Business
Cloud gaming firm Shadow says hackers stole customers’ personal data
French technology company Shadow has confirmed a data breach involving customers’ personal information.
The Paris-headquartered startup, which offers gaming through its cloud-based PC service, said in an email to customers this week that hackers had accessed their personal information after a successful social engineering attack targeted the company.
“At the end of September, we were the victim of a social engineering attack targeting one of our employees,” Shadow CEO Eric Sèle said in the email, seen by TechCrunch. “This highly sophisticated attack had began on the Discord platform with the downloading of malware under cover of a game on the Steam platform, proposed by an acquaintance of our employee, himself a victim of the same attack.”
Shadow said that though its security team took unspecified “immediate action,” the hackers were able to connect to the management interface of one of the company’s software-as-a-service (SaaS) providers to obtain customers’ private data.
That data includes full names, email addresses, dates of birth, billing addresses and credit card expiry dates. Shadow says no passwords or sensitive banking data were compromised.
An individual who posted on a popular hacking forum on Wednesday claiming responsibility for the Shadow breach said they are selling the stolen database, which allegedly contains the personal data of more than 530,000 Shadow customers. The individual said they were selling the alleged data after they claimed they were ignored by the company.
Shadow spokesperson Thomas Beaufils confirmed the authenticity of the email that the company sent to customers but declined to comment further or answer TechCrunch’s questions. Shadow declined to name the software-as-a-service provider when asked by TechCrunch or say if it knows how many Shadow customers are affected, but the spokesperson did not dispute the hacker’s claims when asked.
Shadow’s email to customers, which has not yet been shared on any of the company’s website or social media channels at the time of writing, says that the company has “reinforced the security protocols” it uses with its providers and has upgraded internal systems to “render compromised workstations harmless.”
The company is advising customers to be wary of suspicious-looking emails and to set up multi-factor authentication on their accounts.
-
Entertainment6 days ago
Earth’s mini moon could be a chunk of the big moon, scientists say
-
Entertainment6 days ago
The space station is leaking. Why it hasn’t imperiled the mission.
-
Entertainment5 days ago
‘Dune: Prophecy’ review: The Bene Gesserit shine in this sci-fi showstopper
-
Entertainment5 days ago
Black Friday 2024: The greatest early deals in Australia – live now
-
Entertainment3 days ago
How to watch ‘Smile 2’ at home: When is it streaming?
-
Entertainment3 days ago
‘Wicked’ review: Ariana Grande and Cynthia Erivo aspire to movie musical magic
-
Entertainment2 days ago
A24 is selling chocolate now. But what would their films actually taste like?
-
Entertainment3 days ago
New teen video-viewing guidelines: What you should know