Suspicious login attempts begin to plague Switch owners, Nintendo to investigate

EVMGrbqUYAAz7Ax.jpg

There's something concerning going on, as Nintendo Switch owners are reporting that they're seeing suspicious attempted log-ins for their account. Many users are sharing that they've either received emails from Nintendo with notices of log-ins from new devices, or even some that say their saved payment information was used to purchase V-bucks in Fortnite without their authorization. While Nintendo hasn't confirmed or denied as to whether or not there was a data breach or if there's a problem unfolding, it would be wise to make sure your account is secured. You can do so by resetting your password, checking out if there's been an unauthorized log-in attempt by looking at your history, removing your linked PayPal or Credit Card accounts, or turning 2-Step Verification on for your Switch account, which Nintendo themselves recommended just last week.

Nintendo is now aware of the problem and is "investigating the situation". They again recommend that users turn on 2FA.

EDIT: One of our users is conducting a poll to see who has been affected. You can fill it out here.
 

Gamemaster1379

Well-Known Member
Member
Joined
May 5, 2008
Messages
839
Trophies
1
Age
29
Location
United States
Website
1379tech.110mb.com
XP
2,276
Country
United States
i think nintendo has been hacked far worse than we relised i would run an AV scan for Keyloggers on your pc's if randomly generated passwords are being cracked that easily i suspect more is in play
I have anti-viruses in place. Furthermore, a keylogger would not be able to capture a password generator generating something I'm not keying in. By how the password manager works, I wouldn't be copying to clipboard either with auto-fill, so even a compromised clipboard malware wouldn't run the risk of this happening.

I also have no other services with suspicious login activity. I suspect Nintendo's actual infrastructure is compromised and hackers are likely logging in through some session authentication exploit, bypassing the need of passwords entirely.
 

DarkFlare69

Well-Known Member
Member
Joined
Dec 8, 2014
Messages
5,147
Trophies
2
Location
Chicago
XP
4,751
Country
United States
One of my old Nintendo accounts was accessed by someone in Russia yesterday. This is definitely a data breach on Nintendo's part. I use 18-24 character, randomly generated complex passwords for all my accounts, and this one was no exception. This password is impossible to bruteforce and not shared with any other login anywhere.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
thanks for the heads up, @Chary . I changed my password and enabled two-step verification. I didn't have my credit card info stored after what happened with psn. I guess it would be easy for a good hacker to get through both a password and two-step verification, but like most thieves, they're probably going to go after the easy targets.
 

BiggieCheese

Well-Known Member
Member
Joined
Oct 29, 2017
Messages
124
Trophies
0
XP
1,256
Country
United States
Yeah I read about this the other day, nothing out of the ordinary on my end but I still set up 2FA via Authy as a precaution, also unlinked my Nintendo Network ID in case the breach is on that end.
 

DarkFlare69

Well-Known Member
Member
Joined
Dec 8, 2014
Messages
5,147
Trophies
2
Location
Chicago
XP
4,751
Country
United States
This happened to me twice today from Singapore. The first time I changed my password... a few hours later it happened again. I guess I need to use two-step.
If that's the case, then that means the security breach is still ongoing and there's not just a single database dump like what happens normally. This isn't good for anyone.

EDIT: To keep yourself safe, it's probably best to make sure 2FA is always enabled even if your password is very secure and complex. Password strength probably doesn't matter at this point since it's clear they're not bruteforcing.
 
Last edited by DarkFlare69,

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
my nso is still tied to paypal. do you guys think I should change my paypal password? I can't remember how it works on the switch, but does it ask for your email and password, then saves it if you want to?
 

Xzi

Time to fly, 621
Member
Joined
Dec 26, 2013
Messages
17,785
Trophies
3
Location
The Lands Between
Website
gbatemp.net
XP
8,689
Country
United States
same here. I had no suspicious activity, but I took precautions just in case. it kinda pisses me off that nintendo would be silent about it. I think sony was that way too until it blew up in their face.
To be fair, I don't think this is particularly surprising or unusual. I doubt it's some new hacking method or anything like that, it's just that far more people are bored at home, and most passwords are easy enough to brute force. Thus it's a good idea to use 2FA wherever it's offered.
 

my2k2zx2

Well-Known Member
Member
Joined
Jun 5, 2008
Messages
115
Trophies
1
XP
1,586
Country
United States
Mine was accessed on April 13. I did not have any saved payment methods. I have no idea what my old password was but I do now that I've done a reset.
 

GerbilSoft

Well-Known Member
Member
Joined
Mar 8, 2012
Messages
2,395
Trophies
2
Age
35
XP
4,269
Country
United States
As a reminder, if you have a Nintendo Network ID linked to your Nintendo Account, it is possible to log into the Nintendo Account using the NNID password. Annoyingly, the only way to change the NNID password is through a linked 3DS or Wii U.

Note that enabling 2FA on your Nintendo Account will also prompt for the 2FA code if logging in using the NNID password on the web interface. (On 3DS and Wii U, it won't, but an NNID can only be used on one 3DS and one Wii U at a time.)
 
  • Like
Reactions: HarveyHouston

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • SylverReZ @ SylverReZ:
    @mthrnite, Cheetah Girls, the sequel to Action 52's Cheetah Men.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Pokemon Black I played that one a lot
  • K3Nv2 @ K3Nv2:
    Honestly never messed with Pokémon on ds much
  • mthrnite @ mthrnite:
    I played pokemon once, was bored, never tried again
  • Psionic Roshambo @ Psionic Roshambo:
    Oh Dragon Quest IX
  • K3Nv2 @ K3Nv2:
    Spent like 5 hours on switch one never touched it again
  • Psionic Roshambo @ Psionic Roshambo:
    Sentinel of the stary skies
  • K3Nv2 @ K3Nv2:
    Ds is 20 years old this year
  • Psionic Roshambo @ Psionic Roshambo:
    So MJ no longer wants to play with it?
  • K3Nv2 @ K3Nv2:
    He put it down when the 3ds came out
  • SylverReZ @ SylverReZ:
    @K3Nv2, RIP Felix does great videos on the PS3 yellow-light-of-death.
  • Jayro @ Jayro:
    Eventhough the New 3DS XL is more powerful, I still feel like the DS Lite was a more polished system. It's a real shame that it never got an XL variant keeping the GBA slot. You'd have to go on AliExpress and buy an ML shell to give a DS phat the unofficial "DS Lite" treatment, and that's the best we'll ever get I'm afraid.
    +1
  • Jayro @ Jayro:
    The phat model had amazingly loud speakers tho.
    +1
  • SylverReZ @ SylverReZ:
    @Jayro, I don't see whats so special about the DS ML, its just a DS lite in a phat shell. At least the phat model had louder speakers, whereas the lite has a much better screen.
    +1
  • SylverReZ @ SylverReZ:
    They probably said "Hey, why not we combine the two together and make a 'new' DS to sell".
  • Veho @ Veho:
    It's a DS Lite in a slightly bigger DS Lite shell.
    +1
  • Veho @ Veho:
    It's not a Nintendo / iQue official product, it's a 3rd party custom.
    +1
  • Veho @ Veho:
    Nothing special about it other than it's more comfortable than the Lite
    for people with beefy hands.
    +1
  • Jayro @ Jayro:
    I have yaoi anime hands, very lorge but slender.
  • Jayro @ Jayro:
    I'm Slenderman.
  • Veho @ Veho:
    I have hands.
    Veho @ Veho: +1