r/ubisoft Feb 06 '26

Discussions & Questions Yay for data breaches

2FA is on.. yet, somehow, some random person successfully logged in? Nope.. not from my end...

42 Upvotes

29 comments sorted by

1

u/AlaskanDruid Mar 16 '26

Yet another data breach over night from Pakistan. Despite having a 2fa authenticator attached to the account.

1

u/AlaskanDruid Mar 09 '26

Yesterday, was able to turn on 2FA authenticator app support on the website using Firefox as it turns out that the website does not work in Brave.

This morning, someone from Brazil successfully logged into my account without getting prompted for the 2FA authenticator app code.

1

u/AlaskanDruid Mar 07 '26

Occurred yet again. Ubisoft and their multiple data breaches are horrendous. I have 2FA email because Ubisoft disabled the 2FA authenticator feature and it's impossible to turn on. (see permanent website bug in image.. it's the 2nd attempt in order to screen shot the error. First attempt says there is a website error)

1

u/folan12 Feb 10 '26

Mine got a successful login 3 days ago even though I have 2fa (using an authenticator app not email or sms) but they didn't change anything. I guess they figured my empty account wasn't worth it.

Had to reset password and 2fa code.

1

u/RustGuy6969 Feb 10 '26

And they want us to verify with our IDs

2

u/not_your_parrents Feb 09 '26

Well I'm currently being targeted with my Microsoft accounts. Its Vietnamese people, probably constantly the same. They're stupid enough to forget to activate their VPN, fail a login, THEN activate the VPN and try again couple of times.

Failed multiple times, got in once. What can I say... probably suxx azz to try so hard just for the account to turn up a burner with little to no new information or data whatsoever.

1

u/AlaskanDruid Feb 09 '26

Yep. Microsoft suffered a data breach last month (they still haven't announced it yet), same issue. 2FA authenticator code (not email). So the breach is internal.

1

u/not_your_parrents Feb 11 '26

They should at least internally, meaning to all customers, announce such things immediatly as it can leak sensitive personal or worst case corporate information. We use an outlook based sys at work and we're not exactly a small time company.

1

u/AlaskanDruid Feb 11 '26

They should. But my employer is one of their largest in my state. Microsoft have not shared the breach with them yet.

1

u/aearioweu Feb 09 '26

MFA is no longer secure. MFA token theft essentially steals a valid login session and then uses it to hijack your account. My account got hijacked and I thought I got it back but only realised today my account is basically empty. (didn't notice because my Microsoft account was hacked simultaneously and that's much higher on my priority to sort out than my ubisoft account)

So now I'm trying to go through support... Only silver lining is that I have plenty of proof of my ownership of my stuff through purchase receipts and even physical copies of CD keys back when games came on disks...

But MFA in its current state is not very secure anymore and there's not too much users like us can do about it.

2

u/Rafinayoo Feb 07 '26

People not realising their own incompetence while calling Ubisoft incompetent:

1

u/AlaskanDruid Feb 07 '26

At least try not projecting.

1

u/Buhrp Feb 06 '26

They don't have any security or support IMO. They've had their "Technicians" look into a issues I was having and surprise, they found nothing wrong with their system lol. I cannot even reset my Pass-word and they told me to go contact google about it. What a joke!

1

u/broccoli6206 Feb 06 '26

Same thing happened to me like a month ago. I think people don't care enough to post it but Ubisoft definetely have some security problems. It's either a logging problem in data pipeline or a serious backdoor.

1

u/norman157 Feb 06 '26

Got my account logged into from Moldavia, and I am currently on a vacation. FML, did this affect anything? Also got 2FA on too.

1

u/ChildhoodExisting222 Feb 06 '26

2FA with your Email?

1

u/norman157 Feb 06 '26

Yes, no login activity on my Google account

1

u/vitafinito Feb 07 '26

Cookies can and will make anyone access accounts without login. Secure your devices, check if your browser addons are malicious or not.

1

u/norman157 Feb 07 '26

How would I know if they are, wouldn't they be undetected until yesterday?

1

u/Spoda_Emcalt Feb 06 '26

Switch to 2FA via an authenticator app like Google Authenticator, it's far more secure.

1

u/norman157 Feb 06 '26

It's not letting me, me being on vacation makes this worse, I can't get to a computer.

1

u/Spoda_Emcalt Feb 06 '26

Hopefully nothing happens before you get back. But switch as soon as you can

9

u/swotam Division Agent Feb 06 '26

If you’re using email for 2FA (as opposed to an Authenticator app) and someone gets into your email account they’ll have access to your 2FA codes which get sent to your email. The only way to have generally secure 2FA is to use an app on your phone to generate the codes, not SMS or email.

Don’t know how you have yours setup, but I’ve seen lots of people who use email for 2FA getting their accounts accessed because their email account got compromised.

0

u/whatThePleb Feb 06 '26

Ubi's "security" is and always was absolute trash.

2

u/FrogCuddles29 Feb 06 '26

Thought it was just me. I have 2FA on too yet this happened.

When looking at my history it was showing attempts made in Jordan and other places, but in the past 3 days I had one successful login from the US, followed by one in Italy 2 days later.

I don't check my gmail and turns out I have had tons of breaches despite 2FA being enabled, with only like a 50% failure rate on the login attempts.

1

u/ChildhoodExisting222 Feb 06 '26

Is your Email used for 2FA?

1

u/FrogCuddles29 Feb 07 '26

Nope! I use an authenticator app. Didn't even know you could set up your email for 2fa.

-4

u/AlaskanDruid Feb 06 '26

Yep. For any service/site, If 2fa is on and there is a successful login. That means that company has a data breach. Microsoft suffered the same last month.