CD Projekt confirms forum hack exposed 1.9 million user accounts

Witcher studio CD Projekt Red has confirmed a "Have I Been Pwned?" report, via IT Pro, that its forums suffered a security breach last year that led to the "exposure" of nearly 1.9 million accounts, including user names, email addresses, and salted SHA1 passwords. The breach actually occurred in March of last year,  but as it pointed out, "sometimes there can be a lengthy lead time of months or even years before the data is disclosed publicly." 

CD Projekt made news of the breach public in December, stating that its forum at cdprojektred.com "might have been accessed and copied from our server by an unauthorized party sometime in March 2016." It said at the time that there was no "concrete information" that an intrusion had taken place, but noted that any passwords that may have been downloaded would have been encrypted. It also said that the database in question was obsolete, from the days "before we migrated to the login system powered by our sister company, GOG.com." 

Further examination of the data since then has led to the conclusion that someone did in fact manage to access the database. "It is our understanding that the obsolete forum database contained usernames, email addresses and salted MD5 passwords (MD5 is an encryption algorithm we used to encrypt your data). This means your old passwords were secured and not directly accessible by anyone," the studio wrote in a follow-up posted today. "However, it is still a best practice to ask users to change their passwords. Since the event, we’ve conducted additional external security tests and we will double our efforts to ensure such situations don’t occur in the future." 

CD Projekt apologized for the breach, and said it would send out its own emails to affected users over the following days. 

TOPICS
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Latest in Game Development
princeton review best game design programs 2025
The best game design schools, ranked by the Princeton Review 2025
Sharon Tal Yguado speaking at the 2025 D.I.C.E. Summit.
'These kids do not care about romance': Game devs want to know what today's teens want, and surveys say sex and romance isn't it
Palworld early access
Palworld studio's first move as a publisher is to save a struggling indie dev: 'This is the energy I want to see driving games in 2025'
Yakuza/Like a Dragon creator Toshihiro Nagoshi says his studio's new game won't be that big after all: 'it's not modern to have similar experiences repeated over and over again'
A man with a sausage-shaped head
'Calm down!' says Facepunch Studios: Garry's Mod successor s&box is getting a fan-requested sandbox mode and an alternative to 'Sausage Men'
Hellboy Web of Wyrd
Devolver has a new label dedicated to making games based on comics, films, TV shows and 'cult heroes'
Latest in News
Assassin's Creed Shadows promo image
Ubisoft scores a legendary ratio against Elon Musk on his own platform—which hopefully marks a final end to all the Assassin's Creed Shadows' culture war nonsense
Tzarina Katarin Bokha, the Ice Queen of Kislev
Total War: Warhammer 3 rolls out a cool Kislev overhaul, changes befitting Tzeench’s magic, new projectile units and creakier skeletal horses
An image of a golden first place award from Geoguessr
'We're actually getting GeoGuessr on Steam before GTA 6': the Google Street View puzzler arrives on Valve's platform this April
Napster client circa 1999
Former music-pirating platform Napster to be reborn rather ironically as a metaverse for musicians to connect with their fans after $207 million deal
The snazzy red and black HyperX Cloud Alpha wireless headphones float in a teal void. The microphone is attached to the headset.
The best wireless gaming headset is now even better in the Amazon Big Spring Sale, boasting a more than $50 discount
A chip being held up in an Intel fab
Intel is reportedly 'working to finalize commitments from Nvidia' as a foundry partner, suggesting gaming potential for the 18A node