• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.

Orb

Banned
Oct 27, 2017
9,465
USA


twitter.com

Pixelpar on Twitter

“I suspect Nintendo may have had a major security breach. My account was accessed numerous times overnight. My password is a unique string and my PC is definitely clean (not that I ever login via it). Lots of similar reports on Reddit/twitter. Unlink PayPal & enable 2FA folks!”

I suspect Nintendo may have had a major security breach. My account was accessed numerous times overnight.

My password is a unique string and my PC is definitely clean (not that I ever login via it).

Lots of similar reports on Reddit/twitter.

Unlink PayPal & enable 2FA folks!

This happened to me. Unique, random password and my account was accessed from Russia. Lots of replies on this tweet saying the same things.

This is unconfirmed but I feel like something is up. I would exercise caution if you have a Nintendo Account.
 

NotLiquid

One Winged Slayer
Member
Oct 25, 2017
34,748
Didn't this happen not too long ago? I distinctly remember a similar scare going around earlier in the year that had people unlinking Paypal / setting up Nintendo 2FA, and it seemed Fortnite related somehow.
 

Kemal86

Member
Oct 25, 2017
3,401
Yep. I had a unique password. I got an access notification that someone in the US used Firefox to access my account, which I never use.

I changed to another random unique password.

30 minutes later, I got accessed from Russia.

Changed the PW again and added 2FA.
 

Mekanos

▲ Legend ▲
Member
Oct 17, 2018
44,120
How can you check if your account has been logged into elsewhere?
 

Liquid Snake

Member
Nov 10, 2017
1,893
Thanks for the heads up, done.

As someone who's studying cyber-security currently, this is a really big deal. And not a good sign, it probably means multiple breaches and an incoming shitstorm.
 

TeenageFBI

One Winged Slayer
Member
Oct 25, 2017
10,226
If these are truly long, random, unique passwords, it sure sounds like an actual breach. Couldn't hurt to change your password (and add 2FA if it's not already there).
 

benbeau

One Winged Slayer
Member
Oct 25, 2017
552
Yeah. Got an email from Nintendo the other day saying my account was logged into from Russia. Didn't even realize I hadn't set up 2FA yet. Fixed it up real quick, and they didn't manage to cause any damage.
 

Mekanos

▲ Legend ▲
Member
Oct 17, 2018
44,120
Thanks guys. Looks like I'm good but I should probably change my password just in case.
 

Mad Matt

Member
Dec 12, 2019
98
Wow, strange timing since I just set up 2FA again yesterday. Thanks for the heads-up. I changed my password and unlinked Paypal.
 

Jakenbakin

Member
Jun 17, 2018
11,794
I had a random login from Russia a couple of weeks ago, made me finally get off my ass and implement 2FA
 

RCSI

Avenger
Oct 27, 2017
1,838
Thanks for the heads up, I was tempting fate as 2fa was not enabled, now it is.
 

plebc

Member
Jan 7, 2018
1,017
It's not a breach, just enable 2fa. They are "cracking" Nintendo accounts because of Fortnite.
 
OP
OP
Orb

Orb

Banned
Oct 27, 2017
9,465
USA
If these are truly long, random, unique passwords, it sure sounds like an actual breach. Couldn't hurt to change your password (and add 2FA if it's not already there).
For me it was a truly "random" 20-character string using lower, upper, numbers, and symbols that is not used anywhere else. I don't know any way someone could have got in short of a breach.
 

Jedi2016

Member
Oct 27, 2017
15,614
No unusual activity, but I've been meaning to activate 2FA for my Nintendo account, so there you go.
 

zswordsman

Member
Nov 5, 2017
1,771
Not a fan of using a Google app in order to activate 2FA but it's better than nothing I guess. Apparently if you erase the app on your phone the app won't save it or have a backup since it's local only. So I advise everyone to really save those Nintendo backup codes after setting up 2FA.
 

Naga

Alt account
Banned
Aug 29, 2019
7,850
Weird stuff, would be interesting to get more confirmations and maybe something to link this together to see if it's truly a breach.
Like some are saying it's linked to people having played Fortnite, some having played AC online with random people, etc.

At least it'll push people to enable 2FA. And use Authy.
edit: and yeah, save your backup codes regardless too.
I've had 2fa on my Nintendo account so I should be fine?
If you have 2FA, you should generally be fine yeah.
 

alpha

Member
Oct 25, 2017
4,997
Realized I needed to do this. The problem is, that account is old and uses an email I don't have access to anymore and it wants to send a verification code to that before it will let me change anything like 2FA or changing the email.

So for now I just removed my payment info from it so that wouldn't be able to be accessed.
 

Deleted member 925

User requested account closure
Banned
Oct 25, 2017
3,711
I would enable 2FA, but I don't want to use some Google app. Why can't we just use our phone number?
 

MouldyK

Prophet of Truth
Banned
Nov 1, 2017
10,118
Say my friend uses my account from time to time to try games our on their Switch.

If I enable 2FA now, would they need to sign in again or would this only concern new people signing in?
 

Jonnykong

Member
Oct 27, 2017
7,898
I got two emails a few hours ago saying somebody from Ukraine and Russia was trying to access my account.

I've since changed my password and activated 2fa.
 

P-Bo

One Winged Slayer
Member
Jun 17, 2019
4,405
Done--thanks for the heads up. Also gonna check my bank account for any recent transactions.
 

Linde

Banned
Sep 2, 2018
3,983
im reading up on 2FA and the google authentication app
apparently it stores data to the phone without backup? What happens if we lose access to our phone then? Are we locked out of the nintendo account as well?

Correct me if its wrong
 

Kouriozan

Member
Oct 25, 2017
21,067
I mean, I wouldn't want someone to have my password even if I have 2FA enabled (which I do). We can't be certain that the 2FA implementation is as solid as it should be and it's very easy to change a password.
I would change password but we already got people claiming they just changed it and got hacked again so I'll wait a bit and see if I get attempt emails.
I don't keep my CC infos on my account anyway.
im reading up on 2FA and the google authentication app
apparently it stores data to the phone without backup? What happens if we lose access to our phone then? Are we locked out of the nintendo account as well?

Correct me if its wrong
They give you unique emergency codes to store if you lose your phone.
 

TeenageFBI

One Winged Slayer
Member
Oct 25, 2017
10,226
im reading up on 2FA and the google authentication app
apparently it stores data to the phone without backup? What happens if we lose access to our phone then? Are we locked out of the nintendo account as well?

Correct me if its wrong
I *think* Google has a way to recover your codes (unsure if you have to manually enable it beforehand) but I'd rather just use Authy which allows you to get codes on multiple devices.
 

Garlador

Banned
Oct 30, 2017
14,131
Yeah, I got an email last night, changed my password, and got another email this morning. Something is up.
 

Martin

One Winged Slayer
Member
Oct 25, 2017
2,432
im reading up on 2FA and the google authentication app
apparently it stores data to the phone without backup? What happens if we lose access to our phone then? Are we locked out of the nintendo account as well?

Correct me if its wrong
Use authy, it is a much better app and you can also use it on your pc.
When setting up 2FA you always get backup codes. Keep them safe! They can safe your ass!
 
Oct 27, 2017
42,700
im reading up on 2FA and the google authentication app
apparently it stores data to the phone without backup? What happens if we lose access to our phone then? Are we locked out of the nintendo account as well?

Correct me if its wrong
They give you backup codes that you should save somewhere and use if you lose access to your authenticator