PSA: Possible Data Breach for Nintendo Accounts

There's have been reports of suspicious attempted login for Nintendo Switch owners and some purchases of Fortnite V-bucks without authorisation.
Nintendo recommends removing payment details (PayPal and credit cards) and enable two-factor authorisation.
Also it is recommended to check your login history to see if any unauthorised logins have been made.

Source

Related Stores

Nintendo
Nintendo

Comments

  • +4

    I've checked mine and no suspicious logins were made but I thought I'd warn everyone here especially those with multiple accounts across several regions

  • +1

    Does seem to be a wider issue, but no strange logins on my account.

    Interesting that it seems to be Russian and Indian logins.

  • +4

    Yep. My account was breached late last month. Multiple logins one morning from Chile and the US. They were then able to link my account to their switch and purchased $150 worth of V bucks. Paypal basically told me bad luck but Nintendo were quick to refund the amount back to me after I contacted them.

    I'd definitely recommend removing any linked credit cards or PayPal accounts and enabling 2fa.

    • Can those V bucks be onsold online?

  • +2

    Thanks for the heads up!

  • +3

    TO REMOVE CC AND PAYPAL, TO GO Shop Menu

  • +3

    Should also note you can use Authy for the 2FA code
    you do not need to use the Google one that Nintendo tells you to download

    • +2

      If it's a normal Google Authenticator code this will also work in 1Password

    • Yeah I clicked the link it created and it opened in my Microsoft Authenticator , works just the same.

  • +2

    Mine was hacked last week too, the person bought $200 worth of Fortnite cards. Nintendo actually alerted me, and refunded me the money pretty quickly

  • +1

    I read on reddit the hacks might be coming via old NNID some how.

    https://old.reddit.com/r/NintendoSwitch/comments/g63glk/lega…

    • I have an old NNID, didn’t affect me

    • Looks like Nintendo has confirmed it was through NNID accounts
      source

      • They say no databases or servers were comromised but personal data like birth dates and passwords/hash was stolen. I wonder if Nintendo accidentally let old URLs or IPs lapse?

Login or Join to leave a comment