What happened
Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.
How the deception worked
The attacker sent text messages to an HR employee that led to credential capture, then used the account to move into internal collaboration systems. Once inside Slack, the intruder posted messages attempting to lure additional employees into clicking further links, using the credibility of an internal account to widen the compromise. They also accessed a spreadsheet of employee information including names, email addresses, phone numbers, salaries and office locations, and the marketing content calendar. Screenshots of the internal Slack activity and the stolen data were later published by researchers and on a hacking forum.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA on corporate identity, plus alerting on internal chat messages that contain newly-registered external links, limits both the initial takeover and the internal spread.
Sources (4)
- Activision confirms data breach exposing employee and game infoBleepingComputer·bleepingcomputer.comOpen ↗
- Hackers steal Activision games and employee dataTechCrunch·techcrunch.comOpen ↗
- Activision Data Breach Contains Employee Details, Call of Duty's Future, and MoreInsider Gaming·insider-gaming.comOpen ↗
- Threat actors leak Activision employee data on hacking forumSecurity Affairs·securityaffairs.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.