Nintendo Switch breach exposes 160,000 users: What to do now

Nintendo Switch Lite
(Image credit: Tom's Guide)

Nintendo has confirmed that up to 160,000 Nintendo accounts have been accessed in a massive data breach that exploited accounts with no two-factor authentication enabled. (To be clear, there has been no data breach at Nintendo; these accounts were likely compromised because their owners reused passwords from other accounts.)

We previously reported that cybercriminals have been targeting Nintendo accounts, with users receiveing emails that alerted them to the new logins. Given that such accounts can contain personal data as well as payment details, the cyber-attacks are also potential privacy breaches.

Nintendo released a statement in Japanese, noting that hackers have been impersonating the “Nintendo Network ID” process from the start of April. This resulted in “illegal” logins to a swathe of Nintendo accounts. 

The company said the data that could have been accessed is the user’s nickname, date of birth, gender, country/region and e-mail address. So far, it looks like no payment details were accessed. 

However, the cybercriminals were sometimes able to make purchases via linked payment methods. This has lead to some people having their accounts charged for up to £100 (around $123) worth of digital items.

It's important to note that the malefactors could not actually see users' payment details in full, though, meaning that they could not steal credit card and PayPal info directly. However, Nintendo warns that users' financial information could be at risk if they employ the same username and password for both their Nintendo and bank or PayPal accounts.

Nintendo is now advising Nintendo account holders to reset their passwords when they get an e-mail notification from the company. And for those already logged in, they are advised to re-login. 

Users should also avoid having the same password for their Nintendo account as they have for other services, especially payment services like PayPal.

If your account has been breached and someone has purchased a game using your details, Nintendo recommends you contact the company. 

The Big N will then conduct an “individual investigation” and cancel the purchase. But be prepared to be patient as Nintendo noted: “We will respond. Please wait as we will proceed with the procedure in sequence.”

Nintendo also apologised for the data breach and said it will “make further efforts” to strengthen its security and ensure that similar events don’t occur in the future.

One way to prevent further intrusions is to ensure you have two-factor authentication (2FA) enabled for your Nintendo account. This means that you get a prompt on your phone with an extra code while logging in, thus making the process more secure. Here's how to set up Nintendo 2FA.

Roland Moore-Colyer

Roland Moore-Colyer a Managing Editor at Tom’s Guide with a focus on news, features and opinion articles. He often writes about gaming, phones, laptops and other bits of hardware; he’s also got an interest in cars. When not at his desk Roland can be found wandering around London, often with a look of curiosity on his face. 

Latest in Nintendo
Nintendo Switch 2
Nintendo Switch 2 — industry insider just tipped release month and launch plans
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Nintendo Switch 2
Nintendo Switch 2 — 7 biggest questions that need answers at Nintendo Direct April 2
Nintendo Switch 2
Nintendo Switch 2 — these are the 5 launch games that would make me buy on day one
The Legend of Zelda Tears of the Kingdom screenshot
Massive Nintendo Switch game sale live from $4 — 19 deals I'd buy now
Nintendo Switch 2
Nintendo Switch 2 just tipped for three display upgrades — here's what we know
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now