Full Breakdown
Sony’s Unpatched PSN Account Recovery Flaw Enables Ongoing Hijacks
5/14/2026, 7:48:15 AM
Unresolved Exploit Allows Full Account Takeover
A flaw in Sony’s PlayStation Network (PSN) account recovery lets attackers seize entire accounts. Providing a valid transaction or invoice number convinces PlayStation Support to reset credentials, change the email, disable two-factor authentication and gain full control of the user’s game library.
Recovery Process Relies on Transaction IDs
Sony’s verification treats purchase identifiers as proof of ownership. Support agents accept transaction IDs as “master keys,” allowing them to bypass standard checks, which enables a social-engineering attack without malware or password cracking.
Key Individuals and Entities
- Nicolas Lellouche – Numerama journalist whose PSN account was compromised twice.
- Sony Interactive Entertainment – Owner of PSN and operator of the recovery service.
- PlayStation Support – Customer-service team handling recovery requests.
Timeline of Reported Incidents
December 2025 – Lellouche’s account first hacked after a screenshot exposed an old transaction ID.
May 13 2026 – He posted on X that the account was hijacked again, noting no fix.
May 2026 (ongoing) – Sony has issued no public comment; the flaw remains unpatched.
Data & Statistics
Only a transaction ID or invoice number is required to trigger a reset, bypassing 2FA and passkey protections. Sony’s “high-risk” flag applied after the first breach expired in December 2025, leaving the account vulnerable again.
Implications for Gamers
Digital purchases are tied to the PSN account, not the console, so a takeover can permanently lock the owner out of their entire library, trophies and progress. Users risk losing years of content if they cannot prove ownership to Sony.
Official Response
Sony has not released a public comment on the flaw. Support agents continue to follow the existing verification protocol that relies on transaction details. No patch or policy change has been announced.
Criticism and Concerns
Technology writers and community members criticize Sony for leaving the recovery mechanism unchanged despite repeated exploitation. The attacks have been described as “a concern among netizens” and a “clearly unaddressed security gap.”
First-hand Account
Lellouche says the attacker returned within days after he regained access with Sony’s help. He notes that the support team restored his account quickly once he supplied the requested transaction ID, showing how the process can be abused.
Conflicting Information and Gaps
Public sources give no data on how many users may be affected or whether Sony has internally tested a fix. The lack of an official statement creates uncertainty about the remediation timeline.
Verbatim Quote
> “You remember the hacking of my PlayStation account that went around the world and that Sony still hasn’t fixed? I got hacked again last night. Here we go again. (Don’t buy digital games!)” — Nicolas Lellouche, journalist, Numerama
Recommendations and Outlook
The articles recommend avoiding public screenshots, invoices or transaction numbers and exercising caution when sharing PSN usernames with purchase history. Enabling 2FA and using strong, unique passwords remains advisable, though it does not fully mitigate the social-engineering risk. Until Sony revises its verification process, the vulnerability remains unaddressed.
