CSIDB logo
Incident

CD Projekt

Incident posture

Attack window
Jun 2017
Location
Poland
Status
Historical
CIA posture
Available to members
Updated
2025-12-01 00:00

Linked entities

Victim
CD Projekt
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

CD Projekt Red experienced a data breach where attackers stole internal files, including early design documents for the unreleased game Cyberpunk 2077, and demanded ransom under threat of public release. The company refused payment, acknowledging the files might be leaked but emphasized they were outdated and unrepresentative of the game's current vision, while advising fans to rely solely on official updates. Legal authorities were notified of the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around June 8, 2017, CD Projekt Red, the Polish game development studio responsible for *The Witcher 3: Wild Hunt*, publicly disclosed a data breach involving unauthorized access to internal company files. An unidentified individual or group contacted the studio, claiming possession of stolen documents and demanding an unspecified ransom payment. The attacker threatened to release the files publicly if CD Projekt Red refused to comply. The compromised materials included early design documents related to *Cyberpunk 2077*, an open-world role-playing game then in development and based on the *Cyberpunk 2020* tabletop RPG. CD Projekt Red immediately issued a public statement confirming the breach and explicitly refusing to negotiate with the extortionists. The studio characterized the stolen files as outdated and unrepresentative of the game's current development vision, which had been underway since 2012 but was deprioritized during *The Witcher 3*'s final production and 2015 release.

The studio notified its audience that legal authorities had been engaged to address the situation, though specific law enforcement agencies were not named. CD Projekt Red advised fans to disregard any unofficial information about *Cyberpunk 2077* and await official updates directly from the company. No technical details regarding the breach methodology, such as intrusion vectors or compromised systems, were disclosed publicly. The incident primarily involved intellectual property theft rather than customer or employee data exposure. While the attacker's publication timeline remained uncertain, the studio maintained operational continuity without reported disruptions to development schedules. This transparency contrasted with typical corporate breach responses, as CD Projekt Red proactively alerted its player base about the potential leak while minimizing its significance through contextual framing of the stolen materials' age and developmental irrelevance.

Sources

Sources available to members: 1 source.

CSIDB