CSIDB logo
Incident

Multiplay

Incident posture

Attack window
Mar 2015
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-01-17 09:21

Linked entities

Victim
Multiplay
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Unauthorized access occurred on systems managed by a UK gaming event and hosting company, potentially exposing user account details. The organization advised affected individuals to change passwords as a precaution despite stored credentials being salted and hashed, with no evidence of profile information access or compromise of financial data since payment details were not retained. Some recipients initially questioned the legitimacy of the notification but the company confirmed its authenticity, though no attribution or motive for the intrusion was disclosed.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In March 2015, Multiplay, a UK-based gaming events and online services company known for hosting the Insomnia LAN gaming festival, experienced unauthorized access to multiple servers. The breach potentially exposed user account details, prompting the company to notify affected users via email and advise them to change their passwords. Multiplay confirmed the incident occurred despite its systems storing passwords in a salted and hashed format, a security measure designed to obscure plaintext credentials by appending random characters before cryptographic hashing. The company stated no evidence suggested attackers accessed profile information, and no financial data was compromised since payment details were not stored on the affected accounts. Multiplay characterized the password reset request as precautionary due to the encrypted nature of the stored credentials.

The company faced initial skepticism from users who suspected phishing attempts due to the inclusion of a password reset link in the notification email. Multiplay validated the legitimacy of its communication through a public tweet on March 27, 2015, urging recipients to follow the instructions. The breach impacted an unspecified number of users with Multiplay accounts, though the exact scope of accessed data remained undetermined. Multiplay advised users to update credentials for other online accounts if they reused or employed similar passwords across platforms. No technical details regarding intrusion methods, attacker origins, or motives were disclosed by the company. The incident occurred shortly after Multiplay’s acquisition by UK retailer GAME for £20 million earlier that month, though no confirmed connection between the events was established by Multiplay in available communications.

Sources

Sources available to members: 1 source.

CSIDB