English NewsPSN Security Faces Criticism Again Following Another Account Takeover

PSN Security Faces Criticism Again Following Another Account Takeover

PlayStation account security is back in the spotlight. A prominent member of the PlayStation community, RealRadec, reports losing access to his PSN account. The timing is troubling: earlier this year, several similar incidents sparked criticism of Sony’s recovery and support processes.

This time, the affected account is the PlayStation fan account RealRadec, which has more than 30,000 followers on X.

He says he repeatedly changed his password, signed out every registered device, and re-enabled two-factor authentication, yet the attacker still managed to change the linked email address. How the intruder initially gained access remains unclear.

Well-Known PlayStation Account Reports Takeover

RealRadec went public on October 3, explaining that his PlayStation account had been compromised and that his initial efforts to regain full control had failed. Changing the registered email address is particularly problematic.

Once that happens, the standard recovery process becomes far harder for the real owner. It is not yet clear whether passwords were compromised, support processes were exploited, or other methods were used in this specific incident. For that reason, this case should not be labeled a confirmed social engineering attack.

Previous incidents have put PlayStation Support in the spotlight

Concerns stem from similar incidents. In May, the PSN account of well-known PlayStation podcaster Colin Moriarty was compromised.

Moriarty said he had not fallen for a phishing site nor knowingly shared his login credentials. Subsequent investigations highlighted social engineering through customer support—without directly hacking Sony’s servers.

Instead, attackers impersonate the legitimate account owner when speaking with a support representative. We previously reported on that discussion: https://www.playstationinfo.de/2026/05/25/psn-security-concerns-spark-fresh-debate-among-playstation-users/

In earlier cases, very little information may have been sufficient

Springtime investigations showed that, in some cases, support agents asked for only basic account details to reset access. That information could include the PSN name, an email address linked to the account, and details of past purchases. Under certain circumstances, some of that data is publicly available or can be inferred from other sources.

Purchase data can become a problem if users publicly disclose when they bought a game or share receipts. In one documented test, researchers even accessed an account through customer support with the owner’s consent. Critics therefore focused less on the PlayStation Network’s technical encryption than on potential weaknesses in identity verification.

Two-factor authentication does not necessarily solve this problem

Normally, two-factor authentication is one of the most important security measures for online accounts. It prevents an attacker from accessing an account using only a stolen password. However, the situation can be different in cases of social engineering via a recovery process.

If a support agent can change account details after verifying ownership through such information, the extra login step may not block that attack.
This does not mean 2FA is useless.

It still guards against many attacks and should remain enabled, but it cannot replace secure identity verification during account recovery.

PSN accounts are significantly more valuable today than they used to be

The issue is sensitive because a PlayStation account now holds far more than a username. For long-time players, it may include hundreds of digital purchases, DLCs, PlayStation Plus content, trophies, save files, and years of account history.

As digital games grow in importance, so does the potential damage from an account takeover. In the worst case, a stolen account can open a library that players have invested heavily in over the years. That’s why, ever since earlier incidents, players have demanded stricter security measures for changing vital account data.

Sony has not yet commented on this case.

Sony has not issued an official statement about this new case. It remains unconfirmed whether RealRadec’s account was compromised using the same method as the earlier accounts. The incident is drawing attention mainly because of that history. Back in May, we reported that the allegations at the time appeared unresolved despite public discussion:

https://www.playstationinfo.de/2026/05/13/playstation-network-sicherheitsluecke-sorgt-weiter-fuer-kritik-problem-offenbar-noch-immer-nicht-geloest/ It is not publicly known in detail whether Sony has since changed its internal recovery processes.

Players should keep their account information as private as possible

Regardless of how this particular incident unfolded, several basic precautions remain essential. Enable passkeys or two-factor authentication, and never share purchase receipts, transaction numbers, or other account details publicly.

Even screenshots can reveal more than meets the eye. The RealRadec case does not prove that any PSN account can be easily taken over despite all protective measures, but it does illustrate why the debate over Sony’s recovery processes is flaring up again.

Until investigators determine the method of access, one question remains: Is this an isolated incident, or a continuation of the account takeovers reported this spring? Share your thoughts in the comments.

Wie hat dir dieser Artikel gefallen?

Amazon

Jetzt einkaufen und unterstützen

*Unsere Seite enthält Affiliate-Links zu Amazon. Ihr unterstützt uns durch eure Einkäufe, ohne dass zusätzliche Kosten für euch anfallen.

Weitere News