CSIDB logo
Incident

CD Projekt

Incident posture

Attack window
Mar 2016
Location
Poland
Status
Historical
CIA posture
Available to members
Updated
2025-12-11 00:00

Linked entities

Victim
CD Projekt
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach impacted CD Projekt Red's online forum, compromising approximately 1.8 million user accounts. The incident exposed usernames, email addresses, and passwords associated with forum members. A breach notification service alerted affected individuals months after the unauthorized access occurred, revealing a significant number of its subscribers were among the victims. The developer acknowledged the incident through a brief forum statement advising users to change their credentials as a precautionary measure. This event formed part of a broader pattern of gaming-related security incidents during the period, though specific technical details about the attack vector or perpetrator remained undisclosed by the company.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In March 2016, CD Projekt Red, the Polish developer of The Witcher game series, suffered a breach of its online forums that compromised 1,871,373 user accounts. The incident exposed usernames, email addresses, and passwords stored on the forum system. The breach remained undetected publicly until January 31, 2017, when HaveIBeenPwned, a breach notification service operated by security expert Troy Hunt, disclosed the incident's full scope. Hunt confirmed that 8,110 individual subscribers and 812 domain subscribers to his service were affected, describing this as a "pretty high hit rate." The compromised data appeared in public circulation approximately ten months after the initial intrusion, demonstrating the typical delay between data theft and its eventual exposure. CD Projekt Red acknowledged the breach through a forum statement but provided minimal technical details about the attack vector or intrusion timeline.

Affected users began receiving automated alerts from HaveIBeenPwned on January 31, 2017, prompting discussions on platforms like The Witcher's Reddit community. One user noted the widespread notifications while urging others not to blame the developer excessively, stating "f**k ups happen." The company's primary response consisted of advising forum users to change their passwords as a precautionary measure. This incident formed part of a broader pattern of gaming-related breaches during the period, including a separate compromise of Supercell's Clash of Clans forums affecting 1.1 million accounts in 2025. The CD Projekt Red breach highlighted persistent security challenges facing online gaming communities despite increasing awareness of credential protection practices.

Sources

Sources available to members: 1 source.

CSIDB