According to overseas outlet Push Square, “RealRadec,” a prominent PlayStation fan with over 30,000 followers on X (formerly Twitter), had their PSN account hijacked. The information used to verify identity reportedly amounted to little more than a username, purchase date, and transaction ID — details easily guessable from social media posts and trophy histories. On 5ch’s hardware/industry (Gaha) board, opinions split over whether this was due to lax identity verification at Sony’s support desk, or something that could happen on any platform.
Overnight, RealRadec — a prominent fan known for positive engagement with the community and over 30,000 followers on X — became the latest victim of Sony’s poor security.
For anyone who missed the last piece of news — and this part really matters — it turns out an account can be hacked using nothing more than a handful of publicly available details:
If that much info gets exposed and guessed, any account gets hijacked — Nintendo, MS, whoever. And here we go again with the 'Sony's the only bad guy' routine.
21AnonymousOct 4, 2026 12:19
Re: #8 If that were true, there'd be reports of Nintendo and MS accounts getting hit too, right? 🤔 Funny how it's always just Sony getting singled out — almost like the damage really is concentrated there, huh? 😜
35AnonymousOct 4, 2026 12:28
Re: #8 If Xbox purchase history could leak an MS account, the scale of the damage would be on a whole different level. If you're making this up, that's borderline business obstruction (defamation), you know?
10AnonymousOct 4, 2026 12:12
If you still had the disc, you could've just played on another account.
13AnonymousOct 4, 2026 12:13
Isn't this because games like 'Toukon' (a slang nickname, likely for a specific title) started requiring PSN account linking even on the Steam version?
14AnonymousOct 4, 2026 12:14
I haven't played PlayStation in so long, I probably wouldn't even notice if I got hacked.
16AnonymousOct 4, 2026 12:16
Just another day on PlayStation.
36AnonymousOct 4, 2026 12:31
Re: #16 Nah, if this happened to Nintendo or MS, nobody would just shrug it off as 'business as usual.'
17AnonymousOct 4, 2026 12:17
Ah, the annual 'PSN got hacked again' event has begun. It's usually around June, but it skipped this year, so I guess it moved to October lol
19AnonymousOct 4, 2026 12:18
Dammit! Now I can't play Wolverine!
22AnonymousOct 4, 2026 12:21
What are people even supposed to do about this once physical media is gone?
28AnonymousOct 4, 2026 12:23
How do you even guess someone else's purchase history or transaction number?
68AnonymousOct 4, 2026 12:55
Re: #28 Well, for example, around GTA6's release date, it's a safe bet a lot of people bought GTA6 that day. The same logic applies to early-game trophy dates — they can be used to estimate the purchase date too. It's not like they're targeting one specific person and saying 'let's hack THIS guy' — they just find whoever's hackable and go after them.
32AnonymousOct 4, 2026 12:25
Didn't they merge this with the main Sony corporate account system? Isn't that bad news for the whole network business?
40AnonymousOct 4, 2026 12:33
Re: #32 The main Sony corporate account should be fine — they probably just unified the login entry point while keeping the backend separate. If they weren't separate, Sony would have to put out a press release every time PSN leaks data. PSN didn't leak much back in the SCE days, but ever since it became SIE, there's been leak after leak.
42AnonymousOct 4, 2026 12:35
Set up a passkey — it disables password login entirely, so just do it. If you still get hacked after that, it's 100% on Sony.
53AnonymousOct 4, 2026 12:41
Re: #42 Pointless, pointless. In this case, the victim had 2FA and passkey auth set up perfectly and still got hit. What got exploited this time was the account recovery process through the support desk — support will reset your login with just a few easy pieces of info, so there's nothing a user can do to prevent it.
44AnonymousOct 4, 2026 12:36
The fact that your PSN email address can even leak in the first place is already a problem.
48AnonymousOct 4, 2026 12:38
Re: #44 An email address is contact info — it's technically meant to be something you can share. The real issue is that it shouldn't be used as a login ID.
46AnonymousOct 4, 2026 12:37
Re: #40 Uh, the biggest data breach in the world back then happened during the SCE era, though.
63AnonymousOct 4, 2026 12:47
Re: #46 Yeah, exactly? And there wasn't another large-scale or critical one after that — not until it became SIE, anyway.
49AnonymousOct 4, 2026 12:38
Just posting when you bought a game online is dangerous enough already with this. And they want to unify everything under this garbage system lol
51AnonymousOct 4, 2026 12:40
Re: #49 You don't even need to post it — if you pop a trophy on a game's release day, it's a pretty safe bet you bought it that day.
62AnonymousOct 4, 2026 12:47
If this happened to Nintendo Switch Online, it'd be a massive flame war. But with PSN, all anyone thinks is 'here we go again.' In a weird way, that makes them untouchable.
66AnonymousOct 4, 2026 12:52
Re: #62 People do leave PlayStation, though. After that 100-million-scale personal info leak, people left in droves and 'never register your credit card with PS' became common wisdom — that's probably why their active user numbers are so low. Wasn't there also that thing where a PS5 'master key' got stolen? Preventing that from being exploited would basically require a physical part replacement, so it's not really fixable — honestly, just not engaging with Sony at all is the safest countermeasure.
67AnonymousOct 4, 2026 12:54
Re: #25 This isn't really a leak — isn't it just that SIE's support desk is incompetent?
73AnonymousOct 4, 2026 13:02
Re: #67 Apparently the attack works like this: contact support claiming some accident happened and you can't log in normally → support verifies your identity and opens the door for the hacker (the impersonation succeeds during support's identity check, breaking through security) → account takeover complete. Something like that. The PSN 'transaction ID' is apparently kind of like a receipt number — not something people think to actively hide. I guess some people just post their purchase history on social media themselves, like 'hey, I bought this game!'
69AnonymousOct 4, 2026 12:56
There's no way to even know your own transaction ID if your account has a passkey or 2FA set up — you can't even get to that confirmation screen.
74AnonymousOct 4, 2026 13:03
Re: #69 It says 'transaction ID or purchase date,' so if you tell support you don't know the transaction ID, they'll probably just ask when you bought it. And the purchase date is usually right around (or a bit before) the date of your first trophy, so you'd guess right a good chunk of the time.
78AnonymousOct 4, 2026 13:09
Re: #74 Yeah, fair enough. You wouldn't normally tell someone who contacted support because they can't log in to 'just log in and check your transaction number.' So if you get the purchase date right, you can just say 'oh, I already deleted the order email' and breeze right through?
88AnonymousOct 4, 2026 13:16
Re: #78 Even if you can't log into your account, the order confirmation email you get when you buy a game also has the transaction number in it. 'I can't log in so I don't know' doesn't really fly.
93AnonymousOct 4, 2026 13:25
If you can pass verification with just the purchase date, then for any new release you could basically just say the launch date and pass almost every time. Calling that proper identity verification isn't just lax — it's a whole different level of broken.
99AnonymousOct 4, 2026 13:41
Re: #93 That's exactly the point — it's so lax that it's dangerous.
Background and Points of Debate
PSN has history here: SCE (as it was known then) caused a massive personal data breach back in 2011, and that prior record keeps getting cited in the thread. What makes this method different from a typical password leak is that even with 2FA or a passkey set up, it can be bypassed if the support desk’s identity verification is defeated — meaning user-side precautions alone can’t fully prevent it. Since the purchase dates and transaction IDs used for verification can be inferred from social media purchase announcements or trophy unlock dates, even information users think is private can still serve as a clue for guessing. The thread is split between those who argue Nintendo and Microsoft must be just as vulnerable to this kind of attack, and those who say that since reported cases are concentrated on Sony, the problem lies specifically with its support system. No concrete proposal for fixing the identity verification process has emerged.
Leave a Reply