News

Why Is The Gaming Industry So Attractive To Cyber Criminals?

Giulio Saggin
Giulio Saggin
Thursday 14 December 2023
Why Is The Gaming Industry So Attractive To Cyber Criminals?
Photo: Erik Mclean / Unsplash

Electronic sports - Esports - revenue in 2023 is expected to exceed $200 billion, betting on Esports is expected to reach US$2.1bn in 2023, and the top Esports team in the world, TSM, is valued at $540 million.

With numbers like these - and growing - it's little wonder that hackers have been sitting up and taking note of the gaming industry for some time. Between July 2022 to July 2023, cybersecurity company Kaspersky revealed the weak points of the gaming industry and, in particular, its vast user base, which has been used to access personal data, launch various attacks, and fall victim to trojan and phishing campaigns.

During this period, more than four million attempts were made to download nearly 31,000 unique files masked as popular games, mods, cheats, and other game-related software. These files were capable of downloading other programs, often malicious, to whichever device was being used, and affected more than 192,000 users globally. The mobile gaming community, which consists of more than three billion gamers, was recorded as having more than 435,000 attempts to infect mobile devices, impacting nearly 85,000 users.

DISABLING AN ENTIRE COUNTRY

In recent history - 2021 - there was a 167% increase in web application attacks from the previous year and the gaming industry was the most targeted by DDoS attacks, accounting for more than a third globally. The motivations behind these attacks range from financial gain to, simply, the thrill of wreaking havoc.

DDoS attacks have proven popular for the disruption they cause. Even on a national scale, as was the case when the entire internet service of one small European country, Andorra, was taken down by a DDoS attack. In January, 2022, a large-scale tournament was hosted on Minecraft and featured 150 competitors globally, a grand prize of US$100,000, and attracted more than one million viewers on its first day, was the subject of a DDoS attack. At least a dozen Andorran competitors had to pull out, but the damage went far beyond. The attack took down the country's only ISP for four days and, along with it, the internet service for all 80,000 Andorrans. And not just individuals: schools, offices, and government offices were among the collateral damage.

YouTube: MCBYT
YouTube: MCBYT

Disruption isn't the only game being played by hackers. In 2019, Epic Games, creators of the Fortnite video game, announced that Fortnite’s login system had a flaw that allowed hackers to impersonate players and buy in-game currency using credit or debit card details related to the account. The number of those affected was never disclosed, however Fortnite has an estimated 200 million registered users.

Data is the new gold and the gaming industry has lots of it, which plays into the hackers' hands. In July, 2022, the virtual pet website, Neopets, confirmed that its IT systems had been compromised and 69 million of its member registrations and source codes were on sale for 4 Bitcoin. The compromised data included users’ names, email addresses, usernames, birth dates, gender, IP addresses, Neopets PINs, and hashed passwords, as well as data generated during the game.

BUG BOUNTIES IN PLACE

The gaming industry now rates as the fastest growing media industry sector, with a current - and ever-increasing - viewership of 530+ million annually. As the industry expands, so does the need to make sure it and its fans are protected by robust cyber security infrastructure.

One of the ways the industry is doing this is via the use of bug bounty programs. Microsoft has one in place for Xbox, with incentives to match: qualified submissions are eligible for payouts of US$500 to US$20,000. However, it's not just IT giants with big bucks on offer to protect their resources. Other gaming companies offering bug bounties include InnoGames, Riot Games, Nintendo, FanDuel and Valve.

Bug bounties along won't protect the gaming industry, but it's a positive step, as are measures like regularly updating software and conducting thorough risk assessments to identify potential vulnerabilities. As well as 'looking within', the industry can help themselves by educating those playing their games about cybersecurity best practices, such as using unique passwords and enabling two-factor authentication.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203