DDoS, data theft, and malware are storming the gaming industry

Video games may seem of small importance to the business world at large, but the industry is growing and it can have an outsize effect on business affairs, particularly when it comes to security. The global games market is expected to reach $188.8 billion in 2025, a 3.4% rise from the previous year. Because gaming involves a lot of valuable assets, security is a factor there, and that is where businesses need to pay attention: due to the prevalence of password reuse, security incidents in the gaming sector could lead to information obtained from those incidents being reused to attack other businesses. Additionally, gaming accounts are generally full of valuable financial data. Threat actors have taken notice, which has led to a growing prevalence of cyberattacks against major gaming industry leaders.

It is common for malware to be spread to video game users through freely distributed illegal cheat programs, which lack the same security protections most online gaming sites tend to employ. However, those sites are not invulnerable. There have been multiple occasions this year when a game was successfully uploaded to the Steam gaming web store platform which was later discovered to be spreading malware to its users. In one recent case, a game demo for a game advertised as “Sniper: Phantom’s Resolution” infected users who downloaded it with infostealing malware. This demo and others like it are usually removed after discovery, but the fact that they were able to bypass Steam’s protections is concerning.

Apart from financially motivated activity, DDoS attacks against the gaming industry have become increasingly prevalent due to their outside news media impact. Gaming was the most targeted industry for HTTP DDoS attacks in 2024, with Layer 7 incidents rising 94 percent year over year. Recent DDoS attacks targeted widespread gaming industry networks, including Steam, Epic Games, and the PlayStation Network. These attacks are now attributed to the Aisuru botnet, and some researchers suggest that the large-scale disruption may have acted as a “demonstration of power” to advertise the botnet to potential customers.

Security is often the lowest priority in the game development process, and it’s hard to see how that can be improved. Security teams deal with constant code changes, fast release cycles, and a steady flow of new vulnerabilities. Traditional vulnerability management struggles to keep up. Manual reviews, disconnected tools, and limited visibility across teams slow response times and increase exposure. To stay secure, studios need security practices that fit into each stage of development and release.

Share

Related Posts

shubham-dhage-2nnRCNuHdVs-unsplash
8machine-_-pzcfw9AV5HY-unsplash
bw-blog_un-1682146029185-198922bd8350

Copyright © All Right Reserved

Privacy Policy