Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Activision Gaming Breached When Employee Gets Phished With SMS Text
Facebook   X   LinkedIn   Email

Activision Gaming Breached When Employee Gets Phished With SMS Text

May 18, 2023

In their own words, Activision explains what they do as “We connect and engage the world through epic entertainment.” Late last year, the gaming powerhouse with hits like “Call of Duty” and “Candy Crush” underwent an assault on their data systems. What started the attack was an employee who answered an SMS text, a phishing text. That’s all it took to steal sensitive company data: one phishing text + one response = a data breach.

After learning about the phishing text, Activision says their information security team immediately settled the situation before any sensitive data was lost. But not everyone agrees it was that clear-cut – not even close. Malware analysis gurus vx-underground, the first to publicly expose the breach, reports their own findings contradict Activision’s.

One Phish = One Data Breach

One thing Activision and vx-underground agree on was the breach started with a phishing text. vx-underground found the phished employee was an Activision network “privileged user.” Hackers prefer phishing those with higher access privileges since they can lead to other criminal prospects.

According to vx-underground, the Activision breach led to data loss for the company and its employees, and both had secrets divulged. vx-underground found the attacker used the phished employee’s privileged credentials to steal “sensitive workplace documents.” Also, breaching the compromised employee’s Slack account led to even more phishing possibilities. Insider Gaming reports the breach exposed employee data like salary, email address, phone number, and more. One of Activision’s most coveted products “Call of Duty” had its game release schedule leaked.

It's a Data Breach World Out There

What happened with Activision is a reality for businesses everywhere. No enterprise wants their data stolen, and their employees don’t want that either. However, TechCrunch revealed Activision didn’t plan on telling their staffers about the breach. In fact, some say they have yet to be told it happened at all. It’s a decision making their staff being even more vulnerable to criminal abuse. It takes away their choice to be proactive, and with cyberattacks, quick actions like changing passwords can prevent further compromise, as can reminding employees not to click on links that arrive in text form when they aren't expected or are from unknown senders. And also very importantly, they should never give out their login credentials to anyone.

Cyber-educated employees can prevent a data breach before it happens. And at the rate breaches happen today, fortifying data security is everyone’s responsibility – from the top on down.

Quick strong password hints:

  • Use at least eight characters containing a combination of upper and lower-case letters, numbers, and special characters.
  • Avoid using personal information in passwords such as birthdates of loved ones.
  • Use non-sensical combinations of the above rather than proper names or words that can be found in a dictionary.

Email Scams Threaten Extortion And Blackmail

Scams & Phishing

Email Scams Threaten Extortion And Blackmail

An uptick in email scams has cybersecurity professionals concerned, and for good reason. Symantec researchers found that in the first five months of 2019, they prevented almost 300 million extortion email attacks from going forward. Just some of those discovered include blackmail, sextortion, bombs, hit men, and malware threats. The researchers also determined the average cost of paying demands over a 30 day period was $1.2 million in 243 Bitcoin transactions. READ FULL STORY

 Storing Passwords In Your Browser…It’s Convenient, BUT Very Risky Too

Your Security

Storing Passwords In Your Browser…It’s Convenient, BUT Very Risky Too

Most of us know that password fatigue can lead to security mishaps and that creating a safe and secure entrance into our personal or work accounts can be a real challenge. Fortunately, security experts also know that safe password use has long been a problem, one that can lead to epic malware infections like ransomware, banking trojans, and more. Popular browsers like Chrome, Firefox, Safari, and Opera offer the option to store passwords for you, but hackers using the malware “RedLine Stealer” can hijack those stored passwords in a heartbeat. READ FULL STORY

Children As Online Targets--What Every Parent Needs To Know

Your Security

Children As Online Targets--What Every Parent Needs To Know

Adults should be well-aware of hacking and the risks involved when traversing online. But what many don’t know is the sad truth that children are also targets of online abuse. Sadly, this includes infants. The good news is that parents aren’t helpless when it comes to protecting their child’s online activities and real-world identities. Knowing the signs of child identity theft, other harmful vulnerabilities and how you can help prevent them is a great way to start. READ FULL STORY

Are You Getting Smished? How To Tell And How To Avoid It

Mobile Security

Are You Getting Smished? How To Tell And How To Avoid It

It doesn’t take much to be a smishing victim when just a text message does the trick. A member of the email phishing and voice (vishing) family of criminal scams, replying to a smishing text can be all that’s needed to begin a successful scam. Knowing how smishing works and the tell-tale signs of these scams can help keep you from being the next smishing victim. Using pressure, fear, curiosity, trust, winning a contest, and other tactics increase their chances of reeling you in. But what do you do when a text has only one word? READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...