ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hacker used phishing attack to breach gaming giant Activision's internal systems

Video game developer Activision said a phishing attack it suffered in December did not compromise any data, but vx-underground claims the opposite. An Activision spokesperson in a statement has confirmed that the company’s information security team identified a phishing attack in December last year and took prompt actions to mitigate its impact.“The security of our data is paramount, and we have comprehensive information security protocols in place to ensure its confidentiality. On December 4, 2022, our information security team swiftly addressed an SMS phishing attempt and quickly resolved it,” the spokesperson said.AFter discovering the incident, the company launched a thorough investigation and confirmed that no sensitive employee data, game code, or player data was accessed.However, on Monday, malware research firm vx-underground uploaded screenshots of data allegedly stolen from Activision, including a schedule of content to be released for the Call of Duty computer game. The screenshots also showed that threat actors gained access to Activision’s network on December 2 and tried to victimise more Activision employees.“Activision was breached December 4th, 2022. The Threat Actors successfully phished a privileged user on the network. They exfiltrated sensitive work place documents as well as scheduled to be released content dating to November 17th, 2023. Activision did not tell anyone,” vx-underground tweeted.The same day, video gaming blog Insider Gaming reported that it was able to verify “the legitimacy of an alleged Activision data breach from Twitter user @vxunderground, who recently posted key Call of Duty details to his Twitter account overnight.”“The data obtained contains plans for Modern Warfare 2’s upcoming DLC’s, Call of Duty 2023 (Codenamed Jupiter), and Call of Duty 2024 (Codenamed Cerberus), as well as sensitive employee information,” Insider Gaming reported.Insider Gaming also said that threat actors gained access to employee information like full names, emails, phone numbers, salaries, places of work, and more.“Speaking with vxunderground, Activision was breached on December 4, 2022, and the files were passed on to him recently by a single individual who was unable to sell the contents of the breach. In conversation, it was said that the hacker was able to breach a Human Resources (HR) employee’s computer, which the hacker was able to scrape easily, gaining access to the information.“Although not confirmed at this time, it appears that the hack was limited to that one employee’s computer. However, given the responsibilities given to an HR employee, the computer contained employee details of all Activision employees. It’s understood that no player/user data has been compromised,” Insider Gaming added.Teppo Halonen, VP EMEA at Vectra, said, “Gaming today relies on cloud technology, to help users play anywhere in the world – meaning more devices, more users, and a larger attack surface. So, whether attackers are going after stolen source code from unreleased games or customers’ personal information – with such a huge user base, there are massive amounts of sensitive data at risk.“Following other recent attacks like those on Bandai Namco and Rockstar Games, publishers must be able to identify cybercriminal behaviour and alert security teams before an attack becomes a breach. With attackers now able to bypass prevention, circumvent signatures, infiltrate, blend in, and progress laterally inside and around an organisation – this ‘unknown threat’ is the most significant risk facing games publishers today.”


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543