{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a"},"incident":{"title":"Riot Games loses League of Legends source code to a social engineering attack","date":"2023-01","date_precision":"month","victim_org":"Riot Games","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Service Disruption"],"loss_usd":null,"loss_note":"Riot refused the $10 million ransom demand and did not publish remediation costs.","records_affected":null,"threat_actor":null,"summary":"Riot Games disclosed in January 2023 that attackers used social engineering to compromise its development environment and steal source code for League of Legends and Teamfight Tactics along with a legacy anti-cheat platform. The company received a ransom email demanding $10 million and publicly refused to pay. Riot said no player data or personal information was compromised, but the intrusion disrupted its build pipeline and delayed game patches.","how_it_worked":"Riot attributed the intrusion to social engineering rather than a software vulnerability and said an employee's access was the entry point, without publishing the script used. The attackers' goal shaped the tradecraft: rather than encrypting systems they moved quietly into the build and source environment, took the anti-cheat and game code that has resale value in the cheat-development market, and only surfaced afterwards with an emailed extortion demand. Riot's refusal to pay, and its public commitment to publish a post-incident report, limited the leverage the stolen code created.","lessons":"Source and build environments should require phishing-resistant MFA and device trust separately from general corporate SSO, so one socially engineered employee cannot reach them.","confidence":"Confirmed","sources":[{"title":"Riot Games receives 'ransom email' for stolen source code following social engineering attack","url":"https://therecord.media/riot-games-receives-ransom-email-for-stolen-source-code-following-social-engineering-attack","publisher":"The Record"},{"title":"Riot Games receives ransom demand from hackers, refuses to pay","url":"https://www.bleepingcomputer.com/news/security/riot-games-receives-ransom-demand-from-hackers-refuses-to-pay/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a"}}