• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock

2

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

3

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'

1

Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock

2

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

3

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
TechFortnite

Researchers Discover Big Cybersecurity Flaw In Fortnite

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
January 16, 2019, 9:00 AM ET
Add Fortune on Google for similar content.

Cybersecurity researchers have discovered a major security flaw in the popular online video game Fortnite that may have let hackers gain access to player accounts and use their stored credit card information to buy digital goods and then resell them.

Security firm Check Point Software, which announced its discovery of the vulnerability on Wednesday, said it had notified Fortnite’s developer, Epic Games, in November. Epic Games appears to have fixed the flaw in late December, said Oded Vanunu, Check Point’s head of products and vulnerability research.

Epic Games declined to comment on whether any user counts were compromised because of the security flaw. The company is based in North Carolina, where state laws require “businesses and state and local government to notify people when there is a security breach involving their personal identifying information.” The state’s laws define a security breach as the “unauthorized release of unencrypted or unredacted records or data containing personal information with corresponding names, such as a person’s first initial and last name.”

“We were made aware of the vulnerabilities and they were soon addressed,” an Epic Games spokesperson said in a statement. “We thank Check Point for bringing this to our attention. As always, we encourage players to protect their accounts by not re-using passwords and using strong passwords, and not sharing account information with others.”

Check Point decided to probe Fortnite’s web infrastructure because of the game’s massive popularity and stories involving hackers allegedly circumventing Fortnite’s security methods, said Vanunu. In December, for instance, the BBC talked to roughly 20 hackers who claimed to have stolen the accounts of real-life Fortnite users in order to resell the accounts to others.

The Fortnite security flaw involves people accessing their Fortnite accounts using their login information for other services like Facebook, Sony’s PlayStation Network, and Microsoft’s Xbox Live. Although Check Point’s research highlighted Facebook, the company said the process likely applies to other companies that offer the so-called single sign-on feature.

When people use their Facebook accounts to log into Fortnite, their computers receive a security token that enables them to access their Fortnite account page after being redirected via a website link. However, the Check Point researchers noticed that they could tamper with that website link so that instead of pointing people to their account pages, people would be redirected to older Epic Games websites, or subdomains, that contained player statistics from other video games and online tournaments.

Data Sheet, Fortune’s technology newsletter.

These older Epic Games sites also contained a security flaw that when exploited, could allow hackers to retrieve people’s security tokens that they received when they used Facebook to log into Fortnite. Hackers could then use the security tokens to access people’s accounts.

Check Point researchers said they could launch a phishing attempt—a fake message that looked like it came from Epic Games—that would trick people into clicking on the tampered link.

Vanunu explained that cybersecurity vulnerabilities like the one Check Point highlighted are becoming increasingly common as apps become more complex. Many modern apps, built on multiple software services and databases, can be connected to older company websites or IT infrastructure that may contain security flaws. The challenge for companies is ensuring that their newer apps don’t contain inadvertent connections to these older and forgotten websites, a challenge as apps continue to become more complex and interconnected with other corporate IT infrastructure.

“This is why we see so man big leaks of millions of records,” Vanunu said.

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Amazon Prime Day isn’t a midsummer shopping event anymore. Here’s what changed in 2026
RetailAmazon
Amazon Prime Day isn’t a midsummer shopping event anymore. Here’s what changed in 2026
By Vidhi Choudhary and Retail BrewJune 23, 2026
3 hours ago
The hidden cost of your AI rollout: burning out the high performers running it
Workplace Cultureburnout
The hidden cost of your AI rollout: burning out the high performers running it
By Mikaela Cohen and HR BrewJune 23, 2026
4 hours ago
Quantum computing stocks surge after Trump signed executive orders backing the sector
Investingquantum computing
Quantum computing stocks surge after Trump signed executive orders backing the sector
By Marco Quiroz-GutierrezJune 23, 2026
4 hours ago
Alan Greenspan testifying before the Senate Banking Committee.
BankingFederal Reserve
The man who invented the Fed’s magic trick just died. His successor is about to try it again
By Eva RoytburgJune 23, 2026
6 hours ago
Google DeepMind CEO Demis Hassabis (left) stands on a spiral staircase next to Google DeepMind researcher John Jumper.
NewslettersEye on AI
Defections from Google DeepMind prompt questions about Alphabet’s efforts to stay at the forefront of AI
By Jeremy KahnJune 23, 2026
6 hours ago
college
SuccessEducation
47% of Harvard seniors admit to cheating — and the problem existed long before ChatGPT
By Austin Sarat and The ConversationJune 23, 2026
7 hours ago

Most Popular

Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock
Banking
Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock
By Jim EdwardsJune 23, 2026
14 hours ago
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
12 hours ago
Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
Success
Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
By Sydney LakeJune 21, 2026
3 days ago
Current price of oil as of June 22, 2026
Personal Finance
Current price of oil as of June 22, 2026
By Joseph HostetlerJune 22, 2026
1 day ago
By 7 a.m., Bank of America’s CEO has already read 5 newspapers, his email inbox, and hit the gym—he says if you’re late to meetings, you’re ‘selfish’
Success
By 7 a.m., Bank of America’s CEO has already read 5 newspapers, his email inbox, and hit the gym—he says if you’re late to meetings, you’re ‘selfish’
By Preston ForeJune 22, 2026
1 day ago
Current price of silver as of Monday, June 22, 2026
Personal Finance
Current price of silver as of Monday, June 22, 2026
By Joseph HostetlerJune 22, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.