• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.

doemaaan

Member
Oct 27, 2017
1,693
Activated 2FA last night. My account was hacked twice in a span of 5-6 hours yesterday. Did not have a cc or PayPal on file, but it doesn't calm me to know that, that doesn't seem to be the reason for the breach...
 

Piccoro

Member
Nov 20, 2017
7,093
So that theory that only legacy Nintendo Accounts (created on Wii U/3DS) were vulnerable were correct!

But did they disable legacy logins on the Switch completely?
How am I supposed to login now, then?
 
Oct 27, 2017
525
How as this an "attempt"? Sounds like a successful hack to me. I know it's about liability but companies shouldn't obfuscate.
 

Alvis

Saw the truth behind the copied door
Member
Oct 25, 2017
11,219
Spain
So that theory that only legacy Nintendo Accounts (created on Wii U/3DS) were vulnerable were correct!

But did they disable legacy logins on the Switch completely?
How am I supposed to login now, then?
By logging in with your regular Nintendo account? lol

If you don't remember the password then choose the forgot password option. The legacy login was dumb anyways. "Hey, do you want to login with the Nintendo account or with the other older Nintendo account that's linked with your new Nintendo account" lol there's no reason for that option to even exist.

Anyways, people, enable 2FA on EVERYTHING and use unique passwords generated via Keepass or an equivalent for EVERY website.
 

GamingRobioto

Member
May 18, 2018
1,350
Exeter, UK
I don't think I used a legacy account for my Switch, maybe I did... anyway I added 2FA as soon as I saw the first murmuring of a hack, thought I already had it on but apparently not.
 

Fendajaz

Banned
Oct 29, 2017
2,123
Yikes. Tried to set up 2fa earlier today, but is there a way to set it up without downloading the Google authenticator app?
 

Kouriozan

Member
Oct 25, 2017
21,047
I have NNID linked but made a Nintendo account with my email and thus never used NNID as login.
I'm thankfully not affected but I have 2FA activated already.
 

Alent

Member
Oct 28, 2017
2,716
I never keep my cc data saved on NO/PSN but i really should stop being lazy and get 2fa set up :/
 

Naga

Alt account
Banned
Aug 29, 2019
7,850
Well it's good that it's only this kind of data that got affected, and that they reacted before too many people got hacked.

I think I had 2FA after the hacking started, but nobody used my NNID to connect to my account anyway.
 

Thera

Banned
Feb 28, 2019
12,876
France
Being attack is never a good adverstisement.
But the fact they communicate quickly about it is great.
 

dom

▲ Legend ▲
Avenger
Oct 25, 2017
10,427
So there wasn't a breach after all.
People using same username and password combinations on other sites who's data is breached being used to log into NNID accounts.

Those who had funds spent were using same passwords for their regular Nintendo Accounts as Nintendo doesn't allow the use of saved payment info if entered on Nintendo account side when logged in through NNID
 

Heynongman!

Member
Oct 25, 2017
8,924
Ahh so this is how my Nintendo account was being logged into from Russia a couple weeks ago. I had changed my password but got another email a few days late of the person doing it again, which would make sense if they're using the NNID logins. I was very concerned but this makes sense
 

Deleted member 5491

User requested account closure
Banned
Oct 25, 2017
5,249
Funny how NoE is saying
"While we continue to investigate, we would like to reassure users that there is currently no evidence pointing towards a breach of Nintendo's databases, servers or services."

while NCL is saying, that information was accessed
 

Oregano

One Winged Slayer
Member
Oct 25, 2017
22,878
Hmm, didn't think I was affected and not sure what my NNID password even is... Think I should probably change my password anyway. The good thing is it's definitely not shared with anything and I have 2FA setup...

I wonder where it originated?
 
Oct 25, 2017
4,840
So there wasn't a breach after all.
People using same username and password combinations on other sites who's data is breached being used to log into NNID accounts.

Those who had funds spent were using same passwords for their regular Nintendo Accounts as Nintendo doesn't allow the use of saved payment info if entered on Nintendo account side when logged in through NNID
There's a huge issue here that you aren't able to change the password on an NNID without a Wii U or 3DS. Many people aren't using those systems any more or have sold them or have had them break in the last 3 years. So most NNIDs are going to have old passwords and are therefore very vulnerable.
 

low-G

Member
Oct 25, 2017
8,144
That's a straight up data breach. Odd though that so many accounts were accessed if passwords or some other cert weren't leaked (I'm guessing they actually were). This isn't some mass social engineering drive given the names and birthdates.
 
Oct 27, 2017
12,756
Funny how NoE is saying
"While we continue to investigate, we would like to reassure users that there is currently no evidence pointing towards a breach of Nintendo's databases, servers or services."

while NCL is saying, that information was accessed


NoE:
slowpoke-256x256.png

Added 2FA on my account a few days ago just in case.
 

Deleted member 44122

Guest
Funny how NoE is saying
"While we continue to investigate, we would like to reassure users that there is currently no evidence pointing towards a breach of Nintendo's databases, servers or services."

while NCL is saying, that information was accessed

it was accessed as in viewed by just logging in on their website, not accessed as in through a database hack or whatever
 

Vexii

Member
Oct 31, 2017
2,385
UK
I had my account compromised 5 days ago, and some people have said that their accounts were breached a few WEEKS ago.

Now don't the GDPR regulations say that an individual must be informed of a security or data breach within 72 hours? Have Nintendo not breached GDPR by only coming out with this now?
 

PSOreo

Banned
Oct 27, 2017
3,260
Very lucky my account was okay but I've finally been able to add Two Step (wasn't aware they offered it until now) today as the verification emails weren't coming through for the past few days to me.

I had my account compromised 5 days ago, and some people have said that their accounts were breached a few WEEKS ago.

Now don't the GDPR regulations say that an individual must be informed of a security or data breach within 72 hours? Have Nintendo not breached GDPR by only coming out with this now?

Don't think so; I believe they have a certain window to disclose it.
 

Kevin360

OG Direct OP
Member
Oct 25, 2017
6,639
I've always signed in with my Nintendo Network ID, but now that option is no longer viable. Curious how I'm supposed to log in moving forward.
 

NioA

Member
Dec 16, 2019
3,624
Is there any way I can understand if my account has been hacked or not? I usually make access with the NNID, but I don't see any changes or things out of ordinary
 

Deleted member 31092

User requested account closure
Banned
Nov 5, 2017
10,783
Funny how NoE is saying
"While we continue to investigate, we would like to reassure users that there is currently no evidence pointing towards a breach of Nintendo's databases, servers or services."

while NCL is saying, that information was accessed


Word in the hacking community last week was that people were bruteforcing logins with NNID accounts using email+password combo found in other data breaches. This seems to confirm it.

I had my account compromised 5 days ago, and some people have said that their accounts were breached a few WEEKS ago.

Now don't the GDPR regulations say that an individual must be informed of a security or data breach within 72 hours? Have Nintendo not breached GDPR by only coming out with this now?

There is no security breach here, just people having access to NNID login data from other sources. I may be wrong however.
 

JoeNut

Member
Oct 27, 2017
3,482
UK
I activated 2fa as soon as I heard about this and removed my PayPal link. I have noticed a number of spam emails around the same time of the leak
 

Lynd

Member
Oct 29, 2017
2,437
My account was compromised a couple of months ago. Setup 2FA on switch, but should I have gone onto my Wii U/3DS and checked too?
 

PCK

Member
Oct 26, 2018
281
There's a huge issue here that you aren't able to change the password on an NNID without a Wii U or 3DS. Many people aren't using those systems any more or have sold them or have had them break in the last 3 years. So most NNIDs are going to have old passwords and are therefore very vulnerable.
But if you don't have access to these consoles, you have no reason to have the link. So you just delete the link and log in via your Nintendo account only.
 

kami_sama

Member
Oct 26, 2017
6,993
Very lucky my account was okay but I've finally been able to add Two Step (wasn't aware they offered it until now) today as the verification emails weren't coming through for the past few days to me.



Don't think so; I believe they have a certain window to disclose it.
Yep, like the other poster said, it is 72 hours to notify it once it is known by the company.
While NoE can say they are still investigating, they need to send asap a notification to the European data protection agency asap.