Journalist reports critical PlayStation vulnerability allowing accounts to be "hijacked" even with two-factor authentication

Journalist reports critical PlayStation vulnerability allowing accounts to be "hijacked" even with two-factor authentication

Новости 0 Источник: Wccftech
18:14

Sony support shows complete indifference — agents don't even ask potential fraudsters questions, but simply hand over control of accounts to anyone.

French journalist Nicolas Lellouche from Numerama was the victim of a hack of his PlayStation Network account, despite using access keys and two-factor authentication. The hacker twice in a short time seized control of the account, changed the email and password, and spent money from the card linked to the account.

The incident occurred on December 22. Lellouche initially regained access through Sony support, but soon the hacker "stole" the account again. In an unusual turn of events, the journalist even spoke with the hacker, who explained the method of attack.

According to the hacker, the vulnerability is related to the account recovery process in Sony support. It is enough to know only one detail — the transaction number visible on old screenshots of purchases in the PS Store. With this information, an attacker can convince support to disable all protections and transfer the account to him. Lellouche's account was compromised precisely because of an old screenshot with visible mail, published on the Internet earlier.

Hackers, according to the journalist, are actively collecting such screenshots for mass hacks, making accounts practically unrecoverable for owners.

Lellouche is unhappy with the indifference of Sony support, whose agents hand over control of the account to anyone without unnecessary questions.

run.code
18:14
Источники: Numerama

Сейчас на главной