Ubisoft security breached, over 900GB stolen

Entropi

Veteran
Icon Extra
22 Jan 2023
2,302
3,435
Iirc 2 factor authentication creates some sort of security problem.

Let me tell tell you about someone I know. Let’s call him Steve. MFA was implemented at his company after bad actors social engineered an HR admin and installed ransomware at the org. Huge crisis.

Steve is not happy because MFA is a minor inconvenience, and he doesn't care a bit about his job, it is something that just pays the bills.

If Steve sees a notification repeatedly coming from the MFA app, he will accept it to make it go away.

Steve is the stuff of nightmares for anyone working in infosec, and MFA solutions now need to be designed for bad actors and Steves as well. But MFA itself is a good tool for having a sound cybersecurity posture.
 
  • they're_right_you_know
Reactions: ethomaz

ethomaz

Rebolation!
21 Jun 2022
8,590
7,280
Brasil 🇧🇷
PSN ID
ethomaz
Let me tell tell you about someone I know. Let’s call him Steve. MFA was implemented at his company after bad actors social engineered an HR admin and installed ransomware at the org. Huge crisis.

Steve is not happy because MFA is a minor inconvenience, and he doesn't care a bit about his job, it is something that just pays the bills.

If Steve sees a notification repeatedly coming from the MFA app, he will accept it to make it go away.

Steve is the stuff of nightmares for anyone working in infosec, and MFA solutions now need to be designed for bad actors and Steves as well. But MFA itself is a good tool for having a sound cybersecurity posture.
Yeap.

Steve should see the notification that was not to him and call the company IT immediately to block his access until their do an investigation.

MFA solo is not the solution… it is needs to be combined to a lot of others layers of security.

But no MFA is basically a huge security issue… there is a research that shows that MFA blocks 99% of the openings you could have with username/password leaks.
 
  • they're_right_you_know
Reactions: Entropi

Snes nes

Banned
4 Aug 2023
735
578
Let me tell tell you about someone I know. Let’s call him Steve. MFA was implemented at his company after bad actors social engineered an HR admin and installed ransomware at the org. Huge crisis.

Steve is not happy because MFA is a minor inconvenience, and he doesn't care a bit about his job, it is something that just pays the bills.

If Steve sees a notification repeatedly coming from the MFA app, he will accept it to make it go away.

Steve is the stuff of nightmares for anyone working in infosec, and MFA solutions now need to be designed for bad actors and Steves as well. But MFA itself is a good tool for having a sound cybersecurity posture.

Yeah the guy who doesn’t know anything about computers and doesn’t care to use common sense is an annoyance. I recall hearing this from some youtubers making it seem like it was a huge security flaw. I don’t recall if the details were exaggerated or not though. I’d have to look.
 

Gods&Monsters

Veteran
Icon Extra
21 Jun 2022
4,562
9,322
Let's see if the angry people demanding for all the details in the Insomniac leak to be reported will keep the same energy for Ubisoft 😒

Amazing how Microsoft escapes all the time though.
They get leaked but not in the gaming division (besides the FTC stuff).

We want to know the consoles sales, the budget and how many copies sold. Get on it hackers!!
 
  • Like
Reactions: Diah and Jim Ryan

Systemshock2023

Veteran
8 May 2023
1,743
1,413
Let's see if the angry people demanding for all the details in the Insomniac leak to be reported will keep the same energy for Ubisoft 😒

The thing is, no one cares about Ubisoft stuff. Maybe some assassin's Creed Japan playable build or BG&E2 but other than that... it's not like a leak of far cry 27 will cause a meltdown.
 
  • sad
Reactions: Gods&Monsters

TubzGaming

Admin | Mod
Moderating
21 Jun 2022
2,228
5,103
icon-era.com
PSN ID
Tubz_Gaming
The year of the leaks: 2023
Clive Barker Help GIF by Arrow Video
 

Yurinka

Veteran
VIP
21 Jun 2022
6,088
5,272
Info on beyond good and evil 2 should be interesting.
Unless the hackers leak it, it should be publicly shared next year, maybe in their Ubisoft Forward summer event, because they have been working on it since forever.
 
Last edited:

Yurinka

Veteran
VIP
21 Jun 2022
6,088
5,272
Put 2 factor authentications.
They already have it, but at least some yeaars ago was optional. And like anything, hackable/bypassable.

Control who access your files.
Files in Ubisoft have multiple types of controls to access the files and different levels of confidentiality: some were available for everyone in Ubisoft, other ones were for people from a studio only, or for the pople from a project, or from the people of a specific studio working on that project, or only for a department and a long etc.

They are very open for certain things if you're in certain position: as an example I was head of my department in my studio, so I was given access to the key documents of that department from other games/studios I wanted to learn from them. When theorically I shouldn't have access to them. We shared a lot of stuff internally.

But everything was controlled and tracked.

Have a easy go offline option… if any suspicious access is happening turn everything offline until you check and deal with it.
This is what companies do. Or what happens when there are internet blackouts.

There is no way a hacker will download 1TB of data without you get alerts from suspicious actions if you implemented proper IT security.
It's a company with 20000 employees working from over 40 different studios and a lot of them working in remote constantly sharing a lot of heavy stuff.

1TB isn't even the size of a project (not counting duplied stuff in repositories), he got revoked access probably in under an hour if this is all he could download.

But being a hacker who knows what he got and who hacked. If a studio in charge of testing or the HQ, Montreal or Toronto could get info of a lot of projects.
 

Plextorage

Veteran
26 Feb 2023
1,561
1,585
Really, this is horrible. Cyber security really is a dog shit in gaming industry or hackers got better.
 

Zzero

Major Tom
9 Jan 2023
3,285
1,997
I'm confused, OPs post makes it sound like they failed to extract the data but you are all acting like they succeded.
 
  • they're_right_you_know
Reactions: Johnic

KnittedKnight

Gaming Sage
Icon Extra
13 Jul 2022
2,268
2,741
I'm confused, OPs post makes it sound like they failed to extract the data but you are all acting like they succeded.
Under the impression they got some, just not all that they wanted. It's not clear.