Video game giant Ubisoft investigates reports of a data breach
2023-12-24 22:48:6 Author: securityaffairs.com(查看原文) 阅读量:10 收藏

Video game giant Ubisoft investigates reports of a data breach

Pierluigi Paganini December 24, 2023

Video game publisher Ubisoft is investigating reports of an alleged data breach after popular researchers shared evidence of the hack.

Ubisoft, the popular video game publisher, is examining reports of a potential data breach following the disclosure of evidence by prominent researchers vx-underground.

The researchers reported that on December 20, 2023, an unknown threat actor had access to Ubisoft’s infrastructure for roughly 48 hours. The administrators then locked out the intruders after discovering the attack.

It’s still unclear how attackers breached the company, they attempted to steal R6 Siege user data without success.

The Threat Actor would not share how they got initial access. Upon entry they audited the users access rights and spent time thoroughly reviewing Microsoft Teams, Confluence, and SharePoint.

They attempted to exfiltrate R6 Siege user data but were unsuccessful pic.twitter.com/EPRraDl3MT

— vx-underground (@vxunderground) December 22, 2023

Ubisoft is a prominent multinational video game company that has a strong presence in the gaming industry. It is known for developing, publishing, and distributing a wide range of video games across various platforms, including PC, consoles, and mobile devices. Ubisoft has a strong track record of creating popular franchises, such as Assassin’s Creed, Tom Clancy’s Rainbow Six Siege, Far Cry, Watch Dogs, and many others.

The threat actor claims to have had access to the company Microsoft Teams, Confluence, and SharePoint installs.

The threat actor told vx-underground that they plan to exfiltrate around 900GB of data of data stolen from the gaming company.

On March 2022, Ubisoft suffered another ‘cyber security incident’ that had a severe impact on games, systems, and services. Lapsus$ extortion gang claimed to have breached the company network and exfiltrated internal data.

Ubisoft Lapsus$

In October 2020, the Egregor ransomware gang hit the game developer Crytek and leaked files allegedly stolen from Ubisoft.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)




文章来源: https://securityaffairs.com/156331/data-breach/ubisoft-investigating-alleged-data-breach.html
如有侵权请联系:admin#unsafe.sh