HomeSecurityCredentials and accounts of gaming companies are found on the dark web

Gaming company credentials and accounts found on the dark web

Security researchers are warning gaming companies to improve practices security theirafter were found on the dark web 500,000 compromised employee credentials and one million compromised internal accounts

dark web gaming
Gaming company credentials and accounts found on the dark web

The research team of security firm, Kela, decided to investigate the top 25 gaming companies based on revenue.

Research into dark web markets has shown that both the supply and demand for data related to this industry are increased.

Researchers discovered nearly a million compromised accounts related to employees and customers of gaming companies, half of which were put up for sale last year.

The compromised accounts are connected to internal resources, such as admin dashboards, VPNs, Jira instances, FTPs, SSOs, developer-related environments , and more. Data from all 25 gaming companies studied was found to be exposed.

This means that all companies are vulnerable to breaches and attacks, including: customer data theft, corporate espionage, ransomware and more. Kela said it has identified ransomware on four gaming companies in recent months.

"The credentials for internal company resources, which were recently targeted, were for sale and therefore available to any potential attacker," the researchers said.

Gaming company credentials and accounts found on the dark web
Gaming company credentials and accounts found on the dark web

“We also found an infected computer (bot) that had credential logs for several important accounts that attackers could have accessed during the purchase: SSO, Kibana, Jira, adminconnect, ServiceNow, Slack, VPN, password-manager, and the company’s poweradmin – all in a single bot. This strongly suggests that it is being used by a company employee with administrator privileges. This valuable bot was available for sale for less than $10“.

Researchers also found 500,000 credentials exposed online by third-party breaches. Many of these credentials are freely available and could allow attackers to access companies' internal networks.

Kela advises gaming companies to focus on security and invest in continuous monitoring of their digital assets on the dark web. Staff training on security and implementing multi-factor authentication (MFA) are also essential.

Source: Infosecurity Magazine

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS