Gamers furious as Brit studio Cloud Imperium quietly admits to data breach
- Reference: 1772519059
- News link: https://www.theregister.co.uk/2026/03/03/brit_games_studio_cloud_imperium/
- Source link:
Readers have contacted The Register to point out that the company’s (CIG’s) sites have, in recent hours, included a meek popup “Service Alert” that advises “We are aware of an IT incident that impacts some of our users” and offers a link to [1]this page that reveals the incident took place on January 21st when the company says it was “targeted by a systematic and sophisticated attack, resulting in unauthorised access to some backup systems, including limited access to users’ personal data.”
That went down like a cold bucket of sick to users
One of the readers who contacted The Register about the incident described the company’s tactics as “Notice duly published in a locked filing cabinet stuck in a disused lavatory.”
CIG claims it “acted quickly to contain the activity and block further access to this data and CIG systems, and we have refreshed security settings to ensure that there is no threat to our games or our users.”
Yet the next sentence of the statement says the company does not “consider the incident poses a risk to the safety of our users” because the data accessed “relates only to basic account details (i.e. metadata, contact details, username, date of birth, and name). No financial or payment information was stored in the affected systems and was not accessible. No passwords were impacted, and the access was read-only. No data-injection or modification occurred.”
[2]
That’s an optimistic response because contact details, names and dates of birth are all that’s needed to craft a convincing phishing campaign. Further, the vast quantity of stolen data available online means crooks can take info they swiped from CIG, add it to other troves, and build up more detailed pictures of individuals they might wish to target.
[3]
[4]
“We are closely monitoring the situation and our systems to ensure that no further incidents occur,” the statement adds. “We are also taking steps to assess and detect whether any data that was accessed is released publicly. At this stage, there are no indications of any such activity.”
The company concludes it is “sharing this update in the interests of transparency. However, we do not anticipate that this incident will have any impact on our users.”
[5]
Another tipster criticized CIG’s stance.
“Details compromised –but users expected not to worry because that's 'Basic' information according to CIG/RSI. Yes, that went down like a cold bucket of sick to users.”
Commentors in the game’s [6]forums are similarly unimpressed.
[7]
“WHERE IS THE EMAIL and FRONT PAGE NOTICE?” thunders the first comment in a thread on the matter.
“What upsets me, is the lack of communication, and after a !month!, you get a basically hidden message, that something happened,” wrote another player. Plenty of others have decided CIG has breached one law or another, and expect action.
CIG’s flagship product is a multiplayer game called “Star Citizen” that the outfit has worked on for years, fueled by crowdfunded contributions. The company says its community numbers in the millions, but hasn’t revealed how many were impacted by this incident.
The Register has asked the company to clarify the matter and will update this story if we receive a substantive response. ®
Get our [8]Tech Resources
[1] https://robertsspaceindustries.com/en/Website-Notice
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aaa_URebNGmpXDim2vgFGgAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aaa_URebNGmpXDim2vgFGgAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aaa_URebNGmpXDim2vgFGgAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aaa_URebNGmpXDim2vgFGgAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://robertsspaceindustries.com/spectrum/community/SC/forum/3/thread/security-breach-responsible-disclosure-matters
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aaa_URebNGmpXDim2vgFGgAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
"sophisticated"
“targeted by a systematic and sophisticated attack"
It's always "sophisticated".
Re: "sophisticated"
More sophisticated than the org that they breached. Just having the hood on their hoodie up makes a hacker more sophisticated. Well known fact.
Re: "sophisticated"
That's because it exceeded their understanding, so obviously it was much more "sophisticated" than their defenses.
It's the boilerplate excuse for "We got caught flat-footed, we need to improve our security".
Re: "sophisticated"
"systematic": make a word list
"sophisticated": pip install s3recon
They had a previous [1]accident 10 years ago.
[1] https://gameranx.com/updates/id/70033/article/the-chris-roberts-theory-of-everything/#:~:text=accidentally%20let%2048%20GB%20of%20Star%20Citizen%20game%20assets%20leak
“We are closely monitoring the situation"
Oh ? And you were doing what before ? Having a coffee break ?
Re: “We are closely monitoring the situation"
What were they doing before?
They were busy not finishing Star Citizen ;)
Is it just me..?
If I ever have to sign up to something that isn't too official, I never use my correct DOB. Maybe the correct year for anything slightly age restricted, but never my true DOB.
Re: Is it just me..?
It's not just you.
I wonder how many other people were "born" on the 1/1/01, at least according to the internet sites that ask for this info without actually needing it...
Re: Is it just me..?
I use 1969-12-31.
Star Citizen is the modern definition of Vapourware. 15 years of development, millions of dollars in funding obtained, and all they have delivered is a couple of demos.
I'm not at all surprised that their security is equally nebulous...
Not really a Brit studio
It's on [1]remote control from Texas .
Also, the company registration information they give for their German studio is wrong and it's probably illegal to give false information in Germany when you look at the kind of information German business websites usually include. Even [2]Amazon makes an effort .
[1] https://cloudimperiumgames.com/pages/legal
[2] https://www.amazon.de/-/en/gp/help/customer/display.html?nodeId=GF4WKPX3G65RNNRJ&language=en