LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › EpicGames Listed by mogilevich Ransomware Group

HIGH severityUnverified claimHow we verify

EpicGames Listed by mogilevich Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 27, 2024
EpicGames Listed by mogilevich Ransomware Group

Reported February 27, 2024.

HIGH
Severity
February 27, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The EpicGames Listed by mogilevich Ransomware Group (reported February 27, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Account credentials exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For players, developers, and employees connected to Epic Games, a ransomware group's claim that it has taken internal files raises immediate practical questions about personal accounts, payment details, and workplace credentials. When a listing appears on a leak site, the people whose information may be involved face the ordinary but serious tasks of checking for unusual activity, updating passwords, and watching for fraud — even while the full scope remains unconfirmed.

On 27 February 2024, the ransomware group known as mogilevich listed Epic Games on its leak site, asserting that it had quietly attacked the company's servers and removed a large volume of internal data. The number of people affected is unknown, and independent verification of the claim has not been publicly established. What follows is a careful account of what has been stated, what is known about the actors involved, and what steps make sense for anyone who may be exposed.

Breaking down the breach

According to the listing published by mogilevich, the group carried out an attack against Epic Games' servers and exfiltrated internal files. The group described the victim as a video game publisher and software developer and claimed the stolen material totalled 189 GB. It further stated that the data included email addresses, passwords, full names, payment information, source code, and "many other data," and that the material was also offered for sale. A deadline of 3.4.24 was posted, after which the group implied further action if its demands were not met.

Public reporting of the incident rests on this leak-site entry dated 27 February 2024. No confirmed count of affected individuals has been released, and details of the intrusion method, the precise systems accessed, or any ransom negotiation remain undisclosed. The listing itself constitutes a claim by the group rather than an independently verified disclosure by Epic Games. Until more information is confirmed, the scale and exact contents of any compromise cannot be treated as established fact.

The group behind it: mogilevich

Mogilevich is a ransomware operation that follows a now-familiar double-extortion model: after gaining access to a network, the group encrypts systems or simply steals data and then threatens to publish or sell the material unless payment is made. Like other ransomware crews, it maintains a leak site where it names victims, posts sample files or volume claims, and sets public deadlines. The name itself references a well-known organised-crime figure, a branding choice common among certain Russian-speaking ransomware groups that seek notoriety alongside profit.

Publicly documented activity by the group has typically involved claims of large data volumes, offers to sell the material to third parties, and pressure tactics aimed at both the victim organisation and potential buyers. In this case the group claims it quietly attacked Epic Games' servers and is offering 189 GB of data for sale. No additional statements from the group about this specific incident beyond the leak-site listing have been provided in the available record, so further assertions about motives or methods for this victim would be speculative.

Who is EpicGames?

Epic Games is a major video-game publisher and software developer best known for titles such as Fortnite and for the Unreal Engine used across the industry. The company operates large online platforms that serve millions of players, maintain user accounts, process payments, and host development tools and source code. Organisations of this type routinely hold email addresses, account credentials, payment card or billing information, personal names, and proprietary technical assets.

A breach claim against such a company is consequential because the same systems that support entertainment and commerce also store identity and financial data. Even when the precise impact is unconfirmed, the combination of consumer accounts and internal development material makes the organisation an attractive target for ransomware groups seeking both leverage and resale value.

What data was at risk

The available facts state that internal files were exfiltrated in a ransomware attack. The group's own listing claims the compromised material included email addresses, passwords, full names, payment information, source code, and additional unspecified data, with a total size of 189 GB. These categories are presented as the group's assertion; they have not been independently confirmed in the public record.

Companies in the video-game and software sector typically maintain user-account databases, payment-processing records, employee directories, and proprietary source repositories. Whether any of those specific stores were accessed in this incident remains unconfirmed. Readers should therefore treat the listed data types as claimed rather than verified, while recognising that the kinds of information held by Epic Games could, if exposed, include both personal identifiers and commercially sensitive material.

The real-world impact

For individuals, the practical risks centre on account takeover, credential stuffing, and financial fraud. If email addresses and passwords were among the material taken, attackers could attempt to reuse those credentials on other services. Payment information, if present, raises the possibility of unauthorised charges or identity-based scams. Employees whose workplace credentials or personal details appear in any dump face similar exposure plus potential phishing that exploits knowledge of internal systems.

For the organisation, the claim of source-code theft introduces competitive and security concerns, while any confirmed loss of customer data can trigger regulatory notification duties, support costs, and reputational damage. Because the number of people affected is unknown and the claim remains unverified, the actual impact may range from limited to substantial; the prudent course is to assume that personal and financial data could be at risk until clearer information emerges.

If your data was in this claimed breach

Begin by changing passwords on any Epic Games account and on other services where you reused the same credentials; enable multi-factor authentication wherever it is offered. Monitor bank and card statements for unexpected charges and consider placing a fraud alert with credit bureaus if payment details may have been involved. Be sceptical of unsolicited messages that reference Epic Games or claim to offer "breach assistance," as scammers often exploit public listings.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Doing so provides a concrete starting point for deciding which additional accounts need attention, while recognising that not every claimed incident immediately surfaces in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEpicGames security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See EpicGames’s full breach history →

More recent breaches

BAZAARVOICE.COM Listed by mogilevich Ransomware GroupFebruary 26, 2024Kick Listed by mogilevich Ransomware GroupMarch 1, 2024DJI Company Listed by mogilevich Ransomware GroupMarch 1, 2024INFINITIUSA.COM Listed by mogilevich Ransomware GroupFebruary 20, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the EpicGames Listed by mogilevich Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by mogilevich — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram