Shadow said hacker stole customer data after employee lured on Discord
- Organization
- Shadow
- Exploit
- Credential Compromise
- Industry
- Cloud Gaming
Shadow, the Paris-based cloud gaming provider behind the Shadow PC service, emailed customers in October 2023 to confirm that personal data had been stolen. Chief executive Eric Sele said the company had been the victim of an advanced social engineering attack against one of its employees at the end of September.
The lure arrived through Discord, where an acquaintance who had already been compromised in the same campaign sent the employee malware disguised as a game distributed on Steam. The attacker used a stolen authentication cookie to reach the management interface of one of Shadow's software as a service providers, then queried that provider's API to extract customer records.
Shadow said the exposed data included full names, email addresses, dates of birth, billing addresses and credit card expiry dates, and that no passwords and no sensitive banking data were compromised. A seller on a hacking forum claimed to hold records for more than 530,000 Shadow customers and offered the database for sale; Shadow did not dispute the figure.
TechCrunch obtained a sample of 10,000 records and verified it was genuine by checking addresses against Shadow's signup system, reporting that the data also included private API keys and subscription details. Shadow said it had locked down affected systems and reinforced security controls with its third-party providers. It was unclear at the time whether the company had reported the breach to CNIL.