The Epic Games forums were compromised, exposing 808,000 Unreal Engine and Unreal Tournament forum accounts' salted passwords.
Email addresses, birth dates, and private messages are among the information taken from Epic Games.
Security experts have expressed dissatisfaction with the degree of security put in place to safeguard customers' data. In response, the firm has stated that it would not be forcing account resets because passwords on the Unreal forums were not compromised.
Additionally, the Facebook access tokens that were stored in the database for individuals who logged in using their social account were accessible to the attackers.
Source: https://securityaffairs.com/50537/data-breach/epic-games-hacked-2.html
TPRM report: https://scoringcyber.rankiteo.com/company/epic-games
"id": "epi2054291023",
"linkid": "epic-games",
"type": "Data Leak",
"date": "08/2016",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '808,000',
'industry': 'Gaming',
'name': 'Epic Games',
'type': 'Company'}],
'data_breach': {'data_encryption': ['salted passwords'],
'number_of_records_exposed': '808,000',
'personally_identifiable_information': ['email addresses',
'birth dates'],
'type_of_data_compromised': ['email addresses',
'birth dates',
'private messages',
'Facebook access tokens']},
'description': 'The Epic Games forums were compromised, exposing 808,000 '
"Unreal Engine and Unreal Tournament forum accounts' salted "
'passwords. Email addresses, birth dates, and private messages '
'are among the information taken from Epic Games. Security '
'experts have expressed dissatisfaction with the degree of '
"security put in place to safeguard customers' data. In "
'response, the firm has stated that it would not be forcing '
'account resets because passwords on the Unreal forums were '
'not compromised. Additionally, the Facebook access tokens '
'that were stored in the database for individuals who logged '
'in using their social account were accessible to the '
'attackers.',
'impact': {'brand_reputation_impact': 'negative',
'data_compromised': ['email addresses',
'birth dates',
'private messages',
'Facebook access tokens'],
'systems_affected': ['Unreal Engine and Unreal Tournament forums']},
'response': {'remediation_measures': 'No forced account resets'},
'title': 'Epic Games Forum Breach',
'type': 'Data Breach'}