Cyber Incident Victim: Epic Games
Date:
Mar 2018
Location:
United States of America
Summary
Fortnite players experienced widespread account compromises, leading to fraudulent credit card charges from unauthorized purchases. The developer acknowledged these breaches resulted from common hacking techniques and urged affected users to contact support immediately. Security researchers highlighted that cybercriminals increasingly target gaming accounts due to weak user password practices, noting minimal adoption of strong credentials despite risks. Compromised accounts enabled financial fraud and disrupted access, with attackers exploiting reused or simple passwords to hijack profiles.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In March 2018, reports emerged of unauthorized access to player accounts for the popular video game Fortnite, developed by Epic Games. The incident involved compromised accounts linked to fraudulent credit card charges for unauthorized in-game purchases. Fortnite, a multiplayer survival game available on Xbox One, PlayStation 4, Windows PC, and Mac platforms, allowed players to collect resources and engage in combat. Epic Games publicly acknowledged the account compromises, attributing them to attackers using "well-known hacking techniques." The company directed affected users to contact its player support team for assistance but did not disclose the number of impacted accounts or specific technical details about the breach methodology. Players reported financial losses from unauthorized transactions tied to their stored payment methods.

Security researchers highlighted broader industry risks, with Kaspersky Lab's principal researcher David Emm noting that gaming accounts were frequently targeted due to weak user security practices. Kaspersky's research indicated only 5% of users prioritized strong passwords for gaming accounts, with many reusing credentials or employing easily guessable passwords across multiple services. The incident underscored the financial motivation behind such attacks, as compromised accounts enabled fraudulent purchases of in-game items. Epic Games did not publicly confirm whether the attacks involved phishing, credential stuffing, or other specific vectors. No evidence suggested platform-level vulnerabilities in Fortnite's infrastructure as the root cause. The company's response focused on user-driven account recovery rather than systemic security changes at the time of initial reports.
