Skip to main content
Breach Signal

Breach report

Gaming

Nintendo

Nintendo's NNID hack was almost twice as big as first reported

Attackers hijacked about 300,000 Nintendo accounts in spring 2020 by abusing legacy Nintendo Network ID logins, viewing personal details and in some cases using linked payment methods to buy digital goods.

Reported by The Verge

Records exposed

300K

About 300,000 accounts

Scale vs. largest on file

When
2020
How they got in
Credential stuffing against legacy Nintendo Network ID logins
Sector
Gaming

In early April 2020, Nintendo Switch owners began reporting on social media that their accounts had been accessed without permission, with some saying their stored payment methods or linked PayPal accounts had been used to buy digital items, often the Fortnite currency V-Bucks. On April 24, Nintendo confirmed that about 160,000 accounts had been accessed. On June 9, following further investigation, it said an additional 140,000 accounts had been affected, bringing the total to roughly 300,000.

The attackers exploited Nintendo Network IDs, a legacy login system created for the Wii U and 3DS consoles that many users had linked to their newer Nintendo Accounts. Nintendo said the login credentials had been obtained illegally from sources other than its own services, pointing to credential stuffing, in which attackers try username and password pairs leaked from other breaches. Once inside, intruders could see nicknames, dates of birth, country or region and email addresses, and could use saved payment methods to make purchases on the Nintendo eShop.

Nintendo responded by disabling the option to sign in to a Nintendo Account using a Nintendo Network ID, resetting passwords for affected accounts and contacting users directly. It urged customers to enable two-factor authentication and to review their purchase histories for unauthorized transactions. The company said only a small fraction of the compromised accounts had been used for fraudulent purchases and that it was working to refund them. It said credit card numbers themselves were not exposed.

The incident generated widespread complaints, partly because two-factor authentication had been optional and relatively obscure for many Switch owners, and because of the popularity of the console during pandemic lockdowns. No regulatory penalty was announced. The same period also saw large leaks of Nintendo's internal source code and development files, though those were unrelated to the account takeovers.

The Nintendo case is a textbook example of how older authentication systems can become the weakest link in an otherwise modern platform. Linking legacy accounts for convenience left a path open that lacked the protections of the newer system. It also showed that credential stuffing turns breaches at unrelated companies into problems for everyone, reinforcing the importance of unique passwords and of platforms nudging users toward two-factor authentication by default.

More from the wire

More in Gaming.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.