Cloud Imperium Games (CIG) disclosed that it suffered an IT incident on January 21 described as a “systematic and sophisticated attack,” resulting in unauthorized access to some backup systems and limited access to users’ personal data. CIG stated the exposed information was limited to basic account details such as names, usernames, contact information, and dates of birth, and asserted that no passwords were impacted, no financial/payment data was accessible, access was read-only, and there was no data modification.
The disclosure triggered backlash from users over how and when the company communicated the breach, with reporting highlighting that CIG initially surfaced the incident via a low-visibility website “service alert” popup rather than prominent notices or direct outreach. Coverage also emphasized that even “basic” identity and contact data can materially increase phishing and social-engineering risk, especially when combined with other breached datasets to build richer victim profiles.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Following the disclosure, users and reporters criticized Cloud Imperium Games for delaying notice of the breach and using a subtle website popup instead of direct email or a prominent announcement. Coverage highlighted that even the disclosed "basic" personal data could still be useful for phishing and identity-targeting.
About a month after the attack, Cloud Imperium Games disclosed the incident through a low-visibility website "Service Alert" popup and linked notice. The company said exposed data was limited to basic account details such as contact information, usernames, names, and dates of birth, and that it was monitoring for any public release of the data.
After detecting the attack, Cloud Imperium Games said it contained the activity, blocked further unauthorized access, and refreshed security settings. The company also stated there was no impact to passwords, no financial or payment data exposure, and no evidence of data modification.
Cloud Imperium Games said a "systematic and sophisticated attack" targeted its systems on 2026-01-21. The incident led to unauthorized access to some backup systems and limited read-only access to certain users' personal data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcescworld.com
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.