LIVE · cybersecurity feed
Live wire
security

Fake Fortnite rewards are stealing players’ accounts

Scammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts.

zeroday.news · 1d ago

Cybercriminals are actively deploying phishing scams targeting Fortnite players, using deceptive websites that promise various in-game rewards or account valuations to steal login credentials. These fraudulent pages, which appear frequently under different names and designs, aim to trick players into entering their Epic Games username and password on fake login portals.

The scams often take several forms. Some sites promise free V-Bucks or cash, sometimes under the guise of fake superhero collaborations. Another common variant offers to calculate the monetary value of a player's in-game locker, playing on the real-world value of rare skins and items in unofficial marketplaces. A more recent iteration leverages the legitimate $520 million settlement between Epic Games and the U.S. Federal Trade Commission (FTC), falsely claiming players are owed V-Bucks or other rewards through an "Epic Games Locker." However, the genuine settlement pays out actual dollars through the FTC's official process, and the claim window for that settlement closed in July 2025. References to an "EU Regulatory Mandate" or specific case numbers on these scam pages do not correspond to any authentic legal actions.

Regardless of the specific lure, all these fraudulent sites ultimately direct users to a fake Epic Games login page. Entering credentials on such a page hands the username and password directly to scammers. Stolen Fortnite accounts are valuable to criminals, who can use them to spend any saved payment methods, sell accounts with rare skins on underground markets, or attempt to scam the original owner's friends. Attackers may also try the same stolen credentials on other online platforms, hoping users have reused their passwords.

Fortnite remains a prime target for cybercriminals due to its massive player base, which includes approximately 110 million monthly active players and over 650 million registered accounts. The game's demographic, which includes a significant number of younger players, also contributes to its attractiveness as a target. Industry experts note that young gamers may be particularly susceptible to phishing because they spend more time on social media and might be less familiar with social engineering tactics. The game's emphasis on visible status through purchasable skins and emotes makes the idea of an account's "value" seem plausible, even though Epic Games does not offer an official tool for account valuation and selling accounts violates its terms of service.

Epic Games has confirmed that it does not offer an official tool to value accounts, nor does it conduct legitimate giveaways that require players to sign in through third-party websites. Players are advised to be skeptical of any offers that seem too good to be true and to only sign in to their Epic account directly at epicgames.com.

If a player suspects they have entered their login details on a fraudulent site, they should immediately change their Epic Games password by navigating directly to epicgames.com. It is also crucial to enable two-factor authentication (2FA) on their account to prevent unauthorized access, even if a password is stolen. Players should review their linked email for any suspicious password reset requests or login alerts and remove any unfamiliar connected devices or services from their account. If payment details were entered, contacting the card issuer and monitoring statements is recommended. Suspected phishing pages should be reported to Epic Games support and flagged in the browser. For any claims related to settlements or refunds, players should verify the information on the official regulator's website, such as ftc.gov for the Epic Games settlement.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

security

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]