What happened
A hacker bribed a Roblox customer support representative, listed publicly as an in-game support contractor, to obtain access to the company's customer support panel. The panel exposed personal data on Roblox's user base and allowed password resets, removal of two-factor authentication, account bans and data changes. Roblox said it acted immediately, notified the small number of affected customers, and reported the hacker to HackerOne.
How the deception worked
The attacker skipped Roblox's perimeter entirely and bought a person instead. He identified a support contractor via LinkedIn and paid them for access to the internal customer support console, which was designed to let agents administer any account. With that console the attacker could read email addresses, force password resets, strip 2FA from targeted accounts, ban users and alter records, including for high-profile creators. He used it to change passwords on two accounts and take their in-game items. Roblox had earlier denied him a bug bounty payout over suspected malicious activity, which appears to have preceded the insider approach.
AI involvement · No AI reported
No AI involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Support consoles that can reset any account need per-record justification, least-privilege scoping and anomaly alerting on bulk or high-profile lookups, so a single bribed agent cannot become a master key.
Sources (2)
- Hacker Bribed 'Roblox' Insider to Access User DataVice / Motherboard·vice.comOpen ↗
- Hacker Bribed Roblox Worker For Access To Users' Personal DataGameSpot·gamespot.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.