A PlayStation Network support-side vulnerability lets attackers take over accounts by providing a username and old transaction ID to customer service, completely bypassing 2FA and passkeys. Here is what happened and how to protect yourself.
A reported vulnerability in PlayStation Network’s customer support verification process allows attackers to take over accounts even when two-factor authentication (2FA) and passkeys are enabled. As of May 2026, the flaw appears to remain exploitable despite being first publicly documented in December 2025. Sony Interactive Entertainment’s own data shows PlayStation Network had 125 million monthly active users as of March 30, 2026, meaning the potential exposure is massive.
The issue was brought to global attention by French journalist Nicolas Lellouche of Numerama, whose PSN account was compromised twice in a single day in December 2025. On May 13, 2026, Lellouche announced his account had been stolen again, demonstrating that months of awareness have not led to a definitive fix.
How the Attack Works
The exploit targets Sony’s customer support process rather than the login system itself. An attacker calls PlayStation support, provides the victim’s PSN username and an old transaction number from a past PlayStation Store purchase, and requests an account recovery. If the support agent accepts these details as proof of ownership, they can change the account’s registered email address, effectively removing all existing 2FA and passkey protections.
According to Lellouche’s reporting and follow-up coverage from outlets like Tech4Gamers and DuckIT Tech News, the attacker who originally compromised his account admitted to obtaining the transaction number from an old screenshot Lellouche had posted publicly. The hacker explained that PlayStation support agents asked only for a username and a transaction number as verification, making the process straightforward to abuse.
ComicBook.com’s coverage added that partial payment card details and console serial numbers can also serve as accepted verification by Sony support in some cases, further expanding the potential attack surface.
Why 2FA and Passkeys Cannot Stop This
This is a critical distinction. Passkeys and two-factor authentication protect the login layer: they prevent unauthorized access when someone tries to sign in with stolen credentials. The reported PSN vulnerability operates at a different level entirely. It exploits the account recovery and support verification workflow, where a human agent can be convinced to override those stronger protections using older account-related details.
As DuckIT Tech News explained, this means users can follow every security recommendation Sony publicly provides and still remain exposed if the support-side process is weak enough. The official PlayStation support pages continue to recommend passkeys, email recovery, and password resets, but no public documentation describes a revised verification system for cases where a support agent is asked to transfer account control.
The Lellouche Timeline: Three Compromises, No Permanent Fix
In December 2025, Nicolas Lellouche’s PSN account was taken over twice within hours. After the first takeover, he contacted PlayStation support and recovered his account by providing his PSN username and a transaction number. Within an hour, the same attacker used the exact same type of information to reclaim the account through support.
Lellouche then made direct contact with the attacker, who confirmed the method. The attacker had found a transaction number in a screenshot Lellouche had posted online years earlier. Sony subsequently marked Lellouche’s account as “high risk” and reportedly instructed customer service agents not to process changes on it.
On May 13, 2026, Lellouche reported his account was compromised yet again. This time, the attack may have come from a different individual, as the account changes did not match the previous incident’s pattern. Lellouche argued that as long as the underlying flaw persists, the method will continue to be used repeatedly by anyone who learns it.
What Makes Transaction IDs Dangerous?
Every PlayStation Store purchase, including free-to-play game downloads, generates a unique transaction ID. This identifier was designed for payment tracking and receipt verification. The security risk emerges when this number is accepted as an identity verification tool during account recovery.
Attackers can obtain transaction IDs from screenshots shared on social media, old purchase receipts posted in forums, images on resale platforms, or even data from older breaches. According to Lellouche’s reporting, groups of individuals are actively collecting such screenshots specifically to take over accounts, making sure original owners cannot recover them.
Sony’s Response (or Lack Thereof)
As of mid-May 2026, Sony has not issued a public technical explanation, transparent acknowledgment, or confirmed protocol change addressing this specific support-side vulnerability. PlayStation’s official support pages still recommend standard security measures like passkeys and 2FA without mentioning the reported support verification weakness.
The only known internal action was the “high risk” marker placed on Lellouche’s account after the December 2025 incident, which ultimately failed to prevent the May 2026 compromise. This suggests that even account-specific protective measures are insufficient without a fundamental overhaul of the verification protocol.
The Broader Digital Ownership Context
This vulnerability arrives at a particularly sensitive moment for PlayStation users. In late April 2026, reports surfaced that Sony had quietly implemented a 30-day online DRM check-in requirement for digital games, meaning players who do not connect their consoles to the internet within 30 days could temporarily lose access to purchased titles.
Combined with the account takeover flaw, this has intensified concerns about the security and permanence of digital game libraries. Accounts containing hundreds or thousands of euros worth of games, save data, trophies, and PlayStation Plus entitlements represent significant financial and personal value that can vanish in minutes through this exploit.
How to Protect Your PSN Account Right Now
Until Sony addresses the support-side verification process, users should take these practical steps to reduce their risk:
- Never share transaction details publicly: Do not post PlayStation Store purchase screenshots, receipts, or order confirmations on social media, forums, or resale sites. Review old posts and remove any that contain visible transaction IDs.
- Secure your linked email account: Enable 2FA on the email address connected to your PSN account. Use a unique, strong password for it. If your email is compromised, the attacker gains an additional vector.
- Keep passkeys and 2FA active: While these measures cannot prevent a support-side override, they still protect the login layer against conventional attacks.
- Use a password manager: Tools like Bitwarden or 1Password help generate and store unique credentials for every account, preventing credential stuffing attacks.
- Remove stored payment methods: Consider removing credit or debit cards from your PSN account and using prepaid PlayStation Store cards instead.
- Guard your console serial number: This information can also reportedly be used as identity verification by support agents.
- Monitor account activity: Regularly check for unfamiliar transactions, email change notifications, or settings modifications. Act immediately if anything looks suspicious.
Understanding the Social Engineering Angle
This type of attack falls under the cybersecurity category of social engineering: manipulating people rather than exploiting technical systems. The attacker does not need to crack encryption or intercept data packets. They simply need to convince a human support agent that they are the account’s rightful owner.
According to Kaspersky’s security guidance, the foundational principle against social engineering is “never trust, always verify.” For users, this means treating even seemingly harmless account identifiers as sensitive data. For service providers like Sony, it means designing verification processes that cannot be satisfied by information that may have been publicly or semi-publicly available.
The PSN case demonstrates that the weakest link in digital security is often not the technology but the human process surrounding it. Until Sony strengthens its support verification workflow, user vigilance remains the primary defence.
What Players Usually Ask About This Issue
Can my account really be stolen even with 2FA and passkeys enabled?
Based on multiple reports, yes. The attack does not target the login screen. It targets the customer support process, where an agent can override security protections when presented with a username and a transaction number.
Am I at risk if I have never made a purchase?
Even free-to-play downloads and free game claims generate a transaction ID. If you have completed any transaction through the PlayStation Store, you could potentially be targeted.
What should I do if my account is compromised?
Immediately reset your password from a secure device. Sign out of all devices through account management. Re-enable 2FA. Review your purchase history for unauthorized transactions. Contact PlayStation Support directly and report the incident.
Has Sony acknowledged this vulnerability?
As of May 2026, Sony has not released a public statement detailing changes to its support verification process in response to this specific issue. The company’s official support pages continue to recommend standard security measures without referencing the reported support-side weakness.
Is there anything PlayStation can do to fix this permanently?
The most effective fix would be to overhaul the identity verification process used by customer support agents, requiring stronger proof of ownership that cannot be obtained from public screenshots or old receipts. Until such changes are confirmed, users should treat all account-related information as confidential.
Account security is a foundational concern for anyone investing in digital gaming. For more insights on safe account practices and verified trading processes, the GamerMarkt guide on secure account transactions covers relevant security principles that apply across platforms.










