Hackers don’t necessarily need to break into networks to compromise game companies — sometimes, it’s just about coercing the right people. An anonymous attacker talking to Motherboard has revealed that they bribed a Roblox customer support representative to get access to the customer support panel for the online game platform. The intruder could see email addresses, change passwords, strip two-factor authentication and even ban users.

This was done solely to “prove a point,” the hacker claimed. As evidence, they provided photos showing details of a handful of players, including high-profile examples. However, this wasn’t a strictly virtuous act — the perpetrator changed passwords for two accounts, sold items and updated two-factor settings once it became clear an attempt to claim a bug bounty (for a non-existent flaw) wasn’t going to work.

Not surprisingly, the studio wasn’t pleased. A spokesperson said that it rushed to “address the issue” and alert affected customers. It also reported the culprit to the HackerOne bug bounty program for an investigation.

The incident did little damage, but underscores the growing risks of social engineering attacks (that is, preying on workers with access to key controls). This, SIM swapping and similar schemes frequently exploit lax verification processes and low-paid customer service reps to get access they wouldn’t otherwise have. Unless a company finds ways to discourage staff from taking bribes, you could easily see incidents like this in the future.

Source: https://www.engadget.com/hacker-pays-roblox-worker-for-user-data-access-220138846.html

World news – GB – ‘Roblox’ insider sold user data access to a hacker

Building on its expertise in the areas of digital, technologies and processes , CSS Engineering you in your most ambitious transformation projects and helps you bring out new ideas, new offers, new modes of collaboration, new ways of producing and selling.

CSS Engineering is involved in projects each customer as if it were his own. We believe a consulting company should be more than an advisor. We put ourselves in the place of our customers, to align we incentives to their goals, and collaborate to unlock the full potential their business. This establishes deep relationships and enjoyable.

Our services:

  1. Create professional websites
  2. Hosting high performance and unlimited
  3. Sale and video surveillance cameras installation
  4. Sale and Installation of security system and alarm
  5. E-Marketing

All our achievements here https://www.css-engineering.com/en/works/

LEAVE A REPLY

Please enter your comment!
Please enter your name here