ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hacker leaks stolen Activision data on a dark web forum

A threat actor posted the sensitive personal data of employees of video game developer Activision on a Dark Web forum soon after vx-underground made the breach public.Earlier this month, an Activision spokesperson confirmed that the company’s information security team identified a phishing attack in December last year and took prompt actions to mitigate its impact.“The security of our data is paramount, and we have comprehensive information security protocols in place to ensure its confidentiality. On December 4, 2022, our information security team swiftly addressed an SMS phishing attempt and quickly resolved it,” the spokesperson said.After discovering the incident, the company launched a thorough investigation and confirmed that no sensitive employee data, game code, or player data was accessed.However, malware research firm vx-underground uploaded screenshots of data allegedly stolen from Activision, including a schedule of content to be released for the Call of Duty computer game. Video gaming blog Insider Gaming also reported that it was able to verify “the legitimacy of an alleged Activision data breach from Twitter user @vxunderground, who recently posted key Call of Duty details to his Twitter account overnight.”Insider Gaming also said that threat actors gained access to employee information like full names, emails, phone numbers, salaries, places of work, and more.“Speaking with vx-underground, Activision was breached on December 4, 2022, and the files were passed on to him recently by a single individual who was unable to sell the contents of the breach. In conversation, it was said that the hacker was able to breach a Human Resources (HR) employee’s computer, which the hacker was able to scrape easily, gaining access to the information.“Although not confirmed at this time, it appears that the hack was limited to that one employee’s computer. However, given the responsibilities given to an HR employee, the computer contained employee details of all Activision employees. It’s understood that no player/user data has been compromised,” Insider Gaming explained.This week, a threat actor announced on the Breached hacking forum that the stolen data was acquired from a compromised Azure database managed by Activision. The threat actor’s post revealed that the leaked data included 19,444 unique records of names, phone numbers, job titles, locations, and email addresses of Activision employees, “dumped on December 5th 2022”.The fact that the data of Activision employees is readily accessible on a very popular hacking forum puts all impacted employees at a higher risk of identity theft and other cyber crimes.In September 2020, Activision also received unwanted publicity for a "data breach" that reportedly impacted up to 500,000 Call of Duty players. It later turned out that hackers hijacked players’ CoD accounts by exploiting password reuse across multiple sites. This common practice ensures that hackers can use passwords obtained from a breached website to crack online accounts on other sites that have similar passwords. 

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543