CD Projekt confirms stolen source code is being circulated online

Cyberpunk 2077
(Image credit: CD Projekt)

CD Projekt Red was hacked in February, resulting in the theft of internal documents and source code for games including Gwent, The Witcher 3: Wild Hunt, and Cyberpunk 2077. The hackers threatened to release the data unless a ransom was paid, which the studio refused to do; shortly thereafter the hackers reportedly began releasing the code, which CD Projekt attempted to keep a lid on by way of DMCA takedown notices.

Despite those efforts, it was reported by databreaches.net (via Eurogamer) earlier this month that the stolen data—ranging from source code to internal "comedy bug reels"—are in the wild, and that passwords to the encrypted files had either been cracked or were being shared voluntarily. Either way, it seemed that anyone who wanted access could get it.

Today, CD Projekt issued a statement confirming that the data is in fact now being circulated online. "We are not yet able to confirm the exact contents of the data in question, though we believe it may include current/former employee and contractor details in addition to data related to our games," it said. "Furthermore, we cannot confirm whether or not the data involved may have been manipulated or tampered with following the breach."

CD Projekt is now working with law enforcement agencies including the General Police Headquarters of Poland, Interpol, and Europol, as well as other "appropriate services [and] experts" to resolve the matter. It's also implemented a number of new internal security measures to help prevent breaches like this in the future:

  • Our core IT infrastructure has been redesigned and rolled out
  • New next-generation firewalls with advanced anti-malware protection have     been implemented
  • A new remote-access solution has been employed
  • The number of privileged accounts, and access rights to accounts, has     been limited
  • A new mechanism for the protection of endpoints, servers, and networks has been installed
  • Our event-monitoring mechanisms have been improved
  • We have expanded our internal security department   

"We would also like to state that—regardless of the authenticity of the data being circulated—we will do everything in our power to protect the privacy of our employees, as well as all other involved parties," CD Projekt said. "We are committed and prepared to take action against parties sharing the data in question."

It's progress, but it's also surprising (and, honestly, disappointing) that four months after the attack, CD Projekt still can't say exactly what data was stolen, or who might be impacted by it. The timing of today's announcement, which appeared without notice in the midst of Geoff Keighley's Summer Game Fest Kickoff livestream, also raised a few eyebrowsm

I've reached out to CD Projekt for more information on what data was taken during the breach, and will update if I receive a reply.

TOPICS
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
The Witcher 4 - Ciri
CD Projekt Red boss says 'around 100' Witcher 3 designers still work at the company, while the Witcher 4's story director is 'the same person since Witcher 1'
Geralt sitting on a wall wearing a Cyberpunk jacket modded by TheRealArdCarraigh
The Witcher 3 devs had to practically remake the game engine to make official modding possible
Team Fortress Spy being shocked
An FPS studio pulled its game from Steam after it got caught linking to malware disguised as a demo, but the dev insists it was actually the victim of a labyrinthine conspiracy
Latest in Games
Steel Hunters hands-on
Steel Hunters is like a more tactical Titanfall, but as an extraction shooter it's undermined by boring loot
helldivers 2
'Never thought I'd go back' Helldivers 2 players steel themselves to return to the site of its most infamous battle, Malevelon Creek
Several adventurers in World of Warcraft Classic's hardcore server crying over the death of a fallen comrade.
Blizzard plans to revive WoW Classic Hardcore characters 'at our sole discretion', after DDOS attack puts major streamer guild OnlyFangs in the ground
Assassin's Creed Shadows change seasons - An upper-body shot of Yasuke looking cheerfully up into the distance.
Assassin's Creed Shadows is a hit and Steam played a 'significant role' in that: 27% of activations were on PC and it's the 2nd-biggest AC launch of all time
The outlast trials setting
'You just have to make them think this world is real, and this world can hurt you': The Outlast Trials devs discuss a changing horror genre and an insatiable need for scares
While Waiting
While Waiting is a game all about chugging through life's most mundane tasks with a heaping side order of whimsy
Latest in News
helldivers 2
'Never thought I'd go back' Helldivers 2 players steel themselves to return to the site of its most infamous battle, Malevelon Creek
Several adventurers in World of Warcraft Classic's hardcore server crying over the death of a fallen comrade.
Blizzard plans to revive WoW Classic Hardcore characters 'at our sole discretion', after DDOS attack puts major streamer guild OnlyFangs in the ground
Assassin's Creed Shadows change seasons - An upper-body shot of Yasuke looking cheerfully up into the distance.
Assassin's Creed Shadows is a hit and Steam played a 'significant role' in that: 27% of activations were on PC and it's the 2nd-biggest AC launch of all time
Typing on internet search toolbar: What am I doing?
How a Microsoft exec managed to pitch Microsoft Word through the genius tactic of being able to actually use it in a 'type-off' demanded by clients: 'I was the only one who'd actually been a secretary'
The outlast trials setting
'You just have to make them think this world is real, and this world can hurt you': The Outlast Trials devs discuss a changing horror genre and an insatiable need for scares
Half-Life wallpaper - Gordon Freeman
Former Valve exec says the company struggled to sell Half-Life until coming up with the ultimate 'one simple trick' of marketing manoeuvres: slapping a 'Game of the Year' sticker on the box