Activision warns players after infostealer malware harvested gaming logins

Organization
Activision Blizzard
Exploit
Credential Compromise
Industry
Video Games

Activision told players in late March 2024 to change their passwords and turn on two-factor authentication after a database of credentials collected by information stealing malware began circulating among researchers.

The campaign was surfaced by Zebleer, a developer of Call of Duty cheat software, who said a customer's account had been taken over and then traced the theft to a large credential database. TechCrunch reviewed a sample and confirmed that some of the logins were genuine, but could not establish how many were current or how many people were affected overall.

According to BleepingComputer, the database spanned at least a dozen gaming related services, with roughly 14 million entries tied to Discord, about 3.66 million to Battle.net and about 561,000 to Activision, alongside records from cheat marketplaces and gaming forums such as Elite PVPers and UnknownCheats. Some victims also reported that cryptocurrency wallets on their machines had been emptied.

The malware appears to have spread through free or low cost software marketed to Call of Duty players, much of it cheating tools, rather than through any official distribution channel. Activision said its own servers remained secure and uncompromised, attributed the thefts to unauthorized third-party software, and said it was helping affected players secure their accounts while it continued to investigate.

Sources