PlayStation Network users are reporting a spike in account hijacking, a shift that directly threatens the integrity of digital libraries on the PlayStation 5. This trend matters because compromised accounts often result in permanent profile bans for the original owners, effectively erasing their purchased games and progress. We are seeing a clear pattern where technical security measures are being undermined by human manipulation rather than code exploits.
Social engineering allows attackers to bypass two-factor authentication
The core of this issue involves attackers using social engineering tactics to bypass the PlayStation Network's two-factor authentication (2FA). Instead of cracking passwords, scammers contact Sony support and claim they have lost access to their phone or primary authentication device. This narrative convinces support employees to manually disable 2FA on the victim's account, allowing the attacker to reset the password and take full control.
Once the account is compromised, the hijackers frequently use the stolen profile to send offensive or spam messages to other users. These actions violate Sony's community guidelines and trigger automated moderation systems that ban the profile. The irony is that the original owner, who was the victim of the theft, receives the ban for the misconduct committed by the attacker. This creates a situation where security failures are punished by the very platform meant to protect the user.
Sony advises users who suspect they have been hacked to contact support immediately with proof of ownership. Providing console serial numbers or original purchase receipts helps verify identity and may assist in recovery efforts. While the source notes that owners of short and rare PSN nicknames are especially often attacked, there is no official data to quantify this frequency. We also note that scammers sometimes manage to bypass even two-factor authentication through these support channels, a method that lacks official confirmation on success rates.
Source: IXBT




Discussion
0 comments