nintendo game

Hackers Target Nintendo, Affecting Accounts of 160,000 Users

After customers reported fraudulent purchases, Nintendo announced that a credential stuffing campaign led to breaches of thousands of accounts.

The accounts of about 160,000 Nintendo users have been affected by hacking attempts, causing the gaming company to disable the ability to log into an account with a Nintendo Network ID.

Nicknames, dates of birth, countries and email addresses were accessed through a breach since the beginning of April, according to The Verge. Some customers reported fraudulent purchases using their account information, which Nintendo says was “obtained illegally by some means other than our service.”

The older Nintendo Networks IDs (NNIDs) were used for 3DC and Wii U devices, whereas newer Nintendo products use a modernized account system. Until Friday, those new accounts could be linked to NNIDs, which increased the landscape for attacks, according to The Verge.

All affected users are being notified via email, and the company is encouraging all users to implement two-factor authentication so that there is less of a chance that a hacker is able to log in to their account using just an email address.

Users are also being warned that if they have used the same password for their NNID and Nintendo account, their ”balance and registered credit card / PayPal may be illegally used at My Nintendo Store or Nintendo eShop.” Nintendo gamers who suspect that their account has been used to make fraudulent purchases should report them to the company so they can be investigated and canceled.

The incident demonstrates how the $100 billion video game industry is a “growing target for cybercriminals,” said Anurag Kahol, the chief technology officer of data protection company Bitglass.

“Personally identifiable information (PII) and financial information are often connected to users’ gaming accounts, which is valuable data that attackers can use to commit financial fraud, identity theft, and trade on dark web marketplaces,” Kahol said. “Popularly, attackers will compromise and steal valid, high ranking gaming accounts and sell them for a generous profit.”

Although it’s not clear how hackers were able to obtain Nintendo account information for the credential stuffing attacks, “this incident still underscores why organizations must have full visibility and control over their data to prevent unauthorized access to sensitive customer information,” Kahol added.

The gaming industry is a huge target of credential stuffing campaigns, said Chris DeRamus, the chief technology officer of DivvyCloud.

“Organizations should also implement [multi-factor authentication] for all users, securely manage service accounts and their corresponding keys, enforce least privileged access, and enforce best practices for the use of audit logs and cloud logging roles,” DeRamus said.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • MetLife Stadium Uses Custom Surveillance Solution from Axis Communications

    Axis Communications, provider of video surveillance and network devices, today announced the implementation of a custom surveillance solution developed in collaboration with the MetLife Stadium security team. This new, tailored solution will help the venue augment its security capabilities, providing high-quality video at unprecedented distances and allowing the security team to identify details from anywhere in the venue. Read Now

  • U.S. Cyber Trust Mark Launches for Consumer Internet-Connected Devices

    The White House recently announced the launch of a cybersecurity label for internet-connected devices, known as the U.S. Cyber Trust Mark, completing public notice and input over the last 18 months. During that time, FCC Commissioners decided in a bipartisan and unanimous vote to authorize the program and adopt final rules, as well as the trademarked, distinct shield logo that will be applied to products certified for the U.S. Cyber Trust Mark label. Read Now

  • Motorola Solutions Expands its Retail Portfolio with Theatro Labs Acquisition

    Motorola Solutions has entered into a definitive agreement to acquire Theatro Labs, Inc., maker of AI and voice-powered communication and digital workflow software for frontline workers, based in Richardson, Texas. Read Now

  • FAST Announces National Security Technician Day Jan. 23

    The Foundation for Advancing Security Talent (FAST) has announced the third annual National Security Technician Day, an annual commemorative day held on Jan. 23 to honor security technicians across the country. Read Now

Featured Cybersecurity

Webinars

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening. 3