Pokemon resets some users passwords after hacking attempts

Date:

Share post:


The Pokemon Company said it detected hacking attempts against some of its users and reset those user account passwords.

Last week, an alert was visible on Pokemon’s official support website, which said that “following an attempt to compromise our account system, Pokemon proactively locked the accounts of fans who might have been affected.”

The alert about hacking attempts that The Pokemon Company posted on its official support website.

As of Tuesday, the alert is gone. A spokesperson for the company said there was no breach, just a series of hacking attempts against some users.

“The account system was not compromised. What we did experience and catch was an attempt to log in to some accounts. To protect our customers we have reset some passwords which prompted the message,” said Daniel Benkwitt, a Pokemon Company spokesperson.

Pokemon is a wildly popular game franchise with hundreds of millions of players around the world.

Benkwitt said that only 0.1% of the accounts targeted by the hackers were actually compromised, and reiterated that the company already forced the impacted users to reset their passwords, so there isn’t anything to do for people who have not been forced to reset their passwords.

The description of the Pokemon account breaches sounds like credential stuffing, where malicious hackers use usernames and passwords stolen from other breaches and reuse them on other sites.

A recent example of a similar incident is what happened last year to the genetic testing company 23andMe. In that case, hackers used leaked passwords from other breaches to break into the accounts of around 14,000 accounts. By breaking into those accounts, the hackers were then able to access the sensitive genetic data on millions of other 23andMe account holders.

That prompted the company (and several other of its competitors) to roll out mandatory two-factor authentication, a security feature that prevents credential stuffing attacks.

For its part, the Pokemon Company does not allow its users to enable two-factor on their accounts, when TechCrunch checked.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Hydrow, the at-home rowing machine, announced Thursday that it has acquired a majority stake in Speede Fitness,...

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced...

India weighs delaying caps on UPI market share in win for PhonePe, Google Pay

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the...

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on...

Apple’s ‘Crush’ ad is disgusting

Apple can generally be relied on for clever, well-produced ads, but it missed the mark with its...

OpenAI offers a peek behind the curtain of its AI’s secret instructions

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite...

US Patent and Trademark Office confirms another leak of filers’ address data

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private...

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police...