Menu
Browse

Cyber Incident Victim: Killer Instinct

Date:

Oct 2022

Location:

United States of America

Summary

A cybersecurity incident involving unauthorized access to employee email accounts at Killer Instinct compromised financial data, including credit/debit card numbers paired with security credentials, for over 800 customers. The breach occurred during a multi-week period when threat actors infiltrated the accounts, though investigators could not confirm whether specific emails or attachments were viewed or exfiltrated. The company responded by securing affected systems, notifying impacted individuals, and offering 12 months of complimentary credit monitoring services to mitigate risks of identity theft or fraud.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Killer Instinct, a company specializing in modern crossbow sales through physical stores and an online platform, experienced a data breach between October 12 and October 28, 2022. An unauthorized individual gained access to email accounts used by at least one company employee during this 16-day period. The company discovered the intrusion and initiated an investigation to determine the scope and impact. Forensic analysis confirmed the unauthorized access occurred but could not establish whether specific emails or attachments within the compromised accounts were viewed or exfiltrated by the threat actor. The breach exposed sensitive financial information belonging to over 800 users, including combinations of financial account numbers, credit/debit card numbers, and associated security credentials such as access codes, passwords, or PINs.

Cyber Incident Image

Killer Instinct filed a breach notification with the Maine Attorney General’s Office detailing the incident's parameters and affected data types. The company secured the compromised email accounts upon discovery and implemented measures to assess potential vulnerabilities across its systems. As remediation, Killer Instinct offered affected individuals 12 months of complimentary credit monitoring services through Experian. The notification advised consumers to monitor financial accounts, review credit reports for suspicious activity, and remain vigilant against identity theft or fraud attempts. No evidence suggested broader system compromise beyond the targeted email accounts, though the investigation could not definitively rule out data acquisition due to the nature of the email account access.

Sources
Sources available to members
1 source