• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

Palette Swap

The Fallen
Oct 25, 2017
11,212

ApeEscaper

Member
Oct 27, 2017
8,720
Bangladeshi
were you autologged out of the account on browser?
Seems so probably because I rarely login through desktop browser only login my account directly on my Switch for eShop. I can only still access the account through Switch since I'm still logged in and doesn't require 2FA codes. But once I log out there I'm screwed so I need to sort this out asap
Something like this almost happened to me. I was on a new phone and needed to sign in, but the Google authenticator app's codes would never validate with the account, so it was impossible to sign in. Fortunately I was still signed in on my desktop and was able to disable 2FA so I could sign in on my phone. Otherwise, it would have been impossible to ever access the account. Why is this something that can happen? So secure you can never access your own account because of faulty tech? That sucks.
Yeah pretty sure other online services I seen where if you didn't have 2FA on you there was other methods to get in still think it was Gmail or Steam can't remember, oh well hopefully Nintendo support can help me now
 

flipswitch

Member
Oct 25, 2017
3,955
Yeah, someone from Russia signed into my account on April 3rd. I had 2fa already so they couldn't do anything and the password was unique. Not sure why Nintendo hasn't said anything.

H1Bg7Op.png

This is unusual, and you used a unique password.
 

Deleted member 15457

User requested account closure
Banned
Oct 27, 2017
907
Also, Linking your NNID to your Nintendo Account means you share Eshop balances across both of them.

EDIT: Could we have a modpost or edit the OP with a guide on what you should to to protect yourself? So far I'm seeing:

  • Enable 2FA for Nintendo Account
  • Change Nintendo Account password
  • Change NNID password (Maybe wait a bit because there could be an active breach? IDK)
 
Last edited:

SiG

Member
Oct 25, 2017
6,485
I seem to be safe. All link accounts trigger 2FA (including Nintendo Network), and login history shows just me.
 

Nicko

Member
Oct 25, 2017
482
I just received a google account recovery request from someone in Vietnam using my email address. Likely a result of this hack? I enabled 2FA and changed my PW earlier today just to be safe.
 

NightShift

Member
Oct 25, 2017
9,026
Australia
Changed my password but I'm having trouble activating 2FA. Not getting any vertification emails so I added @accounts.nintendo.com to my safe senders list but I'm still not getting anything. I think I should just wait a hour or two but I would appreciate if anyone knows what the problem may be.
 

Joni

Member
Oct 27, 2017
19,508
i'm sure they're contacting the right authorities but I suspect Nintendo is gonna stay relatively quiet about how this is going as they work behind the scenes to fix it unless the compromised numbers are too high to ignore. Hell, Sony took a week before admitting to their breach back in 2011, and that number was in the millions.
They have to alert impacted users within a certain time period under gdpr. What Sony did isn't relevant as gdpr wasn't a thing.
 

Neural

Member
Oct 27, 2017
1,820
Italy
Done, thanks! Any authenticator app works, not just Google. I used Microsoft Authenticator, which I already had installed.
 

jorgejjvr

Banned
Oct 31, 2017
8,423
Glad I saw this. Money has been taken out. Changed passwords, and canceled my PayPal attached to it for now. Now I'm on the phone with my bank
 

naitosan

Member
Oct 28, 2017
559
Haven't logged in my Nintendo account since I sold Switch. Mine's good but enabled 2FA just in case. Thanks for the heads up!
 

Deleted member 29682

User requested account closure
Banned
Nov 1, 2017
12,290
Nothing weird with my account but turned on 2FA anyway. Does not saving card details on my Switch do anything to protect myself?
 

SigSig

Member
Oct 26, 2017
4,777
Wait so you can't do 2FA via text message? That seems dumb
2FA via text is insecure as soon as the attacker can obtain your phone number, which can be done in a myriad of ways once they have enough info. 2FA via text is mostly used as an excuse to get you to provide your phone number and not about security at all.
 

Dreamwriter

Member
Oct 27, 2017
7,461
Nothing weird with my account but turned on 2FA anyway. Does not saving card details on my Switch do anything to protect myself?
The card details are saved only on the Switch hardware, not stored online anywhere, so that only protects you from someone physically holding your Switch, or you buying crazy games while drunk.

edit: wow, I was totally wrong. I wonder which service I was thinking of...
  • Credit card information stored on your Nintendo Account can also be used for off-device purchases.
 

Klart

Member
Jan 23, 2019
441
User banned (1 day): mocking ethnic accents
Ugh. Notto disu shitto ogen. Tu quoque, Nintendo?
 

Shotterke

Prophet of Regret
Member
Oct 31, 2017
423
Belgium
Last week I got a message that someone in the US logged into my account (I'm from Belgium) so I changed it to a new random generated password from Lastpass. 6 hours later I got a message that someone logged into my account in China with the new password.

Changed my password again and enabled 2FA but my guess is that there was some kind of security breach with Nintendo.
 

Nolbertos

Member
Dec 9, 2017
3,314
Just changed it earlier today. No security breach on my part as I checked my log in history but I guess lesson learned for me.
 

Dreamwriter

Member
Oct 27, 2017
7,461
Last week I got a message that someone in the US logged into my account (I'm from Belgium) so I changed it to a new random generated password from Lastpass. 6 hours later I got a message that someone logged into my account in China with the new password.

Changed my password again and enabled 2FA but my guess is that there was some kind of security breach with Nintendo.
Did you check to see what other services were linked to your account, since those can be used to bypass Nintendo sign-in? Making Nintendo secure doesn't help if it's linked to a service where you are using an old password and no 2FA, like maybe Facebook or the Nintendo Network ID (from 3DS/Wii U)
 
Last edited:

RankFTW

Member
Oct 28, 2017
718
Scotland
Last week I had somebody access my Nintendo account from Columbia and used my PayPal to buy £79.99 worth of vbucks on Fortnite. My password was unique to Nintendo however I did not have 2 step authentication on as I did not see this was an option. I have given all of these details to Nintendo and I'm waiting on them looking into this for me. Hopefully the money is refunded if they can see that I've never played Fortnite on the console. Shitty situation though.
 

Bob Beat

Member
Oct 25, 2017
3,916
Also, Linking your NNID to your Nintendo Account means you share Eshop balances across both of them.

EDIT: Could we have a modpost or edit the OP with a guide on what you should to to protect yourself? So far I'm seeing:

  • Enable 2FA for Nintendo Account
  • Change Nintendo Account password
  • Change NNID password (Maybe wait a bit because there could be an active breach? IDK)
How do I even access the nnid online?
 

Bob Beat

Member
Oct 25, 2017
3,916
2FA via text is insecure as soon as the attacker can obtain your phone number, which can be done in a myriad of ways once they have enough info. 2FA via text is mostly used as an excuse to get you to provide your phone number and not about security at all.
Which is cool because my bank, BOA, doesn't have anything but 2 factor via SMS.
 

Ph8lanx

Member
Oct 29, 2017
101
Dark Side of the Moon
Happen to me last week. $200 was spent on a switch lite in India on Fortnite V-Bucks. Luckily Nintendo customer service was really nice and I got the money back in about 5 business days. Btw I don't own a switch lite or Fortnite. I also live in Los Angeles. Oh and PayPal was awful. I knew it had to be a hack on Nintendo's side. Op is spot on. Make sure to change all your passwords.
 
Last edited:
Oct 25, 2017
4,841
I had a problem with my account a few days ago.

This was the culprit for me.

7R9D9vx.png


I had to bust my old 3ds out to change my nintendo network ID password, since i believe it's the only way to do so.

I'm guessing a ton of people have hella old username/passwords for their NNIDs (with passwords leaked from other sites) and hackers are brute forcing these accounts.
Hold on. Do you actually need a 3DS to change an old Nintendo network account password? It would make this a very serious issue because most people are going to have an old password on that account and it would work as a log-in method to the new Nintendo Switch account.

Has anyone here had their account broken into WITHOUT a Nintendo Network account linked?
 

bagandscalpel

Member
Oct 25, 2017
701
Hold on. Do you actually need a 3DS to change an old Nintendo network account password? It would make this a very serious issue because most people are going to have an old password on that account and it would work as a log-in method to the new Nintendo Switch account.

Has anyone here had their account broken into WITHOUT a Nintendo Network account linked?
No attempts to log into my Nintendo Account aside from my own. I do NOT have my NNID linked.
 

Madao

One Winged Slayer
Member
Oct 26, 2017
4,696
Panama
i upped all my accounts with 2FA thanks to this topic.
i had nothing weird at all but it doesn't hurt to be careful and setting up 2FA was pretty fast.
 

BillerBomber

Banned
Nov 14, 2017
81
Hold on. Do you actually need a 3DS to change an old Nintendo network account password? It would make this a very serious issue because most people are going to have an old password on that account and it would work as a log-in method to the new Nintendo Switch account.

Has anyone here had their account broken into WITHOUT a Nintendo Network account linked?

I delinked my NNID last night just to be sure.
 

adit

Member
Oct 29, 2017
942
tonja
how do you know someone access your account from other country ?, nintendo sent you email warning ?
 

Exodist

Member
Oct 30, 2017
52
how do you know someone access your account from other country ?, nintendo sent you email warning ?

Yeah you'll get an email, it's an automated thing. I got an email earlier this morning saying my account was logged in from USA (I live in UK). I've changed all my stuff and don't see anything, no activity on the account, no purchases and nothing on my bank yet either. But logging into the Nintendo account website it doesn't really seem to give a lot of info to be fair? Pretty much most of it is obscured and don't have a linked paypal account so I should be fine.
 

Merc_

▲ Legend ▲
Member
Oct 28, 2017
6,535
Nobody logged into my account except me, but I've enabled 2FA.

Thanks for the heads up.
 

Deleted member 32135

User requested account closure
Banned
Nov 9, 2017
1,555
I had 2FA activated and didn't have any security break in my account.

However, I realised I didn't have it on my PS account and went there to activate it just to realize I only have the option to do 2FA through SMS message... really Sony?!
 

Deleted member 36578

Dec 21, 2017
26,561
No hacks, but set 2s anyway.
 
Last edited:

itsaziz

Member
Nov 8, 2017
533
Logged out of all devices and changed my password. It doesn't mention that I'm logged into my Switch though?
 
Jan 2, 2018
2,029
Didn't get any login attempts,have 2FA enabled and complex password and no linked account,hope I'm good. I highly recommend to avoid linked accounts as a practice btw.
 

Geode

Member
Oct 27, 2017
4,458
Checked my account and no unauthorized access notifications. I'm wondering those who have had unauthorized notifications have been playing Animal Crossing and if there's a correlation?