Fortnite Security Flaw Allowed Hackers to Eavesdrop on Chats, Take Over Accounts
To fall victim to an attack, a player only needed to click on a link.

Benoit Tessier/Reuters
A major flaw in the security system of popular online game Fortnite exposed players to undetectable hackers, Variety reports. These hackers could control player accounts, purchase in-game items through their credit cards, and drop into in-game chats posing as the hacked player, cybersecurity firm Check Point Software Technologies discovered in November. The breach was fixed this month, according to a spokesperson for Fortnite. The company, developed by Epic Games, encouraged players to protect their accounts by using strong passwords and not re-using passwords—but in this case, the issue wasn’t related to passwords, as hackers could gain access to an account without any login information. Instead, the security hole was tied to flaws found in sub-domains that were susceptible to a malicious redirect, allowing authentic users to be intercepted by a hacker. To fall victim to an attack, a player needed only to click on a link designed to look like it was coming from an Epic Games domain. “The vulnerabilities we recently found... show how susceptible cloud applications are to attacks and breaches,” said Oded Vanunu, head of products vulnerability research for Check Point.“These platforms are being increasingly targeted by hackers because of the huge amounts of sensitive customer data they hold.”
Register below to read this article for free or subscribe
to unlock unlimited access to The Daily Beast.
Monthly
$1
First month then $5.99/month
Annual
$35
First year then $59.99/year
Premium
$79
First year then $119.99/year
*Substack access provided by the next business day, using your subscription email. Choosing the Premium plan constitutes your permission to share your subscription email with Substack and your agreement to Substack’s Privacy Policy.
Already have an account? Sign In
Looks like you already have a subscription!
You're all set!
Thanks for subscribing.
