Adam Marrè, CISO at Arctic Wolf, recounts a chilling ransomware incident in the gaming industry that originated from a single phishing email. He discusses the dire consequences for developers and the crucial need for robust cybersecurity measures. David Adrian from Chrome highlights unphishable authentication methods as a means to fortify defenses. Together, they emphasize the importance of employee training and collaboration in cultivating a strong security culture to combat ever-evolving threats in the gaming sector.
The podcast highlights the alarming rise of ransomware attacks in the gaming sector, driven by high ransom payment likelihood and phishing tactics.
Experts emphasize the necessity for strong unphishable authentication methods and robust security cultures to mitigate vulnerabilities in gaming companies.
Deep dives
The Discovery of a Cyberattack
A cyberattack on a video game studio began when an engineer noticed unauthorized activity on the server, leading him to alert the head of IT. The super admin quickly shut down all accounts and sessions to mitigate the potential threat. Upon further investigation, they discovered multiple super admin accounts had been created by an intruder who was exfiltrating sensitive information. Thankfully, they caught ransomware software that was set to deploy but hadn’t yet been activated, yet the team still faced significant disruptions and needed to halt game development.
Rising Risks in the Gaming Industry
The gaming industry has seen a drastic increase in ransomware attacks, with a reported rise of over 30% year on year. One of the major reasons for these attacks is the high likelihood that game studios will pay ransoms to regain access to stolen assets, including intellectual property and game assets. This situation is exacerbated by social engineering tactics, such as phishing, which allow attackers to gain access to important accounts, as demonstrated by the IT individual's mistake in clicking a malicious link. Companies often focus on anti-cheating measures without securing their accounts, placing them at greater risk of severe security breaches.
Strategies for Enhancing Security Resilience
To improve cybersecurity resilience, businesses in the gaming sector are encouraged to prioritize identity protection and maintain rigorous patch management for vulnerabilities. Additionally, incorporating security measures during the initial design phase of game development can lead to more robust defenses against potential attacks. Companies should invest in strong, unphishable authentication methods to safeguard accounts and assets, as attackers often exploit human factors like phishing. Building a strong security culture through training and awareness is crucial to help prevent breaches, as human error remains a significant vulnerability.
When a team of video game developers notice that their files have been moved, they find themselves in a race against time to save the company from ransomware. Adam Marrè, CISO at Arctic Wolf, explains how this cyberattack traced back to a single phishing email and unpacks the ramifications for gaming companies. Then David Adrian from Chrome lays out how leaders can use unphishable authentication methods to protect their teams.