On February 27, 2024, video game publisher Epic Games appeared on the leak site operated by the mogilevich ransomware group. The listing claims the attackers quietly breached the company’s servers, exfiltrated internal files, and are now offering the data for sale. The 189 GB package is said to contain email, passwords, full name, payment information, source code and other material. The group set a public deadline of 3.4.24 for payment or further release.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch EpicGames
Get alerted the next time EpicGames files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about EpicGames’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The mogilevich leak site states that it carried out an attack against Epic Games’ servers and successfully exfiltrated data. It lists the compromised information as including email addresses, passwords, full names, payment details, source code, and additional unspecified files. The total volume is reported as 189 GB. The disclosure does not quantify how many individuals are affected, nor does it specify which internal systems were compromised. It notes that the data is for sale and directs interested parties, including Epic Games employees, to contact the group directly. No independent verification of the exact contents has been published by Epic Games at the time of writing.
Why This Matters for You and Your Family
If you have ever created an Epic Games account, made a purchase on the Epic Store, or played Fortnite, Unreal Tournament, or any other title published by the company, your personal information may be inside the stolen material. Passwords and payment information are particularly dangerous because many people reuse the same credentials across services. A breach at a gaming company can therefore open the door to account takeovers on email, banking, or social media. Children and teenagers who use family-shared accounts or their own profiles are equally exposed. The disclosure indicates that full names and email addresses were taken, data that can be combined with other leaks to build detailed profiles of you and your household.
The Doxxing and Identity-Chain Risk
Stolen gaming credentials rarely stay isolated. Attackers link an Epic username to an email address, then that email to a phone number or residential address found in other breaches. This creates an identity chain that can lead to doxxing, SIM-swapping, or targeted extortion. Public reporting on similar gaming breaches shows that children’s accounts are frequently weaponized because parents often link them to the same payment methods and recovery addresses. Once passwords and personal details surface on criminal forums, the risk of cascading account takeovers grows quickly. The mogilevich listing explicitly mentions that the data includes source code, which may contain internal comments, developer emails, or configuration details that further expand the attack surface for anyone whose information is inside the archive.