Nintendo says 160K Nintendo accounts were compromised since the beginning of April using credentials obtained illegally by “some means other than our service”
We would like to provide an update on the recent incidents … Tom Phillips / Eurogamer.net : Nintendo confirms up to 160,000 accounts accessed in huge privacy breach Lindsey O'Donnell / Threatpost : Nintendo Confirms Breach of 160,000 Accounts Shubham Agarwal / Digital Trends : Nearly 160,000 Nintendo accounts compromised in massive hack Theo Salaun / dexerto.com : Nintendo confirms major security breach impacted 160,000 accounts Sasha Lekach / Mashable : Nintendo confirms unauthorized access of 160,000 accounts Waqas / HackRead : Nintendo accounts hacked: 160,000 accounts accessed by hackers Harry Pettit / New York Post : Crooks hijack 160K Nintendo accounts to make digital purchases Catie Keck / Gizmodo : Your Nintendo Account May Have Been Exposed, So Here's How to Enable 2FA Jacob Siegal / BGR : Nintendo says 160,000 accounts were hacked in security breach Lance Whitney / TechRepublic : How to protect your Nintendo account after the recent data breach Ben Gilbert / Business Insider : Nintendo says that at least 160,000 Switch users' accounts have been hacked Ash / MSPoweruser : Nintendo discontinues Nintendo Network ID logins after reports of accounts being hacked Chris Nuttall / Financial Times : The PC viruses carried by Covid-19 Tweets: @nintendeal : Official statement from Nintendo regarding unauthorized access to some accounts https://www.nintendo.co.uk/... They have disabled the ability to use Nintendo Network ID to sign into a Nintendo account Heavily encourage users to enable two-step verification https://twitter.com/... Joe Ortiz / @leojtravis10 : Time to create very strong passwords and enable app-based 2FA (if available) folks. No excuse not to do so. https://twitter.com/... @nintendoeurope : In response to recent incidents related to some Nintendo Accounts, it is no longer possible to sign into a Nintendo Account using a Nintendo Network ID. We apologise for any inconvenience caused. Please visit our Support website for more information: http://r.socialstudio.radian6.com/ ... Tom Phillips / @tomphillipseg : Not quite a PSN hack moment, but a painful security breach for Nintendo. And questions to be asked - if this has been ongoing since early April, why has it taken so long for Nintendo to realise? https://www.eurogamer.net/... Catalin Cimpanu / @campuscodi : Nintendo has now disconnected the NNID login feature from the primary Nintendo login system. This comes after I reported earlier this week how hackers were accessing Nintedo accounts to buy Fortnite currency and other games. See hacking service ad below. https://www.zdnet.com/... https://twitter.com/... David Amador / @dj_link : PSA: there seems to be a wave of Nintendo accounts being hijacked, don't forget to turn on 2 Factor Authentication, & changing password now just to be extra safe, when was the last time you changed it anyway? https://www.zdnet.com/... Tom Warren / @tomwarren : Nintendo has confirmed that 160,000 Nintendo Accounts have been accessed in recent hacking attempts. Some account owners have reportedly fraudulent purchases like Fortnite VBucks. Details here: https://www.theverge.com/... https://twitter.com/...
Context & Ripple Effects
Account takeover via stolen credentials is a recurring failure mode for gaming platforms: Twitch responded to a compromise in 2015 by resetting passwords for every user, and Steam patched a password-reset exploit that same summer. Nintendo's disclosure follows the same script but with a twist it emphasizes: the credentials were obtained 'by some means other than our service,' pointing to reuse of logins exposed elsewhere rather than a direct breach of Nintendo's systems.
The immediate fix was structural — Nintendo cut off Nintendo Network ID as a sign-in method, severing the older Wii U/3DS-era credential from modern Nintendo Accounts. Two months later the company nearly doubled the count, confirming 300K compromised accounts with dates of birth, email addresses, and nicknames among the leaked data.
First-order effects
- Roughly 160,000 account holders face unauthorized access to their Nintendo Accounts, and every user who signed in with a Nintendo Network ID loses that login path immediately.
- Nintendo must absorb the support and remediation load of auditing affected accounts while communicating that its own service was not the source of the leaked credentials.
Second-order effects
- The incident pressures Nintendo to make two-factor authentication the default rather than optional, since reused-password attacks bypass password strength entirely.
- Other platforms still federating legacy credentials into modern accounts — the same NNID-style bridge Nintendo just severed — face renewed scrutiny over whether old login systems widen their attack surface.
Third-order effects
- As consoles become services whose accounts carry purchase histories and digital libraries, those identities become standing targets for credential-stuffing campaigns sourced from breaches elsewhere, pushing the industry toward killing legacy sign-in federation and mandating second factors.
- If the pattern holds across platforms like the ones hit in 2015 and Nintendo now, regulators and platform operators will increasingly treat account-takeover volume — not perimeter breaches — as the primary security metric for consumer services.
The trend: Gaming platform accounts are becoming the recurring casualty of credential reuse, forcing platform holders to retire legacy login systems and harden authentication as their stores and libraries move onto those identities.