• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

Nicko

Member
Oct 25, 2017
482
Why isn't this being voiced to Reddit and other forums? Surprised Era is the only place I've heard of it. Surprised as someone personally attempted access to my account from Vietnam last night..
 
Oct 26, 2017
8,734
What are you supposed to do in that situation? I had no idea why it wouldn't work even after I set it up on my new phone a few months back. Almost permanently lost access to my account because of that.

The only thing is use back-up codes, or call Nintendo. I was lucky that I had back-up codes reserved, otherwise, I was going to be locked out. That experience certainly made me never want to look back at google auth.

Why isn't this being voiced to Reddit and other forums? Surprised Era is the only place I've heard of it. Surprised as someone personally attempted access to my account from Vietnam last night..

It's on r/nintendoswitch as a PSA regarding log-in activity
 

empo

Member
Jan 27, 2018
3,112
Nothing weird on my EU account with no NNID linked but I had a pretty bad password from before I used a pw manager so fixed that and took the time to collect all my recovery codes in one place and consolidated everything into Authy.
 

MotherFan

Member
Oct 27, 2017
659
For those worried about having nnid linked, I set up 2fa on my Nintendo account. I then used browser and tried to log in using nnid and got prompted for auth code. So, you don't need to unlink it once you enable 2fa, it should be good.
 
Last edited:

G.O.O.

Member
Oct 26, 2017
3,089
Question => is it useful to change your password now if there was no suspect activity ? We don't know if the breach is fixed as of now, so the new password could leak aswell ?
 

Rodney McKay

Member
Oct 26, 2017
12,205
Did even know Nintendo had 2FA, so at least I have that turned on now!

Didn't have any breach as far as I can tell on my account, but I changed my password just in case.
 

Deleted member 15457

User requested account closure
Banned
Oct 27, 2017
907
How do I even access the nnid online?
Hold on. Do you actually need a 3DS to change an old Nintendo network account password? It would make this a very serious issue because most people are going to have an old password on that account and it would work as a log-in method to the new Nintendo Switch account.

Has anyone here had their account broken into WITHOUT a Nintendo Network account linked?

From what I can tell, you can't change the password without access to a 3DS or Wii U.

This is the same for me, when I took out the online sub it saved the details for auto-renew, I have now taken it off auto-renew.

I took my card details off then set it to take from the stored Eshop funds.
 

SSF1991

Member
Jun 19, 2018
3,263
I've enabled 2-step verification on my Nintendo Account. I've seen no suspicious activity, but I still got that recommended layer of security nevertheless. I also unlinked a few accounts, including my NNID.

Should I be safe from this breach now? Or, at the very least, not as vulnerable to it as I once was?
 

Obsonet

Member
Nov 26, 2019
2,902
I've enabled 2-step verification on my Nintendo Account. I've seen no suspicious activity, but I still got that recommended layer of security nevertheless. I also unlinked a few accounts, including my NNID.

Should I be safe from this breach now? Or, at the very least, not as vulnerable to it as I once was?

Done pretty much everything you can, and you will be a lot more secure with 2FA enabled
 

SSF1991

Member
Jun 19, 2018
3,263
Done pretty much everything you can, and you will be a lot more secure with 2FA enabled

Okay.

Based on what I've read from people that got hacked, a lot of them noticed that the login attempts on their accounts stopped happening once 2FA was enabled, so that seems to be the number one thing you can do to avoid this breach.
 

ColdSun

Together, we are strangers
Administrator
Oct 25, 2017
3,292
Had 2 unauthorized logins since I didn't have 2FA on the account (purely because it's been ages and ages since I used it). Have since enabled 2FA on the account and used the signout all currently logged in sessions.

There definitely seems to be a Nintendo Security issue though.
 

TeenageFBI

One Winged Slayer
Member
Oct 25, 2017
10,241
Okay.

Based on what I've read from people that got hacked, a lot of them noticed that the login attempts on their accounts stopped happening once 2FA was enabled, so that seems to be the number one thing you can do to avoid this breach.
So long as they have a good 2FA implementation, no one is getting to your account without your phone. Wish more places would implement app-based 2FA. Netflix, banks, etc.
 

TheChrisGlass

Member
Oct 25, 2017
5,606
Los Angeles, CA
Seeing how this seems to be a very common issue right now, and no one has shown that they were phished, it either means there's a security exploit to login without knowing someone's password, or someone got a lot of passwords somehow from Nintendo's own database.

I'm pretty sure it's a violation for Nintendo to not disclose information soon, because this isn't a simple "LOL, your password was passw0rd" issue.

So long as they have a good 2FA implementation, no one is getting to your account without your phone. Wish more places would implement app-based 2FA. Netflix, banks, etc.

And that seems to help, but the problem is they DON'T have a good security implementation.
 

Yabberwocky

Member
Oct 27, 2017
3,260
I don't know if the following is of any use for correlating information, but my account hasn't been compromised, and my Switch account has also never been linked to my Nintendo Network ID. (I checked my 3DS, and while I can't tell if someone has accessed my NNID, there's been nothing different in my activity history. I suppose there isn't much one could do with $3.30 credit anyway.)
 

atomsk eater

Member
Oct 25, 2017
3,830
Still looking for two people to water some flowers for me. Kidd is also giving out ironwood cart DIYs as well (you don't need to water anything and can just come get the DIY if you want).
 

Biske

Member
Nov 11, 2017
8,273
Shit like this is why I never save payment methods to my account. Enter that shit manually forever even if its a huge pain in the ass. Didn't realize I didnt have 2FA on so I turned that on. Thanks folks!
 

Kouriozan

Member
Oct 25, 2017
21,122
So far, no suspicious activity on my account, I have 2FA and NNID linked to it, never played Fortnite on Switch or other games that hackers would want to benefit from.
I've been paranoid about getting my account stolen since several years ago so I never store sensible information, even on my very old and unused Paypal (which I unlinked after the promotion), I would feel very awful if my account kept getting accessed.
I do remember my Epic Game account getting tons of failed logins email spam 2/3 years ago ->
https://www.resetera.com/threads/an...mpted-log-ins-on-your-fortnite-account.48497/

I wouldn't even be surprised if this issue is about Fortnite again, similar to PS4 players getting hacked for FIFA.
 

Dekuman

Member
Oct 27, 2017
19,026
I see a lot of questions asking about NNID, but to be clear, that was 3DS/Wii U era Nintendo ID.
With the Switch it's called the 'Nintendo Account' which you can link your NNID to. Most people who got a Switch did to merge their eshop funds into the Switch account.

So if you linked your NNID to your Nintendo Account, your Nintendo Account is the primary account
 
Last edited:

Possum Armada

Banned
Oct 25, 2017
7,630
Greenville, SC
Finally figured out what they did with my account. Someone in the UK logged in, made their system the primary, downloaded a bunch of games and then disconnected their system from the internet.
 

plebc

Member
Jan 7, 2018
1,017
It's definitely not a breach, I saw those forums and groups. They are "cracking" accounts using "configs", "combos" and proxies. Nintendo accounts with games are being sold for really cheap, like $1 per game. Some people are also doing it because of Fortnite.

Just make sure to enable 2fa, unlink other accounts and nnid.
 

catpurrcat

Member
Oct 27, 2017
7,790
It's definitely not a breach, I saw those forums and groups. They are "cracking" accounts using "configs", "combos" and proxies. Nintendo accounts with games are being sold for really cheap, like $1 per game. Some people are also doing it because of Fortnite.

Just make sure to enable 2fa, unlink other accounts and nnid.

Forgive me for asking, but what are configs, combos and proxies in terms of cracking accounts?
 

Lord Arcadio

Member
Oct 27, 2017
2,172
Just realized I didn't have 2FA on PayPal. Yikes!

When I have time, I'm going to have to sit down and make sure all my accounts are secure.
 

Nessus

Member
Oct 28, 2017
3,920
Google Authenticator is awful. I wish Nintendo would just use their own in-house text your cell phone method for 2 factor.
 

Estro

Member
Jul 17, 2019
339
Yep, been hit by this. At least 4 logins from the US (I live in Europe) for the past week or so. Enabled 2FA today.
 

IDreamOfHime

Member
Oct 27, 2017
14,441
It's definitely not a breach, I saw those forums and groups. They are "cracking" accounts using "configs", "combos" and proxies. Nintendo accounts with games are being sold for really cheap, like $1 per game. Some people are also doing it because of Fortnite.

Just make sure to enable 2fa, unlink other accounts and nnid.
Could you actually explain the things you just said? I don't understand.
 

A1an

Member
Oct 26, 2017
1,341
UK

That worked thank you.

Still none of this has been picked up or mentioned by Nintendo of issues or Epic, I only mention the latter because many have said that accounts that have been affected had funds spent on V-bucks.

Is there anything we can do?
Because at the end of the day all of us are gamer's and we all have that in common even if one is a Call of Duty player and the other is a Battlefield player etc, the gaming is getting bigger and bigger and the industry have their powerful hands to deal and the ESRB and PEGI etc are sort of a halfway house, but us as gamer's need to have some sort of voice, hacked (they must be because nobody is going to voluntarily sell) Xbox and PSN accounts are for sale on the likes of eBay, there are many issues and debating on sites like this isn't going to get anywhere really.
 

Akita One

Member
Oct 30, 2017
4,628
It's weird that it's 2020 and yet so many people here don't have 2FA on public accounts, especially anything that has your credit card associated with it. Amazing.
 

McScroggz

The Fallen
Jan 11, 2018
5,973
It's definitely not a breach, I saw those forums and groups. They are "cracking" accounts using "configs", "combos" and proxies. Nintendo accounts with games are being sold for really cheap, like $1 per game. Some people are also doing it because of Fortnite.

Just make sure to enable 2fa, unlink other accounts and nnid.

Can you explain this to me?
 

Kyrios

Member
Oct 27, 2017
14,657
Nintendo is investigating now apparently

twitter.com

Polygon on Twitter

“Nintendo ‘investigating’ reports of Nintendo Switch account breach, recommends 2FA https://t.co/rWxRrUGHvs”