EA Games looted by intruders: Publisher says 'no player data accessed' after reported theft of FIFA 21, Frostbite source
- Reference: 1623414312
- News link: https://www.theregister.co.uk/2021/06/11/ea_games_code_theft/
- Source link:
The company acknowledged the breach while downplaying its impact, saying no personal data of players had been taken and claiming the amount of game source data and tools taken was "limited".
The breach was first reported by Vice's Motherboard offshoot, which said it had been shown screenshots of posts on cybercriminal forums by the apparent thieves, boasting about what they had helped themselves to.
[2]
"You have full capability of exploiting on all EA services," said one message [3]quoted by the news website. Source code for football game FIFA 21, as well as EA's cross-platform Frostbite game engine and various software development kits for other titles are said to have been stolen, with around 780GB having been copied from EA's servers.
[4]EA Games' Origin client contained privilege escalation vuln that anyone with user-grade access could exploit
[5]Red-faced, sweating and still in your chair: Welcome to eSports
[6]EA boots Linux gamers out of multiplayer Battlefield V, Penguinistas respond by demanding crippling boycott
[7]Days Gone PC: Melting pot of open-world influences makes for one of the more immersive zombie slayers out there
[8]Can The Register run Crysis Remastered ? Yes, but we don't see why you would want to
Nothing in Vice's story suggested a ransomware attack, while the attackers are said to be trying to sell the stolen files to their fellow criminals. No details have yet made it into public about how the attackers got into EA's networks.
EA Games did not immediately respond to The Register 's questions but said in a statement reproduced by other news outlets that "no player data was accessed, and we have no reason to believe there is any risk to player privacy." The firm added that it has made unspecified "security improvements" and is working with "law enforcement and other experts" to investigate the intrusion.
[9]
[10]
Game source code is valuable because makers of big-ticket titles go to some lengths to obfuscate their code in order to deter cheaters from giving themselves an unfair advantage in online multiplayer sessions.
ESET security specialist Jake Moore commented: "Attacks on games publishers are usually for other reasons such as cheat making or underground community kudos. Gaming source code makes a popular target for cheat makers and their communities, so protection must be watertight."
[11]
In a chat with Bleeping Computer , people claiming to be the attackers said "full capability of exploiting on all EA services" would be handed over for $28m.
With millions of dollars being up for grabs in e-sports tournaments, the integrity of the game is critical. Nobody is interested in an unfair tournament – though some countries are [12]very interested in subtly skewing internationally regarded tournaments in their favour .
Tom Van de Wiele, principal security consultant at F-Secure, added: "The EA source code and tools have a surprisingly high value to any company that operates in the shadows and want to get a leg up in competing with the bigger game development companies. Being able to steal an algorithm, approach, or game assets themselves and integrate them fast means not having to develop them on your own and means money and effort is saved that can be directed somewhere else."
[13]
If indeed the source for EA's Frostbite engine has been stolen, the potential would exist for cheat developers to build hacks for upcoming titles as well as ones currently on the market.
The effects of the data grab may be seen as embarrassing for EA, but the knock-on effects for that company's position in the e-sports market may take a little longer to be felt. ®
Get our [14]Tech Resources
[1] https://www.theregister.com/2020/01/06/linux_ea_boycott/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMOInJ8b48J9fpVzwNev9gAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.vice.com/en/article/wx5xpx/hackers-steal-data-electronic-arts-ea-fifa-source-code
[4] https://www.theregister.com/2020/11/10/ea_games_origin_privesc_vuln_nettitude/
[5] https://www.theregister.com/2012/12/25/esports_career/
[6] https://www.theregister.com/2020/01/06/linux_ea_boycott/
[7] https://www.theregister.com/2021/05/29/days_gone_pc/
[8] https://www.theregister.com/2020/09/25/can_the_register_run_crysis/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMOInJ8b48J9fpVzwNev9gAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMOInJ8b48J9fpVzwNev9gAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMOInJ8b48J9fpVzwNev9gAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2020/10/19/russians_charged_olympics/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMOInJ8b48J9fpVzwNev9gAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
Good luck with that
Maybe they can sort it all out and hand it back to EA, so they can finally put a game out that's not half-baked at launch.
A number of thoughts
1) Shouldn't a games company be at least one step ahead of data thieves?
2) Shouldn't a tech company have had the skills to tie down vulnerabilities
3) Shouldn't a high security operation have made sure their stuff was siloed so that no one could ever get to more than a part of it
4) All of the above when a high security computer based games company like EA is concerned
And
5)Isn't the big risk now that the criminals will be selling compromised cheats etc. that also take control of foolish purchasers* PCs
*Not a gamer** ( can never be bothered to struggle past that bit early in the game where the only way forward is to keep trying random things in a series of random sequences until a random combination of objects align to open the secret door in a random location), so I don't get the point of having "cheats". (Other than, I guess, to get past that bit early in the game where the only way forward is to keep trying a.........)
**I also don't enjoy all that killing".
Network Security
Obviously that was included in a loot crate, part of some DLC, that they obviously couldn't afford.
Fifa 21 source code taken. Hackers due to release Fifa 21, Fifa 22, Fifa 23, Fifa 24, Fifa 25.... next week.
I think I've seen a preview...
It's the one where England are confidant they can win, struggle to get through the first round and are soundly defeated in the second by a team of part time postmen and telephone sanitisers from a small island in the middle of a large ocean.
Re: I think I've seen a preview...
So they're re-releasing FIFA 2004?
Brave move.
Nah
"Game source code is valuable because makers of big-ticket titles go to some lengths to obfuscate their code in order to deter cheaters from giving themselves an unfair advantage in online multiplayer sessions."
It's a FIFA game. Surely somebody already dumped the code from FIFA 14 BCE that could serve the same purpose as far as advantages go. It's not like Electronic Arts has done any updating to the game since then.
Catastrophe
I guess I'm willing to believe that video game source code is worth marginally more than an invisible sculpture. https://forums.theregister.com/forum/all/2021/06/07/invisible_sculpture_is_a_must/
So, EA must be out of pocket ... hmmm ... somewhere around €15,001? However will they survive?
No player data accessed
“no player data accessed” We get this bullshit statement time and again when ever a company is hacked. These statements that no customer data was accessed should be challenged by the authorities. The reality is they have found no evidence that customer data was accessed. These companies should not be allowed to make these statements that customer data was not accessed unless they can prove it.
Without evidence to the contrary, it should be assumed that customer data has been accessed. Companies should be required to follow the rules/laws that apply when customer data was known to be accessed.
In this case why would you not think that customer data has been accessed? I mean EA are a games company the most important thing to them are their games, the code. Thieves have got away with their crown jewels their most protected assets. If they can do that there is no reason to believe that on they way out that did not take customer data as well.
Couldn't have happened to a nicer AAARGH publisher
[1]Except Ubisoft I guess .
Excuse me while I get the world's smallest violin, EA is part of everything that's wrong with the games industry.
[1] https://www.gamesindustry.biz/articles/2021-05-18-ubisoft-has-reportedly-made-minimal-changes-following-abuse-allegations