{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:21:24.044Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Electronic Arts source code stolen via Slack cookie and IT help desk impersonation","date":"2021-06","date_precision":"month","victim_org":"Electronic Arts","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No confirmed payment or loss figure; the stolen data was advertised for sale on underground forums.","records_affected":null,"threat_actor":"Unnamed criminal group that spoke to Motherboard/Vice","summary":"In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.","how_it_worked":"The chain began with a cookie sold on a criminal marketplace that carried a live Slack session for an EA employee. Inside Slack the attackers had the informal context, names and internal jargon needed to sound like staff. They then approached IT support in chat, claiming a lost phone, and persuaded the agent to issue a replacement MFA token without independent identity proofing. With working corporate credentials and MFA they reached EA's internal developer compilation service, created a virtual machine to gain broader network visibility, and downloaded game source code and internal tooling. EA said no player data was accessed.","lessons":"Help desk MFA resets need identity proofing that does not depend on the requester's own chat account, such as manager verification or a video check against an HR photo record.","confidence":"Reported","sources":[{"title":"How Hackers Used Slack to Break into EA Games","url":"https://www.vice.com/en/article/how-ea-games-was-hacked-slack/","publisher":"Vice / Motherboard"},{"title":"Hackers reportedly used EA Games' Slack to breach network, access source code","url":"https://cyberscoop.com/ea-games-fifa-hack-hackers-slack/","publisher":"CyberScoop"},{"title":"Details Emerge on How Gaming Giant EA Was Hacked","url":"https://www.darkreading.com/cyberattacks-data-breaches/report-details-how-gaming-giant-ea-was-hacked","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp"}]}