Employees | 4 min read

Cybercriminals Use Fortnite to Target Children, Bank Accounts

  

Want to get updates on InfoArmor News?

If you have a 15-year-old, or simply know someone who does, then chances are you’ve heard of Fortnite. Last year, it became the most popular video game on Earth, with an estimated 125 million users, and new reports suggest that number might have grown to 200 million.

Unfortunately, it’s not just a fun pastime for video game enthusiasts. Hackers, identity thieves, and cybercriminals are now using the platform to commit a wide array of crimes, targeting both your children and your bank account.

A security flaw exposes millions

In a report issued January 16, researchers from Check Point Software Technologies Ltd. found that a security flaw in the authentication process allowed hackers to send players malicious links. Once these links were clicked, cybercriminals could make in-game purchases on the victims’ accounts. The purchased items could then be transferred or sold to other users.

Equally troubling, hackers could also access the victim’s private messages and read their chat history. This is particularly troubling given the fact that many players are children, and hackers might have gained unprecedented access into their lives.

As of the publishing of this article, it’s unclear whether hackers actually exploited the vulnerability Check Point discovered. Epic Games, the creators of Fortnite, told Bloomberg they corrected the issue shortly after the discovery:

“We were made aware of the vulnerabilities and they were soon addressed. We encourage players to protect their accounts by not re-using passwords and using strong passwords, and not sharing account information with others.”

Criminals using Fortnite to launder money

This isn’t the only negative publicity Fortnite received in January. An investigation by cyber intelligence firm SixGill found that cybercriminals are using the popular game to launder money.  Here’s how the scam works.

  • Cybercriminals obtain stolen credit and debit cards
  • They create new Fortnite accounts
  • Using the stolen payment details, they purchase in-game currency and skins (outfits for a character or avatar)
  • Cybercriminals then sell the account for a fraction of the amount of in-game currency and skin value on eBay or the dark web
  • After receiving payment, they transfer the Fortnite account and password to the buyer

When Variety contacted Epic Games for comment, the game manufacturer released a statement that sounded frighteningly familiar:

“Epic Games takes these issues seriously, as chargebacks and fraud put our players and our business at risk. As always, we encourage players to protect their accounts by turning on two-factor authentication, not re-using passwords and using strong passwords, and not sharing account information with others.”

Fortnite isn’t alone

Data breaches and security incidents aren’t isolated to Fortnite. Many video games have undergone their own privacy-related scandals in recent months, with two of the most significant being Fallout 76 and League of Legends.

Fallout 76, one of the most-anticipated games of all time, experienced a massive data breach last December. When some users were redeeming in-game items, they were inadvertently granted access to the support tickets of other players, as well as other sensitive data like addresses and contact information.

League of Legends, another massively popular online game, continues to put its users at risk due to improper default voice chat settings. If strangers are invited to join your child’s lobby or party, they can easily spy on their conversations with others.

Safety practices for gaming platforms and beyond

Often, we place ourselves ⁠— and our families ⁠— at risk by not properly evaluating the impact of our online decisions. That’s why it’s incredibly important to stay vigilant online, even while gaming.

If you’re a gamer, make sure to check through your privacy settings on all your platforms, and check back in every so often, especially if there’s an update. If you have children, teach them to do the same. For more information about preserving kids’ online safety, check out ESRB, which has some helpful tips.

Whether or not there’s a gamer under your roof, there are additional steps you can take to protect your privacy ⁠— and the privacy of your family. One smart way to stay safe online is to reduce the size of your digital footprint. From making an in-game purchase to putting up an away message, almost everything you do on the Internet leaves a trace. Limiting what you share is a good first line of defense. 

And to learn more about staying as anonymous as possible, you can download our complimentary guide, Protecting Your Privacy: Best Practices for Mobile, Social, and Search Settings.

  
New Call-to-action
At InfoArmor, we believe everyone deserves the right to privacy, security, and above all else, peace of mind. This is why we’re proud to offer industry-leading solutions for employee identity protection and advanced threat intelligence. From enterprise to employee, InfoArmor redefines how organizations combat an ever-changing cyber threat landscape. If you’d like more information on how we can help your organization protect its most valuable assets, reach out. We’d love to hear from you.