Insomniac Games Falls Victim to Ransomware Attack
Initial Report, Tuesday, December 19: A ransomware group has leaked 1.67 TB of stolen data from Insomniac Games following a security breach that occurred last week. According to Cyber Daily, the Rhysida ransomware group infiltrated the PlayStation studio's systems on December 12 and initially put the stolen data up for auction for 50 bitcoins, approximately $2 million, with a deadline of one week. Prior to the deadline, the group released 1.67 TB of internal data. Some of the stolen information was reportedly sold to an unknown bidder. The leaked data, comprising 1.3 million files, includes Insomniac's release schedule up to 2035, details about unannounced games, and personal information of employees. Additionally, it features extensive details about the upcoming Wolverine game, including gameplay footage, level design, plot, ending, characters, and cast. The breach also revealed an alleged exclusivity deal between Sony and Marvel for X-Men games until December 2035, as reported by IGN. Furthermore, documents related to unannounced projects from other PlayStation studios, such as Guerrilla Games and Bluepoint Games, were found in the leaked data, according to Polygon. GamesIndustry.biz has reached out to Sony for a statement. Earlier this year, a hacker group known as Ransonware.vc claimed responsibility for an attack on Sony's systems, resulting in the leak of 6,000 files. In October, the personal information of nearly 6,800 current and former Sony employees was compromised by the ransomware group Clop. Update, Friday, December 22: Insomniac Games has issued an official statement on social media regarding the data breach. The game developer expressed sadness and anger over the cyberattack and its emotional impact on the development team. The statement acknowledged that the stolen data includes personal information of employees, former employees, and contractors, as well as early development details for Marvel's Wolverine on PlayStation 5. The studio is currently working to determine the full extent of the compromised data.