← Nintendo

2020 — Nintendo: Approximately 160,000 Nintendo accounts were…

2020 160.0K records affected Share on X

Data compromised

Usernames, nicknames, DOB, emails, payment access

Technical writeup

Apr 2020. Approximately 160,000 Nintendo accounts were compromised via the legacy Nintendo Network ID (NNID) system. Attackers used credentials obtained from outside Nintendo's service to access linked accounts, make fraudulent purchases (e.g., Fortnite V-Bucks), and access usernames, nicknames, dates of birth, countries, and email addresses. Nintendo disabled NNID logins and recommended 2FA.

Root cause

Credential stuffing; NNID legacy system exploited.

References