Epic Games, the maker of the game Fortnite, has silently removed a vulnerability from its infrastructure that allowed hackers to access users' accounts with incredible ease.
The vulnerability was discovered by security researchers at Israeli security firm Check Point, who reported the issue privately to Epic Games last year.
“We reported the vulnerability in early November, and by the end of November it had been patched,” Oded Vanunu, one of Check Point’s researchers, told ZDNet.
The vulnerability was actually a combination of multiple bugs in different parts of the company’s infrastructure, some of which were unrelated to Fortnite.
Watch the video:
For a successful attack to occur, users would have to click on a malicious link to connect to Epic Games. Naturally, the vulnerability was a hit with children, who, as less experienced users, were unable to identify the dangerous parameters contained in the link.
“It wasn’t an advanced attack at all, and it was very simple to execute in the background,” Vanunu said. “Login token theft is one of the most emerging attack vectors.”.
Of course, Fortnite accounts are all at risk. As of June 2018, it has been reported that over nine million Fortnite accounts have been compromised by hackers.
Why this game? First of all, because it's popular.
On the other hand, Fortnite's V-Bucks currency is known to be used to launder (real) money by cybercriminals. And it's not just cybercriminals who are after V-Bucks. Teenagers are also getting into the act of hacking into each other's accounts, stealing from each other.
In many cases, hackers don't bother with Fortnite accounts, as all they want is players' money.
_______________________
- KeePass 2.41 New update
- NSA: GHIDRA reverse engineering tool free
- What is Software, Hardware and Motherboard RAID. A Beginner's Guide

