Old Roblox Data Leak Resurfaces, 4000 Users’ Personal Information Exposed

A data breach affecting online gaming platform Roblox exfiltrated sensitive information from thousands of users.

Troy Hunt, founder of the website Have I Been Pwned, first announced on Twitter on July 18, 2023 about the potential leak affecting attendees of the 2017-2020 Roblox developer conference. I warned you. “We have the data and have been contacted by several people about it,” he said.

The next day, Twitter account @Roblox_RTC also report about leaks.

The exposed list was shared in CSV format and contained 4,000 unique email addresses along with personal information such as names, usernames, dates of birth, phone numbers, physical and IP addresses.

A source told Hunt that although the leak was first posted in 2021, it “didn’t spread beyond the niche cheating community within Roblox,” adding that “Roblox has publicly disclosed this leak. I never did anything or warn those affected.”

The leak was recently republished on a public hacking forum, where it received even more attention, according to the source. “Already, high-profile users have started receiving malicious calls, text messages and emails because of the leak,” the official continued.

Roblox Corporation, contacted by Hunt, said it confirmed the leak on July 20 and sent an email to all Roblox developers containing the following message:

“Roblox recently became aware of the unauthorized access to emails of some Roblox users from the invite list for the 2017-2020 Roblox Developer Conference.

We inform you that the following contact information is included in the data accessed: name, address, e-mail, telephone number, date of birth, IP.

We take great care and offer a one-year subscription to our anti-identity theft tool. Please reply to this email to get started.

Maintaining the security of your personal information is of utmost importance to us, and we will do our best to ensure that incidents of this kind are avoided in the future. “

Roblox also told Hunt that “severely affected users were given one year of privacy protection.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *