A new high-profile PlayStation account hacked report has renewed PS5 security concerns, especially around support-based account recovery and PSN account protection.

Image: gamingbible.com
Another visible PlayStation account takeover puts support recovery back under scrutiny
A prominent PlayStation community figure, Radec, known online as RealRadec, said on X on October 3 that his PlayStation account had been hacked, reviving the same PS5 security concern that spread through the community earlier this year after podcaster Colin Moriarty lost control of his own PSN profile. Push Square reported that Radec, who has more than 30,000 followers on X, is the latest high-profile fan account to be affected. Wolf’s Gaming Blog separately reported that Radec said he tried to log in, change his password, sign out of all devices, and re-enable two-factor authentication, but the attacker still managed to change the email address tied to the account.
That detail is the core of the story. This is not being reported as a conventional password breach where a weak password, reused login, phishing page, or malware infection is the obvious entry point. The concern raised by Push Square, Wolf’s Gaming Blog, and security-focused writeups such as Shattered.io is that some PlayStation account hacked cases appear to involve social engineering through Sony’s own customer support and recovery process. In that scenario, the attacker does not need to defeat PlayStation two factor authentication directly. They need to convince support that they are the rightful owner.
Sony has not provided a public statement in the supplied source material acknowledging a specific vulnerability, naming a fix, or giving a timeline for changes. That absence matters because the pattern now has two layers: public victims with large audiences, and regular players who say in comments and support communities that account recovery can be confusing, slow, or unsuccessful. For PS5 players with years of digital purchases, subscriptions, saves, Trophies, linked accounts, and wallet details attached to one PSN identity, the security model is no longer an abstract platform issue. It is the vault that holds most of the modern PlayStation experience.
The reported weak point is account recovery, not the PS5 console itself
The phrase “PS5 security” can send players in the wrong direction. None of the supplied reporting shows that the PS5 hardware has been broadly compromised, nor does it show that PlayStation Network passwords have leaked from Sony. The reports instead point toward account recovery. Push Square summarized the earlier concern by saying accounts could allegedly be hijacked with a PSN username, an associated email address, and a transaction ID or purchase date. Wolf’s Gaming Blog described a similar pattern from the Moriarty case, reporting that basic account and purchase information was enough to persuade PlayStation support to grant access.
Shattered.io’s September 2026 writeup makes the same distinction. It says the alleged attack path does not require malware, brute forcing, or a phishing page. According to that writeup, attackers use support verification, where an email address and old purchase detail may be treated as evidence of ownership. Shattered.io also claims the issue has circulated since roughly November 2025 and says Sony had not issued a public acknowledgment or patch timeline by the time of its update. Those are claims from that outlet, not a Sony confirmation.
This distinction is important for practical PSN account protection. If someone steals your password, PlayStation two factor authentication can block many login attempts. If someone persuades support to move the account to a different email address, the second factor you set up may no longer be the gate they need to open. That is why Radec’s reported experience, trying password changes, sign-outs, and 2FA changes without stopping the takeover, has alarmed players who already followed normal security advice.
Why public profiles may face a different risk curve
The reported information needed for these takeovers is especially dangerous for players with public gaming identities. A PSN online ID is often public by design. Creators, trophy hunters, multiplayer regulars, and community accounts share it so people can follow them, add them, verify clips, or compare progress. An associated email address is not supposed to be public, but people often reuse handles, expose contact details for business, or leave old identifiers searchable across services.
The purchase-detail component is the unusual part. Push Square reported that a transaction ID or purchase date can be part of the alleged recovery path. Wolf’s Gaming Blog noted that a trophy list can help someone infer that a player bought a game around launch. Shattered.io similarly described old receipts, shared screenshots, and purchase timing as possible sources for the information attackers may use. Those claims do not prove every takeover happens the same way, but they identify a pattern that players can actually defend against.
This is where the strategy problem gets uncomfortable. PlayStation has spent years pushing account continuity, digital libraries, cross-generation entitlements, subscriptions, cloud saves, and profile identity. That makes the account more valuable with every year. The same long tail that makes a PSN profile feel permanent also creates a larger attack surface: old email addresses, old receipts, visible trophies, third-party links, and support records from purchases made many years ago. A player who has been loyal since the PS3 or PS4 era may have more to lose than a new account with a small library.
Two-factor authentication still belongs on every account, but it is not the full defense here
The most dangerous lesson players could take from these reports is that PlayStation two factor authentication is useless. That is not what the evidence shows. 2FA remains important against ordinary account attacks, especially stolen passwords and credential reuse. If your login and password appear in another service’s breach, a second factor can stop someone from signing in normally. Players should keep 2FA enabled or use passkeys where available.
The sharper lesson is that 2FA protects the login flow, while the reported problem sits behind the recovery flow. Radec’s own post, as quoted by Wolf’s Gaming Blog, said he tried to re-enable 2FA and still could not regain control after the account email was changed. Shattered.io goes further, arguing that 2FA and passkeys can become irrelevant if support is persuaded to reset ownership through human verification.
That creates a balance problem for Sony. Account recovery must exist because legitimate players lose access to email addresses, phones, passwords, and backup codes. Lock the process down too hard and genuine owners get stranded. Keep it too permissive and attackers can turn customer support into an entry point. Wolf’s Gaming Blog framed this tension directly, noting that basic information can help real users recover accounts but may also be easy for outsiders to obtain. For PlayStation Network security, the hard question is not whether recovery should exist. It is what evidence should be strong enough to override a player’s active security settings.
Practical PSN account protection starts with reducing what attackers can prove
For PS5 players, the immediate play is to shrink the information trail around your account. Do not share PlayStation Store receipts, transaction IDs, purchase confirmation emails, order numbers, wallet top-up details, or screenshots that show dates and prices. If you have posted those in old support threads, social posts, Discord servers, or videos, treat them as sensitive and remove what you can. The reports from Push Square, Wolf’s Gaming Blog, and Shattered.io all revolve around ownership proof that may be gathered or inferred from ordinary account history.
Keep your PSN email private and avoid using a public creator or social email as the address tied to your PlayStation account. If your online ID, contact email, and public identity all point to the same person, an attacker has less work to do. A dedicated email address for PSN, protected by its own strong password and 2FA, reduces that overlap. This does not guarantee safety from support-based social engineering, but it makes the first part of the reported information chain harder to assemble.
Review what your public profile reveals. The supplied reporting specifically raises trophy lists as one possible way to infer purchase timing, particularly for launch-day games. A trophy timestamp is not a transaction receipt, but it can help guess when you bought or first played something. Players who are highly visible, trade in rare items through linked services, or use the same identity across communities should be more conservative with public profile data.
Also keep your recovery materials organized offline. That means knowing which email is attached to PSN, preserving legitimate purchase records securely, and keeping backup codes where only you can access them. If you are forced into a recovery dispute, you want clean proof ready before panic sets in. The Reddit PS5HelpSupport thread in the source material is not evidence of this exploit, but it does show a familiar reality: when players cannot access an account and cannot receive recovery messages, community forums cannot solve ownership problems for them. Only official support can.
Linked accounts raise the stakes beyond PlayStation purchases
The risk is not limited to games bought on PlayStation Store. A Reddit thread in r/RobloxHelp included users discussing fears that a compromised PlayStation account could be used to access a linked Roblox account, with one commenter describing a chain where someone tricks Sony Support, signs into Roblox through the linked PlayStation account, and bypasses the Roblox account’s own protections. That Reddit discussion should be treated as community discussion rather than confirmed reporting, but it highlights a real account-security principle: linked logins can carry damage from one platform to another.
If your PSN account is connected to other services, the value of the account rises. That can include games with their own economies, cosmetic inventories, currency balances, or social identities. The source material specifically mentions Roblox community fears around Robux and limited items, but the same strategic logic applies broadly. A PlayStation account can become a key to third-party services if those services trust Sony’s login state.
Players who are worried should audit linked accounts from the official account pages of each service, not through links sent by strangers or social media replies. If a linked service contains valuable items or currency, check whether it offers its own recovery codes, login alerts, session management, or unlinking options. The PlayStation account may be the front door, but the blast radius depends on what else you have connected behind it.
Sony’s unanswered question is whether support rules have changed
The missing piece is Sony’s side of the story. Push Square said it had expected PlayStation to tighten things after the Moriarty case earlier in the year. Wolf’s Gaming Blog reported that some comments on Radec’s post suggested support may be better at helping some users recover accounts now, while also saying many people still report failing to reclaim stolen accounts. Shattered.io says Sony had not issued a public acknowledgment or patch timeline as of its September update. The supplied materials also include Sony’s PlayStation HackerOne bug bounty page, which shows PlayStation has a public security reporting channel, but that listing by itself does not confirm any response to these account hijacking reports.
For players, the forward-looking read is simple and unpleasant. Digital ownership on console now depends as much on recovery policy as on password strength. A strong password, 2FA, and passkeys are still part of the correct setup, but they do not answer the support-verification concern described by multiple outlets. Until Sony publicly explains what information is sufficient to recover an account, whether purchase dates and transaction details are being handled differently, and how it protects users after an email change request, the community will continue to fill the silence with anecdote and anxiety.
If your PlayStation account is hacked, use official PlayStation Support channels immediately, avoid third-party “recovery” offers, preserve any emails showing account changes, and secure the email account tied to PSN. If your account is still safe, act before there is a crisis: keep 2FA enabled, protect your PSN email, stop exposing receipts or transaction details, review public profile information, and audit linked services. The current concern around PlayStation Network security is not that every PS5 player is doomed. It is that the account has become valuable enough that attackers are learning to play the recovery system as carefully as players once learned a game’s meta.
