Video-game giant Electronic Arts (EA) is facing widespread criticism from the cybersecurity industry after it ignored warnings from researchers in December 2020 that multiple vulnerabilities left the company exposed to hackers.
Researchers from Israeli cybersecurity firm Cyberpion contacted EA late last year to inform it of several domains that could be taken over, as well as misconfigured and potentially unknown data along with domains with misconfigured DNS records.
Read also: Electronic Arts: Hackers stole the source code for FIFA 21 and other video games

But even after sending EA a detailed document about the problems, Cyberpion co-founder Ori Engelberg told ZDNet that EA did nothing to address the issues.
Engelberg added that the company responded that it had not received the information about these vulnerabilities and that it would contact Cyberpion if it had any further questions. But it never did, Engelberg stressed.
Engelberg further stated: “We inspect the entire Internet, but as gamers, we are customers of EA. Many of our employees play FIFA and other EA games. We love EA, so we wanted to reach out to them to help because their online presence is important. What we found is the ability to take over EA assets. It’s not just that someone could steal EA assets, it’s what they can do with those assets because we know EA. We know that if someone can send emails from EA domains to us, to EA customers, suppliers or employees, then that’s the easiest ‘door’ into the company. It’s not even a door. It’s something simpler.”
Engelberg explained that, using stolen domains, malicious actors could send emails purporting to come from EA and ask people to send account information or other data. EA already responded last week after it was revealed that a “chain of vulnerabilities” could allow hackers to gain access to personal information and take control of accounts.

See also: Gamer sues Microsoft for not protecting him from cyberbullying!
In recent weeks, VICE reported that the massive data breach suffered by EA was due to hackers' ability to abuse Slack privileges to gain access to an account.
The hackers behind the breach boasted on forums that they stole 780GB of data and gained full access to matchmaking servers for FIFA 21, API keys for FIFA 22, and software development kits for Microsoft Xbox and Sony. They also claim to have obtained much more, including the source code and debugging tools for Frostbite, which powers EA's most popular games like Battlefield, FIFA, and Madden.
But before the Slack breach, Engelberg and his team had repeatedly warned EA that at least six – now more than 10 according to Engelberg – vulnerabilities were leaving multiple domains and other assets exposed.

Suggestion: Valve: Brain-computer interfaces are changing the game!
Domains such as occo.ea.comwere exposed, and the Cyberpion team found 15 EA sites – such as wwe-forums.ea.com, api.pogo.com, and api.alphe.pogo.com – serving HTTP login pages.
Stats.ea-europe.com serves a mismatched certificate and its DNS record points to an IP address of a site that does not belong to EA, while easportsfootball.it and easoweb01.ea.com serve certificates that expired seven and nine years ago, respectively.
Cyberpion researchers also discovered that the SOA record for ea-europe.com points to an authoritative name server that has a private IP address. A local DNS server at this address can return whatever address its operator decides for eaeurope.com.
Researchers also identified over 500 DNS misconfigurations across all EA domains.
Information source: zdnet.com
