It's 2019. You're one of 200 million Fortnite players. You get a message with a link — a discount, a friend invite, something plausible. You click it.
In the background, a script fires. It redirects through an old Epic Games login page that was abandoned but never deleted. Epic's own OAuth system processes the redirect. Your browser sends your auth token along — automatically, silently.
The attacker receives your token. You never saw a login form. You never typed your password. Your account is already compromised.
Every one of the 200 million Fortnite accounts was potentially vulnerable to this attack. Attackers could charge real money, read private messages, and access linked payment methods. Check Point Research discovered and reported it. Epic Games took two months to fix it after being told.
The attacker didn't steal a password or guess credentials. They exploited a flaw in the system that's supposed to prove who you are. That system is called authentication — and it was broken.