Early October 2026 brought another round of reports from PlayStation players saying their accounts had been taken over, including a well-known community member who said attackers changed his account's primary email address even after he changed his password, signed out of all devices and re-enabled two-factor authentication.
Sony's investigation is the company's to finish, and we cannot say from the outside how any individual account was lost. But the reports are a useful prompt, because gaming accounts are a favourite target and the ways they are lost are well understood.
Why attackers want gaming accounts
A gaming account is worth money in a way people underestimate:
- Rare usernames and items can be resold.
- Stored payment methods and wallet balances can be spent.
- The linked email can unlock other accounts. Taking over the email is often the real goal.
- Reputation: a trusted account can be used to scam friends.
The common ways accounts are lost
1. Reused passwords (credential stuffing). A password leaks from one site, and attackers automatically try it everywhere else. This is by far the most common route, and it needs no hacking of the game company at all.
2. Phishing. A convincing "your account is suspended" or "claim your prize" message leads to a fake login page. Good fakes also capture the 2FA code you type, in real time.
3. Social engineering of support. Instead of attacking the technology, the attacker persuades a human, or an automated recovery flow, to hand over access. Account recovery is often the weakest door, which is why a changed email can survive a changed password.
4. Stolen session tokens. Malware on a PC, often hidden in a cracked game or a fake "mod" or cheat, steals the logged-in session from the browser. The attacker is then already "logged in", and no password or 2FA is asked.
5. Insecure networks. Less common than the above, but real: on open Wi-Fi, an attacker can lure you onto a fake network and intercept unencrypted traffic.
A lockdown checklist
Do these in order. Ten minutes covers the most important ones.
- Secure the email first. Your email account resets everything else. Give it a unique, long password and an authenticator app or passkey.
- Unique password per service, from a password manager. This ends credential stuffing against you.
- Use an authenticator app or passkey instead of SMS where offered.
- Check the recovery options. Make sure the recovery email and phone number are yours and current, and remove old ones.
- Review signed-in devices and sessions and sign out anything unfamiliar.
- Check for a "security notification" setting and turn on alerts for email, password and device changes, so you find out in minutes rather than days.
- Never download cracked games, cheats or "free skins" tools. They are a leading way session-stealing malware gets installed.
- Type the official address yourself rather than following links in messages, however urgent.
If you think you have been hijacked
- Contact the platform through its official support page immediately and start the recovery process.
- Change the password on your email and anything sharing the old password.
- Check your bank or card statements and remove stored payment methods.
- Warn friends not to trust messages from your account until it is recovered.
- Keep a record of dates and screenshots. It speeds up support.
What a VPN does here
A VPN is not a fix for account takeover, and anyone who says otherwise is overselling. It will not stop credential stuffing, phishing or malware. What it does is encrypt your connection on public or shared networks, so people on the same Wi-Fi cannot watch or tamper with your traffic. It is one layer, useful when you game or sign in away from home, and no substitute for the checklist above.
Related reading: Rockstar Games breach: how stolen tokens opened the door, what a VPN really protects and why free VPNs are dangerous.