Nintendo Switch ID: SW-8077-5145-0328
Twitter: https://twitter.com/366GamesToPlay
User avatar
marurun
Moderator
 
Posts: 9960
Joined: Sat May 06, 2006 8:51 am
Location: Cleveland, OH

Re: Nintendo Account Breach April 2020

by marurun Fri Apr 24, 2020 11:53 am

Reprise wrote:
marurun wrote:
Reprise wrote:
If it's credential stuffing then it's not technically a hack, is it? It's just confusing when articles all open with the word "hack".


Hack has become, correctly or not, shorthand for unauthorized access or abuse.


Yeah, that's true I guess. I just wish companies (although having read more I can see Nintendo have said there is no evidence any of their servers or databases have been hacked) and journalists were clearer on what has happened and whether personal information has been accessed.


Try this article, then. Ars Technica is much better about being clear in their reporting than other outlets. In fact, my only complaint about Ars is that they are owned by Advance Publications (who just recently decimated the Cleveland Plain Dealer newsroom in order to brutally kill the union).

https://arstechnica.com/gaming/2020/04/ ... e-of-ours/
B/S/T thread
My Classic Games Collection
My Steam Profile
The PC Engine Software Bible Forum, with Shoutbox chat - the new Internet home for PC Engine fandom.
Return to Nintendo

Who is online

Users browsing this forum: No registered users and 7 guests