Key takeaways
- Use a long, unique password for your EA account and keep it in a password manager.
- Turn on EA's login verification so a stolen password alone is not enough to get in.
- Treat any message asking for your login, codes or backup codes as phishing.
- Never share your EA login with coin sellers, "trading services" or friends.
- FC AutoBuyer never asks for your EA password. It runs inside the Web App session you have already signed in to.
Your Ultimate Team club can represent months of play, packs and trading. That makes EA FC account security worth taking seriously, especially if you trade actively. Coins and cards cannot usually be recovered easily once someone else has emptied a club, so prevention matters far more than cure.
This guide covers the practical steps: passwords, EA login verification, phishing, account sharing and what to do if something goes wrong. It is about keeping other people out of your account. If you want to understand the separate risk of EA restricting your market access, read our explainer on the transfer market soft ban.
Why EA FC traders are targets
Accounts with large coin balances or valuable cards are attractive to thieves because coins can be moved and sold. Traders also tend to be active in communities, Discord servers and marketplaces where scams circulate. That combination makes FC and FIFA traders a regular target for:
- Phishing pages that copy the EA or Web App login screen.
- Fake giveaways, "free coins" offers and fake coin-selling services.
- Password reuse attacks, where a password leaked from another site is tried on EA.
- Social engineering: someone pretending to be EA, a streamer or a support team.
The good news is that a handful of simple habits blocks most of these.
Use a strong, unique password
If you use the same password for your EA account as for anything else, a breach on that other site can hand attackers the key to your Ultimate Team club. The UK's National Cyber Security Centre recommends a separate, strong password for your important accounts, and its top tips for staying secure online are a good checklist.
- Make it long. A passphrase built from several random words is easier to remember and harder to guess than a short, complex password.
- Make it unique. Never reuse your EA password on another site, and use a different one for the email address linked to EA.
- Use a password manager. It removes the temptation to reuse passwords and can warn you about weak ones.
- Secure your email too. Whoever controls the email linked to your EA account can often reset the password, so give it a strong password and two-step verification as well.
Check whether your details have leaked
Have I Been Pwned lets you check whether your email address has appeared in known data breaches. If it has, change the password on any account that shared the leaked password, starting with your email and your EA account.
Turn on EA login verification
Login verification is EA's version of two-step verification. When it is on, signing in from a new device or browser needs a code as well as your password. That means a stolen password alone is not enough.
EA's options and menus change over time, so follow the current instructions on EA Help rather than a screenshot from an old guide. A few general tips apply whatever the method:
- Prefer an authenticator app if EA offers it for your account, as codes are generated on your own device.
- Store backup codes safely, for example in your password manager, not in a screenshot on your desktop.
- Never read a code out to anyone. A genuine support agent does not need your verification code to help you.
- Review trusted devices now and then, and remove any you don't recognise.
How to spot phishing
Phishing is the most common way FUT accounts get taken. The aim is always the same: to get you to type your login details or verification code somewhere an attacker can see them.
| Red flag | What it can look like | What to do |
|---|---|---|
| Urgency | "Your account will be banned in 24 hours unless you verify now." | Go to EA directly by typing the address, never via the link. |
| Too good to be true | Free coins, free packs or a giveaway that needs your login. | Ignore it. Nothing legitimate needs your password. |
| Look-alike links | A login page on a slightly misspelt domain. | Check the address bar. Bookmark the real Web App. |
| Requests for codes | A DM asking you to read out a code you just received. | Refuse and block. That code is the key to your account. |
| Fake staff | Someone claiming to be EA or a tool's support team in DMs. | Use official support channels only. |
A simple habit helps a lot: bookmark the official Ultimate Team Web App on ea.com and always open it from that bookmark.
Never share your EA login
Handing your details to someone else, whether a coin seller, a so-called "comfort trade" service or a friend who offers to do your SBCs, is one of the fastest ways to lose a club. Once someone has your login, you are relying entirely on their honesty and their own security.
Account sharing and buying coins also break EA's rules and can lead to action against your account in their own right. If a service needs your password to work, walk away.
Extensions, autobuyers and your account
Browser extensions can see and change the pages they run on, so it pays to be careful about what you install. Before adding any extension, especially one that works with your EA session, ask:
- Does it ask for my EA password? An extension that runs in the Web App should not need it. Asking for your login is a red flag.
- Where am I downloading it from? Only install from the official source, never from a re-upload shared in a Discord server.
- What else is installed? Review your extensions regularly and remove anything you no longer use. Google explains how to manage Chrome extensions.
FC AutoBuyer is a Chrome extension that runs inside the Web App tab you have already signed in to, so it never asks for your EA password, and nobody from our support team should either. You install it from the download link in your purchase email; the install guide walks through it. If you want to understand what an extension like this actually does, see how an autobuyer works, and for how browser-based tools differ from app-based ones, read Chrome extension vs app autobuyers.
If you use Discord alerts, treat your webhook URL like a password too. Anyone who has it can post messages into that channel.
If your EA account is compromised
If you notice cards missing, coins gone, unexpected emails about sign-ins or changed details, act quickly:
- Secure your email first. Change its password and check its recovery options haven't been altered.
- Change your EA password to a new, unique one and make sure login verification is on.
- Remove unknown devices and sign out of sessions you don't recognise, where EA offers that option.
- Contact EA through EA Help and explain what happened, including when you noticed it.
- Check other accounts that shared the old password and change them too.
Once things are back under control, run through the steps in this guide again. If you trade a lot, it is also worth reading our transfer market trading guide for habits that keep your coins and your club working for you.
FAQs
Use a long, unique password, secure the email linked to your EA account, turn on EA login verification and never share your login or verification codes with anyone.
No. FC AutoBuyer runs inside the Web App tab you have already signed in to in Chrome, so it never asks for your EA password. Anyone asking for it on our behalf is not us.
No. Sharing your login puts your whole club in someone else's hands, and buying coins or sharing accounts breaks EA's rules and can lead to action against your account.
Check your email address on Have I Been Pwned. If it appears in a breach, change the password on every account that used the leaked password, starting with your email and EA account.


