A Valve API bug following weekly maintenance exposed achievement data for unreleased and unannounced titles on Steam, including Fable, Persona 6, and Kingdom Hearts 4. Aggregators Exophase and SteamDB automatically collected the data before the issue was identified. This incident follows a separate data breach at shipping partner CEVA Logistics that compromised European customer information in July.
Nintendo confirms a data breach impacting employee information through TinyPulse, a third-party survey service, with a ransom demand made by "extortion as a service" group ShadowByt3$. The breach does not affect customer or financial data, according to Nintendo. Employee survey data, including names, emails, and bank records, is at risk.
Education technology company Instructure, behind the popular learning management system Canvas, has reached an agreement with hacker group ShinyHunters to recover stolen data of approximately 280 million users. Despite FBI guidance advising against paying ransoms, Instructure secured the return of hundreds of gigabytes of data, including names, email addresses, and private messages. The terms of the agreement remain undisclosed.
Hacking group ShinyHunters, infamous for its recent ransom attempt on Rockstar over GTA 6, claims to have breached Nvidia's GeForce Now servers in Armenia, stealing millions of user records. Nvidia responds that the breach is limited to a third-party partner's systems, affecting only Armenian users. Users of GFN.am are advised to enable 2FA and change passwords immediately.
An in-depth analysis of the recent arrest of the Ragnar Locker Ransomware Group by Europol, its impact on Capcom, and what it signifies for cybersecurity in the gaming sector.