Your PSN account isn't safe. Anyone can steal your account just by knowing your public username because
@PlayStation Support has a proven track record of being bribed and phished.
This happened to
@Hak00m_ in 2024, and now to dav1d_123 last week -- 2 of the most high-profile PlayStation players in the world.
--------------------
Hakoom's Incident: PS Support Bribery & PACMAN
--------------------
If you're unfamiliar with Hakoom, he was a popular content creator in the PlayStation ecosystem and was the #1 ranked trophy hunter for several years.
@PlayStation recognized his success with various sponsorships. His account got stolen last year, and although he eventually recovered it, he retired from PlayStation consoles due to how poorly Sony handled the situation. He documented the full story here:
x.com/Hak00m_/status/1856790…
The most interesting detail of Hakoom's incident is the leaked footage of a PS Support Agent's computer screen:
x.com/Hak00m_/status/1976238…
It shows a utility internally named "PACMAN" (PlayStation Account & Customer Manager). All PS Support Agents can access PACMAN for any user and view the user's payment method history, transaction history, and the serial number of the user's first console -- everything you'd need to recover/verify your account. I could write an entire post about all the security principles being violated here, but the very existence of the leaked PACMAN footage says it all.
The existence of the video proves there was/is at least 1 bad actor working at PS Support. While the motive is unconfirmed, Hakoom's incident includes evidence that the Support Agent was bribed.
--------------------
dav1d_123's Incident: PS Support Phishing
--------------------
I'll just call him "David". If you've heard of him, it's because he's been the #1 ranked trophy hunter for the past 1-2 years. We've been close friends for 9 years (when he only had ~300 platinums, now he has 16,000 ), and together we own
@GGmuksInc. David doesn't have (nor care for) a social media presence, which is why I'm writing this post.
On October 7, David's PSN account was compromised despite his account being secured by Authy 2FA. He never received any email that his security info had been changed. And contrary to what casual trophy hunters mindlessly parrot (like in these comments:
old.reddit.com/r/Trophies/co…), David is, and always has been, the sole person playing games and popping trophies on his account. He's never even game shared with anyone but me. So no, this wasn't an 'inside job'.
As of October 13, David still can't access his account despite several calls with PS Support. I can provide a full timeline of events, but for now there's a single event I'd like to focus on...
On Oct 7, I tried the bold strategy of messaging David's compromised account, asking the attacker how he got access. To my surprise, he was more than happy to boast about it:
The attacker ("Zzyuj", formerly "dav1d_123") reveals "it's possible to get access to any user just by knowing the [public] username". He claims you just need to keep calling PS Support until someone believes your story. He attributes it to Sony outsourcing PS Support to less developed countries, but frankly, I don't want any country's PS Support to have this much power. Bad actors can exist anywhere, as you'll see next.
--------------------
The "Underground" Industry of Account Sellers
--------------------
I say "underground", but it hardly is -- one of the most prominent account sellers goes by "Nich" and has 900,000 followers on Instagram (
instagram.com/nich.legend/). People like Nich make money by stealing accounts (Discord, PSN, etc) and then selling them to (or scamming) people. They typically target accounts with 3- or 4-letter names (they call them "3Ls" / "4Ls"), since those are rare and more valuable, but they're also known to target other accounts if they have an interesting username or are high-profile (like David's).
Speaking of Nich... The attacker initially renamed David's account to "NichTheLegend", and Nich posted an IG Story taking credit:
(More about Nich, including his PSN ID "Audi":
imgur.com/a/david-hack-profi…)
One place these people congregate is a public Telegram group called "ComsChatter" (Nich is an admin). Stolen account credentials are often leaked here, as was David's:
Make no mistake -- PS Support is the root issue. These cockroaches are merely the side effect of that issue, and they will continue to exist as long as PS Support has as much power as they do.
Like I said, bad actors can exist anywhere, so this isn't necessarily an issue of PS Support being outsourced to less developed countries (though that certainly doesn't help). One of these account sellers could work at PS Support for all we know:
--------------------
WHO IS AT RISK?
--------------------
After reading this, you might think you're safe if you don't have an interesting or 3L/4L username and aren't a high-profile account such as being a top-ranked trophy hunter. But that couldn't be further from the truth. Hakoom got his account back, and I'm confident David will too, precisely because they are high-profile figures.
All it takes is for you to catch the attention of the wrong person. Maybe you upset them in a CoD/FIFA match, or an internet argument, or they see a post where you brag about having a lot of games. That's all it takes for you to be a target too.
--------------------
CLOSING
--------------------
It's disheartening that nothing changed after Hakoom's incident, despite it going viral with millions of YT views and several news articles written about it. I don't know if there's any way to truly affect change at
@PlayStation, but making this post seems like a good place to start. Please share it as far as you can.
I'm happy to elaborate on anything or get news outlets directly in touch with David.
CC:
@Kotaku @Dexerto @IGN @MSN @gameranx @pushsquare @MysticRyan