Drag the artwork to explore. Use the arrow keys when it is focused.

Security & ExploitsAccount Hijacking

Minecraft Hack Wave Chains Through Fake Mod Requests

Hacked accounts are impersonating friends to trick players into downloading token-stealing JAR files, with multiple reports surfacing in the last 48 hours and victims waking up to Peter Griffin skins or wiped progress.

3 min read

The latest wave isn’t some shadowy data breach. It is social engineering that turns your buddy list against you. One player gets compromised, often through an earlier mod download or reused password. The attacker then slides into DMs from that trusted account, drops a link to what looks like a harmless Minecraft client tweak or modpack, and the cycle continues.

@lumosterris
@lumosterris Source

A post from @lumosterris on October 6 showed their Microsoft account hijacked with the only visible change being the Minecraft skin switched to Peter Griffin. Other users replied with similar stories, including one noting the attacker immediately pivoted to asking for more downloads from fresh contacts.

Minecraft character with Peter Griffin skin after Microsoft account compromise
Victim's skin changed to Peter Griffin following account takeover on October 6 2026 Source
Enable 2FA on your Microsoft account right now. These token stealers bypass passwords entirely once they have session data. Changing your skin to something ridiculous is the least of the damage. Full account access means Realms, Marketplace purchases, and linked emails can all get drained or used to spread the scam further.

The method echoes earlier WeedHack-style campaigns but feels more personal because it comes from people you actually play with. One X user with 30-plus likes laid it out plainly: the scammer controls the hacked account, pretends to be the owner, asks you to download a Minecraft mod, steals your tokens, then repeats. Reporting the account rarely stops the chain fast enough.

Players are also seeing hacked accounts used to push Discord invites or “test this modpack” calls that lead to JAR files packed with stealers. The advice circulating is simple and repeated: verify out-of-band before downloading anything suggested by a friend in-game or in chat, and lock down your Microsoft login with app-based 2FA instead of SMS.

  • Verify unexpected mod or client links with a separate call or message, even from friends
  • Never run JAR files from untrusted sources, even if they claim to be popular clients like Meteor or Wurst
  • Check your Minecraft skin and recent logins regularly; sudden changes are the first red flag
  • Use a dedicated Microsoft account for Minecraft with strong unique password and 2FA

Yall need to start using 2fa on everything. Everyone getting hacked recently it seems.

Lumo (indies can't stop WINNING) (@lumosterris) on X
Image via X (formerly Twitter) Source

The pattern is not new, but the volume of fresh complaints in the last two days suggests the current batch of operators is active and scaling through existing friend networks. Mojang has not issued a specific statement on this latest surge, but the community response is clear: treat every unsolicited mod link like malware until proven otherwise.

Did you enjoy this story?