Case Library / Help-Desk & MFA Manipulation / EA Games Slack/MFA Social Engineering Breach (2021)

EA Games Slack/MFA Social Engineering Breach (2021)

Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack, then twice talked EA IT support into issuing a fresh MFA token by claiming a lost phone, then walked straight into EA's network and out with ~780GB including FIFA 21 and Frostbite engine source code.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In early June 2021, a cybercriminal group breached Electronic Arts' internal network and exfiltrated a large trove of proprietary game development data. The attackers told Motherboard/Vice that they began by purchasing stolen Slack session cookies for $10 on an underground marketplace, using them to access a Slack channel used internally by EA employees. From inside that trusted internal channel, they impersonated an EA employee and messaged IT support claiming to have "lost our phone at a party last night," requesting that a new multi-factor authentication token be issued, a request IT support fulfilled, and did so successfully a second time as well. Armed with valid MFA-backed access to EA's corporate network, the attackers located an internal service used by EA developers to compile games, logged in, created a virtual machine to expand their visibility into the network, and used it to reach another internal service from which they downloaded game source code. The hackers claimed to have taken roughly 780GB of data, including the source code for FIFA 21 and its matchmaking server tools, the source code and debug tools for the Frostbite game engine (used in Battlefield and other EA titles), assorted proprietary frameworks/SDKs, and internal documents. EA confirmed the intrusion publicly on June 11, 2021, characterizing the loss as a "limited amount of game source code and related tools," stating no player data was accessed and no material business impact was expected. On July 14, 2021, EA disclosed that the hackers had made an extortion threat and released a portion of the stolen files publicly; EA maintained that its analysis still showed no material risk to player privacy or its business, and said it continued working with federal law enforcement.

How the Attack Worked

The attackers first purchased stolen Slack session cookies for $10 from an online marketplace and used them to gain access to an EA-used Slack channel, bypassing the need to phish or guess a password since the cookie carried an already-authenticated session. Once inside Slack, posing as a legitimate EA employee, they messaged an IT support staffer and explained they had "lost our phone at a party last night," then asked for a new multi-factor authentication token to be issued so they could log into EA's corporate network. IT support complied, and did so successfully a second time as well. With a freshly issued MFA token and VPN/network access, the attackers found an internal service EA developers use to compile games, logged in, spun up a virtual machine for deeper network visibility, then reached another internal service and downloaded game source code, including FIFA 21 and its matchmaking server code, the Frostbite engine source and debug tools, and various internal frameworks/SDKs and documents.

The Lure & the Tell

There was no phishing email, fake login page, or malicious attachment to catch. The entire pretext played out as a normal-looking internal Slack conversation from an account whose session had been hijacked via a purchased cookie, followed by a verbally plausible helpdesk request ("I lost my phone last night, I need a new MFA token"). The only "tell" was procedural, not visual: EA's IT support accepted a self-reported, unverified identity claim over chat as sufficient grounds to reissue an MFA token, twice, with no independent verification step (callback, manager sign-off, ID check), a process gap rather than a spoofed artifact a user or filter could have flagged.

Outcome

EA publicly confirmed the intrusion on June 11, 2021, stating a "limited amount of game source code and related tools" were stolen, that no player data was accessed, and that it did not expect material impact to its games or business; EA said it made security improvements and was working with law enforcement. The hackers advertised the data (claimed at ~780GB, including FIFA 21 and Frostbite source) on underground forums, initially seeking $28 million. On July 14, 2021, EA disclosed it had become aware of an extortion threat and that a portion of files had been released publicly by the hackers; EA reiterated it saw no material risk to player privacy or its business. A later archived forum post (captured July 26, 2021) attributed to a poster using the name "4c3" and invoking the LAPSUS$ name demanded 10% of the asking price and threatened to release 20-25TB more data if unpaid within 45 days; this later extortion/attribution detail is less firmly corroborated than EA's own confirmed statements. No arrests, indictment, or definitive threat-actor attribution tied to this specific incident were identified in public reporting.

Why It Matters

This incident is a foundational case study in MFA-target social engineering: rather than defeating MFA cryptographically, the attackers defeated the human process surrounding it, a helpdesk willing to reissue a token on a plausible verbal claim with no independent verification, reached via a hijacked internal-chat session rather than any phishing lure. It foreshadows the wave of helpdesk-centric MFA/identity attacks that followed (e.g., Uber 2022, Cisco 2022, MGM Resorts/Caesars 2023), all of which exploit the same weak link: human help-desk verification of identity for credential/MFA resets, rather than technical bypass of the MFA mechanism itself. It also illustrates how a stolen session cookie can be a more direct path into an organization than credential phishing, since it inherits an already-authenticated session and does not require multi-factor login at all.

Defenses

Require out-of-band, multi-factor identity verification before any helpdesk-initiated MFA re-enrollment or token reissuance (e.g., callback to a pre-registered number/device, manager attestation, video/photo-ID check) rather than accepting a plausible story alone; treat "lost device, need new MFA" requests as high-risk and route them through a stricter, logged, non-chat verification workflow; shorten session/cookie lifetimes and bind sessions to device fingerprints so a stolen cookie alone cannot grant durable access; monitor and alert on anomalous session reuse (new IP/geo/device on an existing session token); move toward phishing-resistant, hardware-bound authenticators (FIDO2/WebAuthn security keys) that cannot be "reissued" via a helpdesk conversation the way a soft MFA token can; segment and limit what an authenticated Slack/chat session can reach on the corporate network; monitor underground forums/marketplaces for employee credential and session-cookie sales; run helpdesk staff through social-engineering-resistance training specifically covering pretexts like "lost my phone."

Sources
  • EA Statements on Recent Security Incident. Electronic Arts (official company statement) Primary. EA's own June 11, 2021 and July 14, 2021 statements confirming the intrusion, that game source code/tools were stolen, no player data accessed, and later confirming the extortion threat and partial file release.
  • How Hackers Used Slack to Break into EA Games. Vice / Motherboard (Joseph Cox) Secondary. First and primary journalistic account, based on direct chat interview with a hacker representative plus corroborating screenshots and EA's own confirmation; source of the $10 cookie detail, the 'lost our phone at a party' quote, and the 'worked twice' MFA detail.
  • Hackers Steal Wealth of Data from Game Giant EA. Vice / Motherboard Secondary. Companion report detailing the ~780GB claim and the specific stolen assets (FIFA 21 source code, matchmaking server code, Frostbite engine source and tools).
  • Hackers Move to Extort Gaming Giant EA. Vice / Motherboard Secondary. Reports the July 2021 extortion threat and public release of a portion of the stolen files.
  • Hackers leak full EA data after failed extortion attempt. The Record by Recorded Future Secondary. Corroborates the $28 million asking price and reports the hackers' own claim that the stolen Slack authentication cookie was purchased from the Genesis dark-web marketplace, plus the eventual full-data leak after the extortion attempt failed.
  • EA Games Credentials Leaked via Slack Cookies. Lookout (threat intelligence) Secondary. Security-vendor technical summary corroborating the cookie-theft-to-MFA-social-engineering chain.
  • EA Acknowledges Breach; Says Game Source Code Stolen. DataBreachToday / Information Security Media Group Secondary. Secondary reporting corroborating the breach confirmation, the June 6 RaidForums listing date, and the 780GB data description; this article does not itself state the $28 million asking price (see Threatpost source for that figure).
  • Hackers Steal FIFA 21 Source Code, Tools in EA Breach. Threatpost Secondary. Reports the $28 million asking price quoted in the hackers' cached RaidForums listing for the 780GB data dump, corroborating that figure independently of Vice/Motherboard's reporting.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and tooling acquisition: Attackers likely researched EA's internal tooling and Slack usage before contact; Motherboard separately reported that in February 2020 an ex-EA engineer had left a list of EA Slack channel names in a public-facing code repository, a detail Motherboard noted was not confirmed to be connected to this specific breach but is consistent with the kind of low-cost OSINT that lets attackers make an internal-chat pretext sound credible.
Countering Stage 1: Employee-facing OSINT and accidental internal-tooling exposure (leaked channel names, org charts) is very hard to fully eliminate; the realistic controls are secret-scanning on public code repositories and departing-employee access/repository audits, so the exposure window closes quickly if it happens again, plus hardening the downstream process (Stage 5) that this kind of reconnaissance is ultimately used against.
2
Acquisition of a stolen session cookie: The attackers told Motherboard they purchased a stolen Slack authentication cookie for $10 from an underground online marketplace, a commodity-credential market of the kind (subsequent reporting on the wider incident named Genesis Market as the likely source type) that trades in browser session data harvested from infected devices.
Countering Stage 2: Monitor underground and dark-web marketplaces for employee session-cookie and credential listings tied to the organization, and deploy endpoint detection that flags infostealer malware before it can harvest browser session cookies from employee devices in the first place.
3
Session hijack for initial access: The purchased cookie carried an already-authenticated session, letting the attackers log into an EA-used Slack channel directly, without phishing a password or defeating any login-time MFA prompt.
Countering Stage 3: Shorten session and cookie lifetimes and bind sessions to device fingerprints or IP ranges, so a stolen cookie alone cannot grant durable access, and alert on anomalous session reuse from a new device, browser, or geography.
4
Pretext development and impersonation: Once inside the trusted internal channel, the attackers posed as a legitimate EA employee and messaged an IT support staffer with a low-suspicion, relatable cover story, that they had lost their phone at a party the night before.
Countering Stage 4: A crafted verbal pretext delivered inside an already-trusted chat session is very hard to flag at the point of telling; the realistic control sits at the point the pretext is acted on, hardening the helpdesk verification step in Stage 5 rather than trying to detect a plausible story in isolation.
5
Helpdesk social engineering for MFA reissuance: The attackers asked IT support to issue a new multi-factor authentication token so they could log into EA's corporate network; IT support complied based on the chat identity claim alone, and the same request succeeded a second time as well.
Countering Stage 5: Require out-of-band, multi-factor identity verification (callback to a pre-registered number or device, manager attestation, video or photo-ID check) before any helpdesk-initiated MFA re-enrollment or token reissuance, and route "lost device" requests through a stricter, logged, non-chat verification workflow rather than accepting a plausible story alone.
6
Network foothold expansion: With a freshly issued MFA token and network access, the attackers located an internal service EA developers use to compile games, logged in, and created a virtual machine to gain broader visibility into the internal network.
Countering Stage 6: Segment and limit what an authenticated Slack or chat session and a freshly reissued MFA token can reach on the corporate network, apply least-privilege access to build/compile infrastructure, and monitor for anomalous virtual-machine creation or unusual logins to internal developer services.
7
Lateral movement and data exfiltration: From that foothold the attackers reached another internal service and downloaded roughly 780GB of data, including FIFA 21 and its matchmaking server source code, Frostbite engine source and debug tools, other proprietary frameworks/SDKs, and internal documents.
Countering Stage 7: Apply data-loss-prevention and egress monitoring around source-code repositories and internal file-sharing services, log and alert on abnormally large or unusual data transfers, and limit which accounts can reach sensitive source trees in the first place.
8
Monetization and payout: The attackers first advertised the stolen dataset on underground forums for $28 million; when no buyer materialized they pivoted to directly extorting EA, releasing a 1.3GB partial file cache publicly on July 14, 2021, and, per a later archived forum post signed with the LAPSUS$ name, threatened to release a much larger 20 to 25 terabyte cache if a ransom was not paid within 45 days.
Countering Stage 8: Once data has been exfiltrated, no technical control stops an attacker from advertising or publishing it; the realistic defense is upstream, preventing the Stage 6 to 7 exfiltration itself, combined with monitoring underground forums for early warning of a sale or leak and engaging law enforcement promptly, as EA did.
Quick Facts
Victim
Electronic Arts (EA)
Location
Electronic Arts headquarters, Redwood City, California, USA (attackers' physical location was not disclosed/attributed)
Date
2021-06-06 to 2021-07-14 (intrusion/theft occurred by early June 2021; forum sale ad ~June 6; EA confirmed breach June 11, 2021; extortion threat and partial file leak disclosed by EA July 14, 2021)
Impact
No direct ransom paid and no material financial impact publicly confirmed by EA. The stolen ~780GB dataset (including FIFA 21 and Frostbite engine source code) was initially advertised for sale on underground forums for $28 million; hackers later shifted to extortion, releasing a portion of files publicly in July 2021 while demanding payment. EA's official statements said it saw no material risk to its games or business and no impact to player data; no SEC filing or disclosed monetary loss figure was located.
Status
Confirmed
Case Type
Real-World Incident
Sector
Media & Entertainment, Technology & Software
Related

Related Cases

Caesars Entertainment Vendor Social Engineering Breach (2023)

Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since…

Incident 2023Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group…

Incident 2022Read →