Insomniac Games said it was the victim of a ransomware attack after the Rhysida gang published stolen material that reportedly included employee personal data and internal company files. The studio described the incident as "extremely distressing," said it was working quickly to determine what data was affected, and notified current and former employees whose information may have been exposed. Reports on the leak said the dumped files also contained development material tied to upcoming projects, intensifying the impact beyond privacy risks.
The breach added Insomniac, a Sony-owned game developer known for the Marvel's Spider-Man franchise, to a growing list of entertainment and technology companies hit by extortion-driven intrusions. Public reporting indicated the attackers had attempted to auction the stolen data before releasing it, a tactic increasingly used by ransomware groups to pressure victims even when encryption is not the primary disruption. The incident highlighted the dual business risk of modern breaches: exposure of sensitive workforce records and theft of commercially valuable intellectual property.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Insomniac Games publicly acknowledged a data breach and described it as extremely distressing. The statement confirmed the company was responding to the incident after reports of stolen data surfaced.
A report alleged that Ubiquiti suffered a breach that could put many cloud-based devices at risk of takeover, raising concerns about the security of customer environments. The article was later retracted, but the reported breach allegation itself marked the key development.
Reports emerged that Kremlin official Vladislav Surkov had been hacked, with the incident described as a potentially significant shift in cyber conflict involving Russia. The disclosure drew attention as a notable geopolitical cyber event.
A large internet outage tied to DNS provider Dyn disrupted access to major online services and prompted investigation into possible causes. U.S. officials, including the Department of Homeland Security, began looking into the incident.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
videogameschronicle.com
Open sourcearstechnica.com
Open sourcetime.com
Open sourcetime.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.