Several PlayStation users say they lost access to their PSN accounts after attackers persuaded Sony customer support to transfer control. One user, who posts as realradec, reports that an attacker convinced support staff they were the account owner, leading support to disable two-step verification (2FA), change the email address linked to the account and lock the user out.
The affected user insists they never clicked a suspicious link and was not the victim of a phishing message. 'I'm 100 percent sure I wasn't phished,' they wrote, stressing that the takeover did not involve the usual click-to-compromise pattern.

How the takeovers appear to work
Reports from multiple account holders, including journalist Nicola Lellouch and podcast host Colin Moriarty, point to social engineering as the common pattern. In these cases an attacker gathers information about a target and uses it to persuade customer support to hand over access or make account changes, bypassing technical protections that the account owner had in place.
These incidents show that social engineering can defeat technical safeguards such as two-step verification when customer support is convinced to make account changes.
Sony has not announced a general fix or a public mitigation for this problem. PlayStation users who have reported account takeovers are awaiting an official response as reports of similar incidents increase.




Leave a Comment
Comments
No comments yet. Be the first.