CSIDB logo
Incident

Epic Games

Incident posture

Attack window
Mar 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
Epic Games
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Fortnite players experienced widespread account compromises, leading to fraudulent credit card charges from unauthorized purchases. The developer acknowledged these breaches resulted from common hacking techniques and urged affected users to contact support immediately. Security researchers highlighted that cybercriminals increasingly target gaming accounts due to weak user password practices, noting minimal adoption of strong credentials despite risks. Compromised accounts enabled financial fraud and disrupted access, with attackers exploiting reused or simple passwords to hijack profiles.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In March 2018, reports emerged of unauthorized access to player accounts for the popular video game Fortnite, developed by Epic Games. The incident involved compromised accounts linked to fraudulent credit card charges for unauthorized in-game purchases. Fortnite, a multiplayer survival game available on Xbox One, PlayStation 4, Windows PC, and Mac platforms, allowed players to collect resources and engage in combat. Epic Games publicly acknowledged the account compromises, attributing them to attackers using "well-known hacking techniques." The company directed affected users to contact its player support team for assistance but did not disclose the number of impacted accounts or specific technical details about the breach methodology. Players reported financial losses from unauthorized transactions tied to their stored payment methods.

Security researchers highlighted broader industry risks, with Kaspersky Lab's principal researcher David Emm noting that gaming accounts were frequently targeted due to weak user security practices. Kaspersky's research indicated only 5% of users prioritized strong passwords for gaming accounts, with many reusing credentials or employing easily guessable passwords across multiple services. The incident underscored the financial motivation behind such attacks, as compromised accounts enabled fraudulent purchases of in-game items. Epic Games did not publicly confirm whether the attacks involved phishing, credential stuffing, or other specific vectors. No evidence suggested platform-level vulnerabilities in Fortnite's infrastructure as the root cause. The company's response focused on user-driven account recovery rather than systemic security changes at the time of initial reports.

Sources

Sources available to members: 1 source.

CSIDB