EA confirms FIFA accounts were hijacked because of 'human error'

FIFA 19
(Image credit: Electronic Arts)

Electronic Arts has confirmed reports that a number of "high-profile" FIFA Ultimate Team accounts have been taken over by hackers, who were able to "exploit human error within our customer experience team" in order to bypass two-factor authentication.

The original takeover reports surfaced last week via Eurogamer, which noted that several top FUT traders had reported their accounts had been taken over and stripped of FIFA points and coins. According to the report, the attackers, using gamertags taken from FIFA leaderboards, were able to convince EA support staff that they were in fact the proper owners of the account. The reps then revealed the email addresses attached to the gamertag and reset the passwords on the accounts, enabling the attackers to log into the accounts and strip them.

After investigating the claims, EA has now confirmed that it is responsible for the security failure

"Through our initial investigation we can confirm that a number of accounts have been compromised via phishing techniques," EA wrote. "Utilizing threats and other 'social engineering' methods, individuals acting maliciously were able to exploit human error within our customer experience team and bypass two-factor authentication to gain access to other player accounts."

EA currently estimates that fewer than 50 accounts have been taken over in this fashion, and it is now working to figure out who the proper owners are, and to restore all stolen content. It also promised that steps will be taken to ensure this sort of thing is less likely to happen again in the future.

  • All EA Advisors and individuals who assist with service of EA Accounts are receiving individualized re-training and additional team training, with a specific emphasis on account security practices and the phishing techniques used in this particular instance. 
  • We are implementing additional steps to the account ownership verification process, such as mandatory managerial approval for all email change requests.
  • Our customer experience software will be updated to better identify suspicious activity, flag at-risk accounts, and further limit the potential for human error in the account update process.    

It also warned that these new steps "could impact customer experience wait times"—make them longer, in other words—but added that they are necessary to ensure better account security.

The reaction to the changes amongst FUT fans on Reddit seems generally positive so far: Longer wait times for support requests isn't great, but neither is the idea that some smooth talker can make off with your account credentials if they connect with a sufficiently inattentive support rep. The situation isn't fully resolved yet, though.

"Really happy to see this, this SHOULD prevent future victims from getting hacked," FUT Donkey, whose account was hacked last week, tweeted. "Now my question is what are you gonna do for us who got hacked? I've not heard a single word from EA since I got hacked. Are we ever getting our coins back?"

And there may be repercussions beyond FUT itself: NickRTFM lauded the account security changes on Twitter but added that someone is now using his leaked personal details to apply for credit in his name.

Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
talk to the joneses fortnite
Epic's war against the Fortnite fraudsters sees it simultaneously name and shame alleged ne'er-do-wells as its high-powered lawyers sue them
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
talk to the joneses fortnite
Epic will give Fortnite cheaters 'a second chance' with a new, more forgiving ban policy, as long as they didn't do anything too awful or illegal
Latest in Sports
A goalkeeper in a plague mask wields an axe
Silent Hill gets a soccer league in FEAR FA 98, and you can play the demo now
Roman Reigns in the ring in WWE 2k25
WWE 2K25: Every superstar on the roster
Tony Hawk doing a kickflip or whatever the hell it is in the cover art for Tony Hawk's Pro Skater 3 + 4
Tony Hawk's Pro Skater 3 + 4 remake is real, and it's coming in July with new skaters, parks, music, and more
Image for
Sure seems like the new Call of Duty map is teasing a Tony Hawk's Pro Skater game
Football players flying through the air
PC Gamer's simulated Super Bowl 2025 predicts Eagles victory, player getting hit so hard he flies out of the stadium and into the parking lot
Football Manager key art - manager of a football team watching play on the field
Sports Interactive announces the shock cancellation of Football Manager 25, but fans are weirdly pleased: 'Better to be honest and admit a mistake'
Latest in News
Silent Hill f transmission trailer screenshots
Silent Hill f is not messing around – now it's been banned in Australia
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
'Google must divest the Chrome browser:' DOJ renews call for Google to sell Chrome, and Android could be next
Victory screen of Big Rigs showing infamous "You're Winner" message under a three-handle gold trophy
One of the worst games ever made is coming to Steam, but we won't know how cruel this joke is until we see the price tag
Sci-fi character from Dune
Dune: Awakening promises us a breath of fresh air, skipping early access for a full launch with no monthly subscription in May
Baldur's Gate 3 Karlach concept art
'The dream of the tech industry is to sell off your company at an overinflated price and retire,' says actor behind Baldur's Gate 3's Karlach, 'And I feel that's being done with game studios right now'
assassin's creed shadows protector's armor
Assassin's Creed Shadows hits 2 million players, putting it on track to be the series' most successful game yet