EA hackers say they used stolen cookies, bought online for $10, to gain access to EA Slack, and then tricked IT support to give login tokens for EA's network
Context & Ripple Effects
EA’s reported intrusion sits alongside its confirmation that attackers claimed 780GB of data, including FIFA 21 source code and the Frostbite engine. The access account also points to the supply chain behind the incident: related coverage describes an invite-only market for stolen browser cookies, turning a compromised employee session into a purchasable entry point.
First-order effects
- EA must treat Slack sessions and IT-support token issuance as connected access controls, because the reported path moved from a bought cookie to credentials for its network.
- The reported theft claim raises the immediate stakes beyond a collaboration-tool compromise: EA’s game source code and engine assets were reportedly among the exposed data.
Second-order effects
- EA’s IT support process faces pressure to require stronger verification before issuing login tokens, while security teams must invalidate or re-authenticate sessions that may rely on stolen cookies.
- Markets selling stolen browser sessions gain relevance as a threat source for enterprises whose internal tools trust an already-authenticated employee browser.
Third-order effects
- If cookie theft and support-led token resets continue to be combined, enterprise identity security shifts from protecting passwords alone to governing session tokens and help-desk recovery as equally sensitive control points.
The trend: The breach is part of a broader shift in which stolen authenticated sessions, rather than only stolen passwords, become a practical route into corporate networks.
Related: EA · How stolen cookies were sold through Genesis Market · EA confirms breach and reported source-code theft
Related Coverage
- EA Hackers Used Slack to Breach Security | Game Rant Game Rant
- Cybersecurity News Round-Up: Week of June 7, 2021 Security Boulevard
- Electronic Arts Hackers Say Slack Was Their Secret Weapon: Report Gizmodo
- EA hack reportedly used stolen cookies and Slack to target gaming giant TechRadar
- Hackers breach Electronic Arts, stealing game source code and tools CNN
- Hackers reportedly used EA Games' Slack to breach network, access source code CyberScoop
- Hackers steal game source code from EA The Hill
- Hackers hit EA, steal source code for FIFA 21 and more CNET
- Hackers Obtain 700GB Of EA's Data And Source Code Using Stolen Cookies - Report GameSpot
- Fallout of EA source code breach could be severe, cybersecurity experts say TechRepublic
- It took hackers $10 worth of stolen cookies and some lies to breach EA's systems Neowin
- The EA hack was worryingly simple SlashGear
- EA hack results in theft of FIFA 21 and Frostbite engine source code Destructoid
- Hackers pretended to be EA employees and got access to source code for games like FIFA 21 KnowTechie
- Hackers Explain How They Stole Wealth of Data From EA Slashdot
- The cost of the EA data breach: $10 and a bit of social engineering TechSpot
- Hackers say they've stolen FIFA and Frostbite source code in EA breach Polygon
- Hackers make off with FIFA 21 source code, data from EA - report Gearburn
- EA Games looted by intruders: Publisher says ‘no player data accessed’ after reported theft of FIFA 21, Frostbite source The Register
- Electronic Arts hacked, here are the games affected GameRevolution
- Hackers gained access to EA's corporate network via Slack Dot Esports
- Gaming Giant EA Suffers Major Data Breach infosecurity-magazine.com
- Hackers Steal FIFA 21 Source Code, Tools in EA Breach Threatpost
Discussion
-
@josephfcox
Joseph Cox
on x
New: here is how hackers broke into EA games and stole a ton of code/internal tools - bought cookie online for $10 - logged into EA Slack - trick IT support to give login token for EA network “We explain to them we lost our phone at a party last night” https://www.vice.com/...
-
@racheltobac
Rachel Tobac
on x
Slack is often thought of as a fully trusted internal channel — orgs wrongly believe social engineering can't happen there. When hacking I commonly target IT Support 1st, requests to IT Support like the EA intrusion “lost phone, still need network access, please help” work often.…
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
The hackers who stole source code and documents from Electronic Arts broke in through the company's Slack. “Once inside the chat, we messaged a IT Support members we explain to them we lost our phone at a party last night.” https://www.vice.com/... https://twitter.com/...
-
@benedictevans
Benedict Evans
on x
How to get past 2FA? Ask IT to turn it off for you 🤦🏻♂️ 🤦🏻♂️ 🤦🏻♂ ️ https://www.vice.com/...
-
@viss
@viss
on x
- bought stolen cookies for slack (means 2fa isnt on, and they werent the first ones in) - they stood up their own vms (means EA staff either couldnt tell or didnt notice these were ‘evil vms’. thats bad.) this, to me, telegraphs “woefully bad security” on the part of EA. https:/…
-
@antumbral
Katelyn Gadd
on x
I'm sure some people will claim this is about covid and wfh but this is really just an example of how immature technology like Slack gets integrated into workflows without people considering all the vulnerabilities in their security model https://www.vice.com/...
-
@vickerysec
Chris Vickery
on x
Video call verify if your IT department received password/2-factor reset requests via Slack or other chat platforms. If your IT admins aren't familiar with your users enough to recognize them in a video call... well, maybe work on that. https://twitter.com/...
-
@mmasnick
Mike Masnick
on x
This is absolutely fascinating. New attack vectors coming from all over... https://t.co/2XRhfDPl7a
-
@k8em0
Katie Moussouris
on x
Multifactor authentication: We got this. Slack: 🗣🔓🏴 ☠️ https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
Pretty ingenious - both purchasing the cookies and doing social engineering from inside Slack. When social engineering is coming from someone inside the company's Slack channel, it's assumed they're legitimate employee, and any caution IT might normally have gets dropped. https:/…
-
@carnage4life
Dare Obasanjo
on x
Hackers bought login cookies belonging to an EA employee for $10 from the dark web. Used them to login to Slack then told IT the employee lost their phone so to provide them 2FA tokens directly. Then stole code. Real life hacking's nothing like the movies https://www.vice.com/...
-
@hshaban
Hamza Shaban
on x
The group of hackers that stole a wealth of data from game publishing giant Electronic Arts broke into the company in part by tricking an employee over Slack to provide a login token, Motherboard has learned. https://www.vice.com/...
-
@josephfcox
Joseph Cox
on x
Then once inside the main EA network, the hackers found another development service. They created a virtual machine, accessed another service, and downloaded the source code https://www.vice.com/... https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
Once inside the Slack, the hackers then pretended they were a worker who had lost their phone, so they needed their multifactor authentication code. EA IT support gave it https://www.vice.com/... https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
Started with hackers buying cookies online. These can save the login details for a user to a particular service; if you have that, you can potentially log in as them. The hackers did this to get into EA's Slack https://www.vice.com/... https://twitter.com/...
-
@joshhymannhl
Josh Hyman
on x
Hackers ignored the NHL series, just like EA has done for the past decade https://twitter.com/...
-
@tha_rami
Rami Ismail
on x
If I was EA I'd just dare the hackers to try and make something with Frostbite tbh https://www.vice.com/...
-
@josephfcox
Joseph Cox
on x
Scoop: games giant EA hacked. Hackers say they have 780GB of data, including source code for FIFA 21 and the Frostbite engine, used in games like Battlefield. EA confirmed breach and the items impacted. Hackers are trying to sell data on underground forums https://www.vice.com/..…