Millions of Fortnite Users Hacked Due To Security Bug | MobileAppDaily
News

Fortnite Hacked: A Massive Loophole Made Hackers Take Over Your Accounts

As per reports, this bug even allowed hackers to eavesdrop on your in-game conversations.

Fortnite Hacked: A Massive Loophole Made Hackers Take Over Your Accounts

Fortnite, created by Epic Games, is undoubtedly one of the most famous video games in the world and accounts for almost half of the company’s $8bn estimated valuation. With such massive popularity, cybercriminals stealing access to player’s account illicitly should not come as a surprise for the game.

However lately, Check Point Research pointed out multiple vulnerabilities in Epic Games’ Fortnite, which allowed hackers to control the players’ accounts, view their personal information, purchase in-game items through their credit cards, and drop into their in-game conversations.

The cybersecurity firm discovered the Fortnite security bug in November, and it was later fixed in January. An Epic Games spokesperson said,

In this case, the issue that caused the security to oscillate wasn’t related to passwords, but instead, was created because the Epic Games’ account page had not been validated. It leads to a redirect URL to a separate, malicious webpage, allowing users’ authorized login tokens to be intercepted by hackers from compromised sub-domain using custom JavaScript codes.

Or in layman language, the hackers sent a malicious link to the users’ Fortnite account, which, when clicked, redirected attackers to a page that stole their login credentials.

Oded Vanunu, Check Point’s Head of Product vulnerability research stated,

How Was Fortnite Hacked?

The Fortnite security flaw initially started due to an Epic Games page from 2004 that created a small loophole for hackers to take over people’s accounts.

Researchers at Check Point found an unsecured URL on ut2004stats.epicgames.com, a records page for the Unreal Tournament that Epic Games first developed in 1998.

Access Tokens are codes generated by different platforms that keep you logged in so you don’t have to hustle every time you open a page. When cybercriminals stole information of around 30 million Facebook users, they used access tokens to do it. Similarly, the Fortnite loophole allowed hackers to log into your Epic games account in many different ways, using these tokens from Facebook, Google and Xbox accounts.

Eran Vaknin, a security researcher at Check Point, said that if you had linked your Epic Games’ account to Facebook, the hack would have to go through the social network.

As the affected page had an Epic Games’ URL, it made victims less suspicious about the whole scenario. Mr. Vaknin further added that the attack is happening without any user interference.

As people are becoming aware of these phishing attacks and more careful about typing passwords on suspicious pages, hackers would be using access tokens instead. It is suggested by officials to use two-factor authentication for your accounts, which Epic Games promote as well.

Tanya <span>Editor In Chief</span>
Written By
Tanya Editor In Chief

She is a content marketer and has more than five years of experience in IoT, blockchain, Web, and mobile development. In all these years, she closely followed the app development, and now she writes about the existing and the upcoming mobile app technologies. Her essence is more like a ballet dancer.

News

Facebook Is Scrapping These Three Apps Due To Low Usage

4 min read  

It is very rare that Facebook shuns something that it has initiated. But you can’t hit the bullseye every time. In a recent move from Facebook, the online social media, and social networking company is shutting down three of its apps due to low usage. The three apps are Hello, Moves, and tbh.

News

Dropbox Ready To Go Public And Seeking $500m Fundraise

4 min read  

Dropbox, the popular file hosting company has finally announced its IPO filing publically. However, we knew about it already, but the company has kept its lips closed about the step till now. In January, there were reports that Dropbox confidentially filed for the US IPO. Since it launches back in 2

News

Google To Add Personalized Feed In Your Event Info

4 min read  

Google is infusing new life into the event feature which it launched last year. The feature helps the users with the information about all the local events. After the launch of the feature, Google conveyed that it was devised to cater to the numerous searches related to local events and activities.

News

How Uber Drivers are Tricking the Company's System to Make Profit

4 min read  

Uber is growing well and expanding its services in many new regions across the globe. But, there is something that needs to be known, you are being cheated in terms of payment, not by Uber but some of its drivers.According to the latest study, some of the drivers from the U.K. and U.S. ditched t