Bandai Namco confirms ransomware hack of internal servers

Little Nightmares art
(Image credit: Bandai Namco)

Yesterday it was reported, though unconfirmed at the time, that Japanese videogame giant Bandai Namco had been the victim of a ransomware attack. The corporate playbook in these circumstances is to keep quiet until the damage has been assessed: unless, that is, customer data has been affected, in which case it's a whole other ballgame.

Such seems to be the case here. Bandai Namco has now issued an official statement acknowledging the breach, which is titled 'Regarding Unauthorized Access to Bandai Namco Group Companies in Asian Regions (Excluding Japan)' and reads:

"On July 3, 2022, Bandai Namco Holdings Inc. confirmed that it experienced an unauthorized access by third party to the internal systems of several Group companies in Asian regions (excluding Japan). After we confirmed the unauthorized access, we have taken measures such as blocking access to the servers to prevent the damage from spreading.

"In addition, there is a possibility that customer information related to the Toys and Hobby Business in Asian regions (excluding Japan) was included in the servers and PCs, and we are currently identifying the status about existence of leakage, scope of the damage, and investigating the cause."

Bandai Namco goes on to say it will disclose the results of its investigation "as appropriate" and work on strengthening its security. It ends by offering "our sincerest apologies to everyone involved for any complications or concerns caused by this incident."

The news was broken by the malware-watching bunch vx-underground. The group that targeted Bandai Namco is known as ALPHV, and has been linked rightly or wrongly with earlier ransomware such as Noberus. The BlackCat moniker comes from an image of a black cat on the group's blog.

I asked a representative of vx-underground to explain just what ALPHV is, and the tactics they use: such as releasing confidential information in public.

"ALPHV is a double extortion group," the rep writes. "They lock the machines to disrupt operations and also exfiltrate data—the goal is to apply pressure to force [the victim] to pay. So, regardless if they can resume operations they do not want company secrets exposed.

"Embarrassment is only a small piece of the puzzle. Sure, it is bad publicity to see a Russian cyber cartel openly disclose a breach—but knowing [that it can also leak] sensitive financial data (or proprietary data) is far worse."

ALPHV is also a seriously active and going concern. PC Gamer is covering this because Bandai Namco is an enormous games publisher, but plenty of the group's targets never make the headlines. "Some mainstream media outlets cover ransomware activity," writes the vx-underground rep. "I know CNN, MSNBC, and others do for their 'cyber crime' and tech sections. However, they usually look for things geopolitical focused, 'cyber war', or sometimes things like scamming home users or something... Many people in the world [would] not be as focused on Bandai Namco... That is not their demographic."

ALPHV is bad news for its victims. It has previously boasted of wanting to create a "ransomware metaverse" to The Record, and is sold on underground markets (per Hacker News) as "the next generation of ransomware." The latest tactic is publishing victims' information to the clear web, so that it gets indexed by search engines, and threatening more unless multi-million payments are made.

I asked how active the hacker ALPHV group is outside of incidents like this that make headlines.

"From the best of my knowledge ALPHV has approx 25 hackers as 'employees' and is constantly breaching companies. They are ALWAYS ransoming... So... Ya lol."

Rich Stanton
Senior Editor

Rich is a games journalist with 15 years' experience, beginning his career on Edge magazine before working for a wide range of outlets, including Ars Technica, Eurogamer, GamesRadar+, Gamespot, the Guardian, IGN, the New Statesman, Polygon, and Vice. He was the editor of Kotaku UK, the UK arm of Kotaku, for three years before joining PC Gamer. He is the author of a Brief History of Video Games, a full history of the medium, which the Midwest Book Review described as "[a] must-read for serious minded game historians and curious video game connoisseurs alike."

Read more
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Team Fortress Spy being shocked
An FPS studio pulled its game from Steam after it got caught linking to malware disguised as a demo, but the dev insists it was actually the victim of a labyrinthine conspiracy
Nvidia RTX 4090 Founders Edition graphics card
A single RTX 4090 managed to brute force crack an Akira ransomware attack in just 7 days
A computer screen with program code warning of a detected malware script program. 3d illustration
Second Steam listing this year found hiding 'new and clever' malware. This time through a fake demo link on developer's website
Latest in Gaming Industry
Typing on internet search toolbar: What am I doing?
How a Microsoft exec managed to pitch Microsoft Word through the genius tactic of being able to actually use it in a 'type-off' demanded by clients: 'I was the only one who'd actually been a secretary'
Half-Life wallpaper - Gordon Freeman
Former Valve exec says the company struggled to sell Half-Life until coming up with the ultimate 'one simple trick' of marketing manoeuvres: slapping a 'Game of the Year' sticker on the box
Gabe Newell looks into the camera, behind him is a prop of a turret from Team Fortress 2.
Gabe Newell's cult of personality is intense, but a Valve exec who worked with him says his superpower is how he 'delighted in people on the team just being really good at what they did'
The Spy from Team Fortress 2 holds up a folder with an accusatory expression.
One of Valve's original executives shares a very simple secret to its success: 'You can't use up your credibility' by trying to make bad games work
Gabe Newell in a Valve promotional video, on a yacht.
Gabe Newell had his eyes on a social network in the '90s that 'was not in a games context at all'—meaning Valve-owned social media could've been a very real thing
Shadow of Mordor's beloved nemesis system exists because the publisher threw a tantrum about second-hand sales
Latest in News
Ciri in The Witcher 4
The Witcher 4 won't be out until sometime in 2027 at the soonest, CD Projekt says
Dwarf Fortress adventure mode art
After 23 years of making Dwarf Fortress, even its creator is still 'terrified' of drowning all his dwarves with aquifers: 'Part of the problem is we are just not good at videogames'
A unique aspect of Japanese architecture turned out to be a key reason the Like a Dragon games can reuse assets so effectively—and deliver more compact, memorable open worlds than western cities
Pacific Drive Endless Expeditions spring 2025 update trailer still - a sexy, tricked-out 1980s station wagon being blasted with magic healing electricity
Pacific Drive developers change their mind: A year after refusing to give it mid-run saves, it's getting mid-run saves
Starfield's companion robot giving a thumbs-up
Former Bethesda dev who quit Starfield to go solo says it's 'much less stressful as an indie' without daily meetings or 'office politics': it's 'very refreshing to just care about the game'
Schedule I drug deal going down
Forget REPO, Monster Hunter Wilds and Assassin's Creed Shadows, Steam's current global top seller is an early access game about managing a drug empire