/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

EA hackers say they used stolen cookies, bought online for $10, to gain access to EA Slack, and then tricked IT support to give login tokens for EA's network

VICE Joseph Cox

Context & Ripple Effects

EA’s reported intrusion sits alongside its confirmation that attackers claimed 780GB of data, including FIFA 21 source code and the Frostbite engine. The access account also points to the supply chain behind the incident: related coverage describes an invite-only market for stolen browser cookies, turning a compromised employee session into a purchasable entry point.

First-order effects

  • EA must treat Slack sessions and IT-support token issuance as connected access controls, because the reported path moved from a bought cookie to credentials for its network.
  • The reported theft claim raises the immediate stakes beyond a collaboration-tool compromise: EA’s game source code and engine assets were reportedly among the exposed data.

Second-order effects

  • EA’s IT support process faces pressure to require stronger verification before issuing login tokens, while security teams must invalidate or re-authenticate sessions that may rely on stolen cookies.
  • Markets selling stolen browser sessions gain relevance as a threat source for enterprises whose internal tools trust an already-authenticated employee browser.

Third-order effects

  • If cookie theft and support-led token resets continue to be combined, enterprise identity security shifts from protecting passwords alone to governing session tokens and help-desk recovery as equally sensitive control points.

The trend: The breach is part of a broader shift in which stolen authenticated sessions, rather than only stolen passwords, become a practical route into corporate networks.

Discussion

  • @josephfcox Joseph Cox on x
    New: here is how hackers broke into EA games and stole a ton of code/internal tools - bought cookie online for $10 - logged into EA Slack - trick IT support to give login token for EA network “We explain to them we lost our phone at a party last night” https://www.vice.com/...
  • @racheltobac Rachel Tobac on x
    Slack is often thought of as a fully trusted internal channel — orgs wrongly believe social engineering can't happen there. When hacking I commonly target IT Support 1st, requests to IT Support like the EA intrusion “lost phone, still need network access, please help” work often.…
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    The hackers who stole source code and documents from Electronic Arts broke in through the company's Slack. “Once inside the chat, we messaged a IT Support members we explain to them we lost our phone at a party last night.” https://www.vice.com/... https://twitter.com/...
  • @benedictevans Benedict Evans on x
    How to get past 2FA? Ask IT to turn it off for you 🤦🏻‍♂️ 🤦🏻‍♂️ 🤦🏻‍♂ ️ https://www.vice.com/...
  • @viss @viss on x
    - bought stolen cookies for slack (means 2fa isnt on, and they werent the first ones in) - they stood up their own vms (means EA staff either couldnt tell or didnt notice these were ‘evil vms’. thats bad.) this, to me, telegraphs “woefully bad security” on the part of EA. https:/…
  • @antumbral Katelyn Gadd on x
    I'm sure some people will claim this is about covid and wfh but this is really just an example of how immature technology like Slack gets integrated into workflows without people considering all the vulnerabilities in their security model https://www.vice.com/...
  • @vickerysec Chris Vickery on x
    Video call verify if your IT department received password/2-factor reset requests via Slack or other chat platforms. If your IT admins aren't familiar with your users enough to recognize them in a video call... well, maybe work on that. https://twitter.com/...
  • @mmasnick Mike Masnick on x
    This is absolutely fascinating. New attack vectors coming from all over... https://t.co/2XRhfDPl7a
  • @k8em0 Katie Moussouris on x
    Multifactor authentication: We got this. Slack: 🗣🔓🏴‍ ☠️ https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Pretty ingenious - both purchasing the cookies and doing social engineering from inside Slack. When social engineering is coming from someone inside the company's Slack channel, it's assumed they're legitimate employee, and any caution IT might normally have gets dropped. https:/…
  • @carnage4life Dare Obasanjo on x
    Hackers bought login cookies belonging to an EA employee for $10 from the dark web. Used them to login to Slack then told IT the employee lost their phone so to provide them 2FA tokens directly. Then stole code. Real life hacking's nothing like the movies https://www.vice.com/...
  • @hshaban Hamza Shaban on x
    The group of hackers that stole a wealth of data from game publishing giant Electronic Arts broke into the company in part by tricking an employee over Slack to provide a login token, Motherboard has learned. https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    Then once inside the main EA network, the hackers found another development service. They created a virtual machine, accessed another service, and downloaded the source code https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Once inside the Slack, the hackers then pretended they were a worker who had lost their phone, so they needed their multifactor authentication code. EA IT support gave it https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Started with hackers buying cookies online. These can save the login details for a user to a particular service; if you have that, you can potentially log in as them. The hackers did this to get into EA's Slack https://www.vice.com/... https://twitter.com/...
  • @joshhymannhl Josh Hyman on x
    Hackers ignored the NHL series, just like EA has done for the past decade https://twitter.com/...
  • @tha_rami Rami Ismail on x
    If I was EA I'd just dare the hackers to try and make something with Frostbite tbh https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    Scoop: games giant EA hacked. Hackers say they have 780GB of data, including source code for FIFA 21 and the Frostbite engine, used in games like Battlefield. EA confirmed breach and the items impacted. Hackers are trying to sell data on underground forums https://www.vice.com/..…