Hacker Bribed Roblox Worker For Access To Users' Personal Data

The social engineering attack was carried out just to prove a point.


A hacker has been able to gain access to personal information in Roblox users' accounts, as well as disable two-factor authentication and change passwords, after bribing a Roblox worker for access to the customer support center.

Apparently only intending to point out the flaw in Roblox's security, the hacker shared screenshots and details of the attack with Vice's Motherboard. With Roblox enjoying huge popularity among children, any exploit with the potential to expose personal data is taken incredibly seriously.

Initially, the hacker paid an insider at the company to access the data for them, they claimed, but then targeted a customer support representative in order to gain access themselves. With that access gained, the hacker could view and change a user's data, including passwords and two-factor authentication.

While the hacker attempted to claim a bug bounty for this exploit, Roblox denied the request due to suspected malicious activity, including selling users' items.

In a statement sent to Motherboard, Roblox confirmed that the attack was an example of social engineering, and that it had reported the hacker to bug bounty platform HackerOne for investigation.

Roblox is a huge online gaming platform, and has become a social space for younger people during the COVID-19 crisis. The company was recently valued at $4 billion.

GameSpot may get a commission from retail offers.

The products discussed here were independently chosen by our editors. GameSpot may get a share of the revenue if you buy anything featured on our site.

Got a news tip or want to contact us directly? Email news@gamespot.com

Join the conversation
There are 4 comments about this story