Account security
Quick answer
A game account is the single point holding a roster, a purchase history and usually an email address, which is what makes it worth taking. The two measures that do most of the work are a password used nowhere else and multi-factor authentication on both the game account and the email address that can reset it.
Account security in free-to-play games is the practice of keeping control of the credentials that unlock an account and the recovery channel behind them. The account is the asset: it holds months of progress, any purchases made, and a link to a real identity through an email address or a linked social or platform login.
The risks in this category are not exotic. They are the ordinary ones — reused passwords, credential phishing, and account-recovery flows exploited through social engineering — applied to an asset whose owner is often a teenager and whose value is obvious to anyone looking at the roster.
How the account is structured
Most titles support more than one way to sign in, and the differences matter when something goes wrong.
- Publisher account
- An email address and password held by the game's publisher. Portable across devices, recoverable by email, and only as secure as the mailbox behind it.
- Platform or social login
- Sign-in delegated to a platform or social account. The game never holds a password, which removes one risk and concentrates another: whoever controls the platform account controls the game account.
- Device-bound or guest progress
- Progress stored against a device identifier with no credentials attached. Convenient at install and the usual cause of permanently lost accounts, because there is nothing to recover with.
The first action after installing
Where a game starts an account as device-bound or guest progress, binding it to a real credential is the step most worth taking early, before there is anything to lose. Progress existing only against a device identifier generally cannot be restored by support after a device is reset, replaced or lost, because there is nothing to prove ownership with.
How accounts are actually taken
Three routes account for most compromises, and none of them involves breaking the game's own security.
Credential reuse. A password used on the game and also on an unrelated service is exposed when that unrelated service suffers a breach. Automated attempts against game logins using lists of previously exposed combinations are cheap to run and need no skill. A password used in exactly one place removes the entire route.
Phishing. A message — by email, in-game chat, a community server or a video comment — offers currency, a rare character, a giveaway entry or an early look at a feature, and leads to a page asking for the account login. The page is a copy. Variants include a fake support agent asking for credentials to restore an account, and a trade offer requiring a login on an external site. Scamwatch collects reports of this pattern and publishes current examples.
Recovery-channel attack. The mailbox behind the account is compromised, or support is persuaded to transfer an account using details an attacker gathered from public profiles. The defence is to secure the mailbox at least as well as the game account, since the mailbox can reset it.
Measures that make a difference
| Measure | What it prevents | Effort |
|---|---|---|
| A unique password per account | Credential reuse attacks entirely | Low, with a password manager |
| Multi-factor authentication on the game account | Login with a stolen password alone | Low, where the publisher offers it |
| Multi-factor authentication on the mailbox | Takeover through password reset | Low |
| Treating every unsolicited offer as untrusted | Phishing in chat, email and community channels | A habit rather than a setting |
| Keeping purchase receipts | Nothing — but it supports an ownership claim during recovery | Low |
| Reviewing linked applications and sessions | Access that persists after a password change | Occasional |
The Australian Cyber Security Centre publishes general guidance for individuals on passphrases, multi-factor authentication and recognising phishing, written for a general audience rather than for gaming specifically, and it applies directly here.
Worked example: a trade that is not a trade
A player receives a direct message offering to transfer a rare character in exchange for an in-game item. The sender provides a link to a site styled like the publisher's, which asks for the game login to verify the roster. Two features identify it without any technical check: the publisher's game does not transfer characters between accounts in the way described, and no legitimate verification process asks for a password on a site reached from a direct message. The appropriate response is to use the in-game report function and to report the approach to Scamwatch; no action on the player's own account is needed, because nothing was given away.
If an account has been taken
- Change the password on the email address first, then on the game account, and enable multi-factor authentication on both if it is not already on.
- Sign out of all other sessions where the publisher or platform provides that option, since a password change alone may not end an existing session.
- Contact the publisher's support through a route reached from the game or the publisher's own site, never through a link received in a message. Provide purchase receipts, the original registration email and the approximate creation date — these are the details that support ownership.
- Where money was taken or a payment method was used, contact the card issuer or payment provider promptly and report the incident to Scamwatch.
- Check whether the same password was used anywhere else and change it there too, since the exposure is rarely confined to one service.
Recovery outcomes vary by publisher and this site cannot predict them. What consistently improves the odds is documentary evidence of ownership held outside the account, which is a reason to keep receipts somewhere other than the mailbox that was compromised.
A note on what this entry does not say
Nothing on this page is a statement about the reader's own device or account, and this site performs no check of any kind on the visitor. The measures above are general practice, published by the bodies linked, and are worth applying in advance rather than in response to a prompt from any page, including this one.
Key terms used in this entry
- Credential stuffing
- Automated login attempts using combinations exposed in breaches of other services.
- Multi-factor authentication
- A second proof of identity at login, in addition to a password.
- Phishing
- A message or page imitating a legitimate party to obtain credentials.
- Account binding
- Attaching device-held progress to a recoverable credential.
- Session
- An existing authenticated connection, which may survive a password change.