ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Shadow PC warns of data breach affecting over 500,000 customers

Shadow PC, a provider of high-end cloud computing services, has warned its customers about a recent data breach that exposed the private information of more than 500,000 users. The breach resulted from a sophisticated social engineering attack on the company’s employees.

 

Shadow PC offers a cloud gaming service that allows users to access high-end Windows PCs remotely, enabling them to run demanding AAA games on virtual computers across various devices such as PCs, laptops, smartphones, tablets, and smart TVs.

 

The breach came to light following multiple reports from Shadow customers who received data breach notifications. The company revealed that the attack occurred at the end of September and was initiated through a social engineering scheme involving downloading malware disguised as a game on the Steam platform via Discord.

 

The downloaded malware functioned as an info-stealer, enabling the hackers to obtain an authentication cookie granting them unauthorized access to a software-as-a-service (SaaS) provider used by Shadow. Using this access, the attackers extracted customers’ personal information, including their full names, email addresses, dates of birth, billing addresses, and credit card expiration dates. Importantly, the breach did not compromise account passwords or sensitive payment/banking data.

 

Shadow PC has taken immediate steps to address the breach. The stolen authentication cookie has been revoked, and the hackers’ access to the company’s systems has been blocked. Additional security measures have been implemented to mitigate the risk of similar incidents. The company also assured affected customers that the compromised service provider did not possess any other user data apart from what was outlined in the breach notification.

 

Customers impacted by the breach are encouraged to exercise caution against phishing and scam attempts and to enable multi-factor authentication (MFA) on all their accounts. While a limited discussion on the incident can be found on a Reddit thread involving an employee of the firm, Shadow PC has not issued any official statements on its website or social media channels.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543