Security

EA Games looted by intruders: Publisher says 'no player data accessed' after reported theft of FIFA 21, Frostbite source

'Surprise stealing mechanics' made short work of network perimeter security


EA Games, publisher of Battlefield, The Sims and FIFA, has admitted to a "recent incident of intrusion into our network" in which attackers reportedly stole game source code and software development kits.

The company acknowledged the breach while downplaying its impact, saying no personal data of players had been taken and claiming the amount of game source data and tools taken was "limited".

The breach was first reported by Vice's Motherboard offshoot, which said it had been shown screenshots of posts on cybercriminal forums by the apparent thieves, boasting about what they had helped themselves to.

"You have full capability of exploiting on all EA services," said one message quoted by the news website. Source code for football game FIFA 21, as well as EA's cross-platform Frostbite game engine and various software development kits for other titles are said to have been stolen, with around 780GB having been copied from EA's servers.

Nothing in Vice's story suggested a ransomware attack, while the attackers are said to be trying to sell the stolen files to their fellow criminals. No details have yet made it into public about how the attackers got into EA's networks.

EA Games did not immediately respond to The Register's questions but said in a statement reproduced by other news outlets that "no player data was accessed, and we have no reason to believe there is any risk to player privacy." The firm added that it has made unspecified "security improvements" and is working with "law enforcement and other experts" to investigate the intrusion.

Game source code is valuable because makers of big-ticket titles go to some lengths to obfuscate their code in order to deter cheaters from giving themselves an unfair advantage in online multiplayer sessions.

ESET security specialist Jake Moore commented: "Attacks on games publishers are usually for other reasons such as cheat making or underground community kudos. Gaming source code makes a popular target for cheat makers and their communities, so protection must be watertight."

In a chat with Bleeping Computer, people claiming to be the attackers said "full capability of exploiting on all EA services" would be handed over for $28m.

With millions of dollars being up for grabs in e-sports tournaments, the integrity of the game is critical. Nobody is interested in an unfair tournament – though some countries are very interested in subtly skewing internationally regarded tournaments in their favour.

Tom Van de Wiele, principal security consultant at F-Secure, added: "The EA source code and tools have a surprisingly high value to any company that operates in the shadows and want to get a leg up in competing with the bigger game development companies. Being able to steal an algorithm, approach, or game assets themselves and integrate them fast means not having to develop them on your own and means money and effort is saved that can be directed somewhere else."

If indeed the source for EA's Frostbite engine has been stolen, the potential would exist for cheat developers to build hacks for upcoming titles as well as ones currently on the market.

The effects of the data grab may be seen as embarrassing for EA, but the knock-on effects for that company's position in the e-sports market may take a little longer to be felt. ®

Send us news
18 Comments

Husqvarna ports Doom to a robot lawnmower – not, thankfully, its chainsaws

Seminal game runs on everything, so why not pay €2,199 to run it on a tiny screen?

Boss fight between Donkey Kong champ and leaderboard org ends with settlement

Video game record keepers Twin Galaxies finish messy four-year fight with Billy Mitchell

If you're gonna use AI-made stuff in your game, you better tell us, says Steam

And pinky swear there's no copyright-infringing material

$6.2B in profit wasn't enough: Nvidia hikes GeForce Now prices for Canada and Europe

Cites 'increased operational costs' but whatever they are US gamers aren't impacted

Guild behind actors' strike fears video game workers also at risk from AI

Authorizes strike for voice and motion capture talent at major game studios

Unity talks of price cap and fees for only largest games developers

That sound? It's the screeching noise of a massive U-turn as games engine biz admits mistakes

Minecraft's 'first luxury goods collection' features real-world $3,000 Burberry coat

Surely only a blockhead would pay these prices?

Microsoft to blockheads: NFTs and blockchains aren't welcome in Minecraft

Cites flakiness of NFT community and speculative activity as inimical to the game's goals

Grand Theft Auto 6 maker confirms source code, vids stolen in cyber-heist

So is that three or four stars?

Oh, WoW: Chinese gamers to be cut off from Blizzard games next week

Contractual mess has players wondering if preserving progress in Warcraft, Overwatch, and StarCraft will be possible

The PainStation runs Windows XP because of course it does

Retro fun and games in Berlin's ComputerSpieleMuseum