Vantage Portal

Symptom guide

I cannot get into my account

Being locked out of a game account feels like a security incident and usually is not one. This page separates the ordinary causes from the genuine ones, sets out the recovery path in the order that works, and lists the Australian services worth contacting when something has actually gone wrong.

Quick answer

Before assuming the worst, check three ordinary explanations: the account was created with a different sign-in method than the one you are using, the email address on it is an older one you no longer check, or the password manager is filling in credentials for a different service. These account for a large share of lockouts. If the recovery email or phone number on the account has been changed without you doing it, that is a different situation, and the section on suspected access covers it.

Most lockouts are administrative, not hostile

Game accounts accumulate sign-in methods. A player may have created an account directly with an email address, then later signed in through a platform account or a social login, and the two can end up as separate accounts with similar details. Someone who is certain their password is correct is often correct — and using it on the wrong one of two accounts.

The second ordinary cause is an email address that has lapsed. Accounts created some years ago frequently sit on an address tied to an old internet provider, a former workplace or a school. Recovery messages are sent there and never arrive, which looks from the outside like recovery being broken.

The third is a mismatch between what you remember and what is stored — a password changed on one device and never updated in the manager on another. Where a manager has more than one entry saved for the same service, it will fill one of them, and it is not necessarily the current one.

How access is genuinely lost

When an account has actually been taken, the route is rarely dramatic. Four patterns cover most of it, and the Australian Cyber Security Centre publishes guidance for individuals on each of them.

A password reused somewhere else
Where the same password protects a game account and an unrelated service, a breach of the unrelated service exposes both. This is the most common route by a wide margin, and it requires no skill on anyone's part — the credentials are simply tried elsewhere.
A message that led somewhere convincing
A sign-in page reached through a link in a message, rather than typed or opened from a bookmark, may be a copy. These are often distributed as prize notifications, account warnings or offers connected to a game, because that context makes the request to sign in feel expected.
Software installed to help with the game
Tools offering free items, automation, or an advantage in a game are a standing route for credential theft, because installing them is voluntary and the user grants the access themselves. A tool that requires your account details in order to function has already asked for more than any legitimate one needs.
An account that was shared or traded
Accounts handed to someone else for help with progress, or bought from a seller, are frequently reclaimed later using recovery details the original holder still controls. The person left without access generally has no standing to recover it.

The recovery path, in the order that works

  1. Identify which sign-in method created the account. Direct email, platform account, or social login. Attempting recovery on the wrong one produces failures that look like the account does not exist.
  2. Search your email archive for the original confirmation. The welcome or verification message tells you the address the account actually uses and, often, the exact date it was created. Support channels ask for that date.
  3. Use the official recovery form only. Reach it from the publisher's own site or launcher rather than from a search result or a message, since recovery pages are among the most copied pages that exist.
  4. Assemble evidence of ownership before contacting support. Approximate creation date, the first payment method used if any, and receipts. This is what distinguishes a genuine holder from someone claiming to be one.
  5. Make one clear report and wait. Duplicate requests through several channels commonly reset a queue position rather than accelerating it.

If you believe someone else has the account

The indicators worth acting on are a changed recovery email or phone number that you did not change, sign-in notifications from places you have not been, or purchases you did not make. Any one of them is a reason to move to recovery immediately rather than to keep trying passwords.

The order matters here. Secure the email account first, because whoever controls it controls every recovery process that reports to it. Then change the password on the game account if you can still reach it, and enable a second factor if the publisher offers one. Then review any payment method stored against the account, and speak to your bank if a charge appears that you do not recognise — that is a payment question with its own process, covered on our purchases and refunds page.

Where a company has lost your data rather than you losing your account

If a publisher notifies you that your information was exposed in a data breach, that is a separate matter from a lockout. In Australia, the Notifiable Data Breaches scheme requires eligible breaches likely to result in serious harm to be notified, and the Office of the Australian Information Commissioner is the regulator that administers the scheme and publishes guidance for individuals on what to do after being notified.

Linked accounts, and why the link is the weak point

Signing into a game through a platform or social account is convenient and consolidates risk. The game account then depends entirely on the security of the account it is linked to, and anyone reaching that one reaches the game as well. This is not an argument against linking; it is an argument for treating the linked account as the one that matters most, and for reviewing periodically which applications still have access to it.

It also matters for recovery. Where a game account is reached through a platform login, the publisher frequently cannot reset a password it does not hold, and recovery has to start with the platform. People spend weeks in the wrong queue for this reason.

Reporting, in Australia

Three services are relevant depending on what happened, and they are not interchangeable.

  • Deception and financial loss. Scamwatch, run by the National Anti-Scam Centre, is where scams are reported and where current approaches are described.
  • Cyber security incidents and practical guidance. The Australian Cyber Security Centre publishes advice for individuals and has a reporting function for cyber incidents.
  • Harm involving people rather than systems. Where the issue is harassment, image-based abuse or the online safety of a young person, the eSafety Commissioner is the Australian regulator with a complaints function.

What this site cannot do

We are not the publisher of any game and hold no account data, so we cannot restore access, verify ownership, reverse a ban or contact a publisher on anyone's behalf. Nobody outside the publisher's own support channel can do those things, and any service claiming otherwise is worth declining. What we can usefully offer is the order of operations above, which is where most recoveries go wrong.