Insomniac Games hackers leak Wolverine footage, Spider-Man 2 details, 12-year release...

midian182

Posts: 9,745   +121
Staff member
What just happened? A trove of stolen data originating from a hack on developer Insomniac Games has been released online, revealing footage of the upcoming Wolverine game, sensitive documents, and the company's release schedule over the next 12 years.

On December 12, a ransomware gang called Rhysida posted what appeared to be limited evidence supporting its claim that it had hacked Insomniac Games, maker of the Ratchet & Clank and Marvel's Spider-Man series. Rhysida was offering to sell the data for 50 Bitcoins, or around $2 million.

Cyber Daily reports that with the ransom deadline now having passed, Rhysida has posted the data to its darknet leak site. A total of 1.67 terabytes were uploaded, containing more than 1.3 million files. It appears that someone bought a portion of the stolen data, as 98% of the full set was uploaded.

Much of the leak is related to the highly anticipated Wolverine game, including details about the levels, characters, locations, plot, a target release date, and gameplay/animation videos – a lot of the clips are being shared across X. The stolen data is even said to include a bootable build of Wolverine.

Rhysida has also revealed personal employee information, details on unannounced Insomniac and Sony games, budgets, deals, and screenshots of internal spreadsheets. The data covers Insomniac's planned releases stretching through to 2035, including future Spider-Man and Ratchet & Clank games, a new intellectual property, and a series of X-Men games. There are also plans for online titles featuring Wolverine, Spider-Man, and the X-Men.

In a statement attributed to Rhysida, a group spokesperson said, "Yes, we knew who we were attacking. We knew that developers making games like this would be an easy target. We were able to get the domain administrator within 20 – 25 minutes of hacking the network. Sony has launched an investigation, but it would be better in the backyard." They also confirmed that money was the only motive for the attack.

The data dump appears to be even worse than the infamous GTA VI leak that took place in September 2022. The people behind that incident were revealed to be two UK teenagers, one of whom was declared unfit to stand trial in July 2023.

Rhysida has been behind hacks on the British Library, healthcare companies, and possibly government organizations this year. The group was the subject in a joint cybersecurity advisory that highlighted how it attacks "targets of opportunity," often using VPNs to connect to internal networks from the outside, usually due to organizations not enabling MFA by default.

Permalink to story.

 
Unfit to stand trial yet intelligent enough to steal this data? Also, did the article not mention the intent was
trying to extort money?
 
Bummer for them.

BUT.

What in the world are their cybersecurity teams doing? and I know its not sony per se, but its still a SONY studio that got attacked and lost the data, what kinda swiss cheese systems do they have running that lets people keep cracking it?

I'll guess it's like alot of big companies, the work is hired out to underpaid contractors, welp, you get what you pay for.
 
Bummer for them.

BUT.

What in the world are their cybersecurity teams doing? and I know its not sony per se, but its still a SONY studio that got attacked and lost the data, what kinda swiss cheese systems do they have running that lets people keep cracking it?

I'll guess it's like alot of big companies, the work is hired out to underpaid contractors, welp, you get what you pay for.
Security is not as easy as you may think, especially when you now have to take into account working from home. Even when following strict rules and have proper security audits, human error or a simple bug exploit can ruin your day (f you QNAP!!!).

Besides, it's a game dev company, not a bank. Cybersecurity teams are not really a thing, you just have some audits from a contractor from time to time. :)
 
Back