Nintendo says over 160,000 accounts were compromised, disables NNID logins

midian182

Posts: 9,778   +121
Staff member
What just happened? Nintendo has confirmed that over 160,000 of its account holders were victims of hacking attempts—a result of vulnerabilities in the legacy Nintendo Network ID (NNID) system, which can be used to log into main Nintendo accounts.

Nintendo says login IDs and passwords were “obtained illegally by some means other than our service.” It has now disabled the ability to log into Nintendo Accounts through a NNID, and is resetting passwords for affected accounts.

NNIDs were used for older Nintendo devices such as the Wii U and 3DS before the more recent account system used for the Switch and other newer platforms was introduced. Until today, it had been possible to sign into a Nintendo Account though a NNID, but that ability has been disabled.

Hackers could have viewed compromised accounts’ details, including nicknames, date of birth, country, and email addresses. Many of the breached accounts were used to purchased digital items, such as Fortnite VBucks, via their linked payment methods, though Nintendo has promised to refund any fraudulent purchases.

Nintendo is emailing affecting users, warning them that their credit card/PayPal details may have been used at My Nintendo Store or Nintendo eShop. The company stressed that credit card data was not accessed.

Nintendo is now recommending that all its users enabled two-factor authentication for an extra layer of security, which is something we should all be doing wherever possible. You can read Nintendo’s instructions on how to set it up using the Google Authenticator app, though the method also works with other authenticator apps.

Permalink to story.

 
It's a bit shame, they did not inform/enforce two steps authentication sooner.
I added my Nintendo account to Google authenticator as soon as I was aware it's possible.
 
It's a bit shame, they did not inform/enforce two steps authentication sooner.
I added my Nintendo account to Google authenticator as soon as I was aware it's possible.

Google is the last company I would ever give any sort of authentication control to.
 
The irony when sotware companies get hacked.........it's not like they don't have software engineers or someone who knows about cyber security!!
 
Back