PlayStation Network account security flaw reportedly remains unresolved six months after warning
A reported PlayStation Network account security weakness is facing renewed scrutiny after a journalist who helped expose the issue in December said his account had been compromised again.
The issue centres on Sony’s customer support account recovery process, which has allegedly allowed attackers to take over PlayStation Network accounts even when two-factor authentication and passkey protection are enabled. According to earlier reports, attackers may be able to persuade support staff to transfer account control by providing limited account details, including a transaction number from a previous PlayStation Store purchase.
The latest incident was reported by French technology journalist Nicolas Lellouche, who said this week that his PlayStation account had again been accessed without authorisation. Lellouche had previously drawn attention to the issue in December 2025, when his account was reportedly taken over despite modern security protections being active.
The concern is that the weakness does not appear to sit in the user’s password, device or two-factor authentication setup, but in the way account ownership is verified through support channels. If an attacker can use a transaction ID or other purchase-related information to convince support that they are the rightful owner, then passkeys and two-factor authentication may be bypassed at the recovery stage.
Reports from the original December incident said the transaction number used by the attacker came from an old screenshot of a PlayStation Store invoice. That detail has alarmed players because screenshots of receipts, purchase confirmations or support interactions are often shared online without people realising that seemingly harmless identifiers may later be used against them.
Wccftech reported that the only protection allegedly applied after the first incident was a “high-risk account” marker instructing customer service not to intervene. Lellouche’s account has now reportedly been compromised again, raising questions about whether that measure was temporary, insufficient or inconsistently applied.
The renewed report is especially troubling because the latest intrusion does not appear to have followed the exact pattern of the previous one. According to Wccftech, the new intruder reportedly did not change the account ID and appeared to play different games, suggesting the issue may not be limited to one retaliatory attacker.
For PlayStation users, the risk is significant. A compromised PSN account can put a digital game library, wallet funds, saved payment methods, trophies, subscriptions and personal information at risk. For players who have spent years building a digital collection, losing access to an account can mean losing access to hundreds or thousands of dollars in purchases.
The case also highlights a growing problem in account security. Passkeys and two-factor authentication can make direct login attacks much harder, but support workflows can become the weak point if recovery procedures rely on information that may have been exposed, reused or shared publicly.
Until Sony addresses the reported support-side weakness, users should avoid posting screenshots of PlayStation Store receipts, order confirmations, transaction IDs, support chats, email headers or account pages. Even information that does not look like a password may help an attacker convince a support agent that they own an account.
Players should also review their PSN security settings, use a passkey where available, enable two-factor authentication, remove old payment methods if they are not needed, and avoid sharing account details in forums, social media posts or resale listings.
Sony has not publicly confirmed a specific fix for the alleged account recovery weakness. The continued reports suggest that, for some users, the most important security advice may be less about login settings and more about protecting every fragment of account ownership evidence from public view.
Photo Credit: DepositPhotos.com
