Menu
Browse

Cyber Incident Victim: Crytek

Date:

Oct 2020

Location:

France

Summary

A game developer was targeted by the Egregor ransomware group, resulting in encrypted files marked with a '.CRYTEK' extension and the theft of internal data including materials related to WarFace, a canceled multiplayer game, and network operations. The same attackers leaked purported Ubisoft assets, including Watch Dogs: Legion source code, though the legitimacy of the Ubisoft breach remains unverified despite prior warnings about employee phishing vulnerabilities. The incident involving the German company was confirmed, while the French firm's compromise lacked definitive evidence beyond the ransomware gang's claims.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around October 15, 2020, the Egregor ransomware gang executed a confirmed cyberattack against Crytek, a Germany-based game development company. The attackers encrypted files on Crytek's network and appended the ".CRYTEK" extension to compromised files—for example, renaming "test.jpg" to "test.jpg.CRYTEK." While the exact number of affected devices remained undisclosed, the incident involved both data encryption and theft. Egregor subsequently leaked a 380MB archive of stolen Crytek data on their extortion portal, containing files related to the live game WarFace, development materials for the canceled Arena of Fate multiplayer online battle arena (MOBA) project, and internal network operation documents. BleepingComputer verified the ransomware attack through undisclosed sources but could not confirm the intrusion timeline due to Crytek's lack of response to media inquiries. The company did not publicly acknowledge the incident or provide details regarding containment efforts, recovery actions, or potential operational disruptions.

Cyber Incident Image

In parallel, Egregor claimed responsibility for breaching Ubisoft, a France-based game developer, alleging theft of source code for the unreleased Watch Dogs: Legion title. The group leaked a 20MB archive purportedly containing Watch Dogs-related assets, though BleepingComputer noted these files lacked verifiable proof of origin and could have been sourced from non-Ubisoft channels. Security researcher MalwareHunterTeam disclosed prior attempts to alert Ubisoft about employee phishing incidents over nearly a year, receiving no response. Ubisoft did not confirm the alleged breach or data legitimacy, and like Crytek, did not reply to media requests for comment. The incidents highlighted Egregor's dual strategy of encrypting victim systems while exfiltrating and leaking unencrypted data to pressure organizations into paying ransoms.

Sources
Sources available to members
1 source