Menu
Browse

Cyber Incident Victim: Epic Games

Date:

Mar 2018

Location:

United States of America

Summary

Fortnite players experienced widespread account compromises, leading to fraudulent credit card charges from unauthorized purchases. The developer acknowledged these breaches resulted from common hacking techniques and urged affected users to contact support immediately. Security researchers highlighted that cybercriminals increasingly target gaming accounts due to weak user password practices, noting minimal adoption of strong credentials despite risks. Compromised accounts enabled financial fraud and disrupted access, with attackers exploiting reused or simple passwords to hijack profiles.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In March 2018, reports emerged of unauthorized access to player accounts for the popular video game Fortnite, developed by Epic Games. The incident involved compromised accounts linked to fraudulent credit card charges for unauthorized in-game purchases. Fortnite, a multiplayer survival game available on Xbox One, PlayStation 4, Windows PC, and Mac platforms, allowed players to collect resources and engage in combat. Epic Games publicly acknowledged the account compromises, attributing them to attackers using "well-known hacking techniques." The company directed affected users to contact its player support team for assistance but did not disclose the number of impacted accounts or specific technical details about the breach methodology. Players reported financial losses from unauthorized transactions tied to their stored payment methods.

Cyber Incident Image

Security researchers highlighted broader industry risks, with Kaspersky Lab's principal researcher David Emm noting that gaming accounts were frequently targeted due to weak user security practices. Kaspersky's research indicated only 5% of users prioritized strong passwords for gaming accounts, with many reusing credentials or employing easily guessable passwords across multiple services. The incident underscored the financial motivation behind such attacks, as compromised accounts enabled fraudulent purchases of in-game items. Epic Games did not publicly confirm whether the attacks involved phishing, credential stuffing, or other specific vectors. No evidence suggested platform-level vulnerabilities in Fortnite's infrastructure as the root cause. The company's response focused on user-driven account recovery rather than systemic security changes at the time of initial reports.

Sources
Sources available to members
1 source