In short
Podcast Episode Summary: Security, Bookmarked: Gaming
Podcast Title Masters in Business
Episode Title Security, Bookmarked: Gaming
Episode Overview In this episode, host Kate Fazzini discusses a critical cybersecurity incident involving a video game studio that faced a ransomware attack. The discussion features insights from Adam Marrè, CISO at Arctic Wolf, and David Adrian from Chrome, focusing on the implications for gaming companies and strategies to bolster security against cyber threats.
Key Points and Discussions
Incident Overview
- Initial Discovery: An engineer notices files moved by an unauthorized account, prompting immediate action from the IT team.
- Response Actions: The IT manager locks down accounts and requires password changes to prevent further access.
- Ransomware Threat: The presence of ransomware software was detected, indicating an ongoing threat and potential for data encryption.
Impact on the Gaming Industry
- Financial Stakes: The gaming industry generates over $300 billion annually, making it a lucrative target for cybercriminals.
- Account Takeovers: The rise in remote access by team members increases the risk of account takeovers.
- Double Extortion: Attackers not only demand ransoms but also threaten to leak stolen data, amplifying pressure on companies.
Key Cybersecurity Insights Adam Marrè's Insights
- Phishing Attack Vector: The initial breach stemmed from a phishing email, which allowed the attacker to gain super admin access.
- Multi-Factor Authentication (MFA): The absence of MFA contributed to the vulnerability, showcasing the importance of robust authentication measures.
- Preventive Measures: Companies should shift security measures to the forefront of their operations, including baking security into the game development process.
David Adrian's Insights
- Authentication Strategies: Strong, unfishable authentication methods are crucial in protecting employees and sensitive data.
- Browser Security: Properly securing web browsers, which are key for enterprise operations, can prevent phishing and unauthorized access.
- Training and Culture: Cultivating a security-aware culture among employees is essential to mitigate social engineering threats.
Broader Cybersecurity Considerations
- Vulnerabilities: Attackers often exploit account weaknesses or software vulnerabilities, underscoring the need for continuous updates and patches.
- Collaboration Challenges: Game development teams often work remotely, increasing complexity in managing sensitive information.
- Security Culture: Companies must actively train staff to recognize and resist phishing attempts.
Important Takeaways
- Proactive Security Measures: Companies should not view data breaches as a cost of doing business; instead, they should invest in security to mitigate risks.
- Resilience Against Attacks: Organizations need to prioritize identity protection and vulnerability management to safeguard against attacks.
- Implementation of Security Practices: Integrating security from the design phase of game development can significantly enhance resilience against cyber threats.
Conclusion The complexities of managing cybersecurity in the gaming industry are evident in the challenges posed by ransomware and phishing attacks. By learning from incidents and implementing effective security measures, gaming companies can better protect their intellectual property and maintain operational integrity.
Next Episode Teaser In the following episode, Kate will speak with J.F. Legault, Deputy Chief Information Security Officer at J.P. Morgan Chase, discussing strategies to raise awareness and turn the workforce into early detection sensors against cyber threats.
Note This episode is sponsored by Chrome Enterprise. For more information on privacy, listeners can visit [omnystudio.com/listener](https://omnystudio.com/listener).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:01Really, it started relatively innocently. you have an engineer who's looking at the server and looking at files on the server. This is a story about a cyber attack on a video game studio. As a software engineer was hard at work on the company's next big game, he saw one of his files had been moved by an imposter in their network. So he immediately reaches out to the head of IT, the main IT guy, and says, who is this? Who owns this account? The main IT guy was the super admin. So he knew right away that something was wrong and this wasn't a normal account. So actually what he did just shut down all the accounts, killed all sessions, locked everybody out, required a password change while he could dig into this because he immediately was pretty freaked out about what was happening.
0:44What they realized was someone had come in and made a number of accounts as super admin and had been poking around and looking at everything and even exfiltrating information. They had no idea how long this had been going on, how much data had been extracted, or what else was lurking in their network. They started digging into it and they found Locker software, so ransomware software that would encrypt. And it was on the server and it was ready to be deployed, but it hadn't been deployed. Catching the ransomware didn't mean the company was safe. They still had to investigate all of their files and their accounts, searching for any other signs of attack.
1:23And worst of all, they had to stop working on the new game. Those minutes count and those days count. So every day you can't have your employees behind keyboard are days that are going to be delayed. This is making it even worse. And this IT guy kind of becomes the hero of the story because it was a really courageous call that he made to do this, knowing what it was going to cost the company. They probably would have had to pay a huge ransom.
1:54From Bloomberg Media Studios and Chrome Enterprise, this is Security Bookmarked.
2:03I'm your host, Kate Fazzini. I've been a cybersecurity professional and journalist for more than 20 years. And on this podcast, I'm talking with leaders in gaming, finance, and manufacturing about what security looks like in a workplace that's moved to the cloud. The video game industry is a massive business, bringing in over$300 billion per year. That's nearly 10 times the size of Hollywood's global box office revenue. But as the gaming business keeps growing, more and more teams are accessing key systems and data so they can do their jobs. And that means we've seen a rise in account takeovers.
2:39So today I'm speaking with Adam Marais. I am the Chief Information Security Officer at Arctic Wolf. We are a managed detection and response company, SOC as a service, and a concierge model so that we make sure that we're not only providing them security today, but also make sure that we take them on a security journey to improve their security over time. I'm going to unpack Adam's story about helping a game studio survive a ransomware attack to understand the account security risks that all companies need to get control of. Then I'll chat with David Adrian, security product manager for Chrome, about why phishing attacks are so difficult to stop and why this doesn't have to be the case.
3:22In 2023, ransomware attacks in the gaming industry were up more than 30 % year over year, and they can freeze a game studio's entire operation, causing major delays. In this story from Adam, the game studio caught the ransomware threat early, But then they realized the attacker had also stolen their intellectual property, including details about new releases, videos, and images that they weren't ready to share with the world. We call it double extortion, where I've sealed up your code, right? And then not only am I saying pay me the ransom where you don't have access to it, I'm saying I will release this to the world unless you pay me.
3:57So I would say video game companies are likely to be targeted by these ransomware groups, mainly because video games are likely to pay the ransom if you're able to successfully lock up their code and get their backups and lock up their backups as well. And then finally, once they put out all the fires, they could figure out, how did this attacker get access in the first place? It was actually a phishing message, as it all, you know, very often is. It was a phishing message to this IT individual, to this person. The very person who had caught the intruder and pulled the alarm. And, you know, he clicked on the link and it'd take him to a webpage, then a login prompt to come up.
4:35He put in his credentials. They did not have MFA. So the attacker was able to get those credentials, then log in and quickly make other accounts and get off of that IT person's account. So they wouldn't notice social engineering works and it works really well. And it's why attackers use it so often. There are lots of other protections they could have had in place, but yeah, that was how the attackers got in. And then we're using the other accounts to worm their way through all of the servers and the whole environment. Later in the episode, I'll share my conversation with David Adrian at Chrome about how leaders can defend their companies against phishing.
5:11But first, Adam and I are going to unpack what this one breach shows about the cybersecurity risks that gaming companies face and what they can do to be more resilient to attacks. Video games is a large industry. And so there are all kinds of companies involved. And depending on the size and the type of game, you'll have very different levels of security. And that security will be leveraged at these different problems at different levels. Let me give you an example. With the rise of online gaming, so massive multiplayer online games, there is a huge incentive for these companies to prevent cheating.
5:46So you have these video game companies and they're spending millions of dollars and using the latest cutting edge technology, AI, to detect and defeat cheating on their games, on their online games. They're leveraging all of this great technology to do that. And then on their corporate side, they don't have MFA to protect their main accounts. It is understandable that they focus on the anti-cheating because that directly goes to their bottom line. Because if there's cheating, then players are going to go elsewhere. And there are other game companies that would love for that to happen. So it makes sense while they do this.
6:19But you have to understand, you could have a breach that costs you millions, tens of millions of dollars. You've said that companies shouldn't treat data breaches or ransomware attacks as part of the cost of doing business. Tell me a little bit more about that. I mean, I guess if you're a business, everything is the cost of doing business, right? Like everything is going to your bottom line. But what I mean is there are things you can do today that will greatly lower the likelihood that you will have a breach. And, you know, my whole job is to prevent breaches. So I think they're terrible. We should all leverage security against them.
6:47But it might be seen as a risk worth taking or a cost of doing business, or maybe we won't get hit with an attack. And maybe I want to spend money on making my render look that much better and the graphics look that much better. And I just don't see how security is hitting that. It's the similar thing many companies do. And then when they get breached, they really regret it. Because if you've been developing a game for three years, an attacker comes in and they're able to deny you access to all of your information, your source code, your art assets, all of that. and get your backups, you are in a world of hurt.
7:17That is a very bad position to be in. And the likelihood that you're going to pay the ransom is very high. I don't recommend that. Obviously, my stance is not to pay ransoms, but - Yeah, it's almost, I can't imagine not paying it in that, because if your whole entire company is at stake, it's the entire lifeblood of your company, the reason for its existence, basically. Exactly. It is literally your entire business. And so then you're going to want to start thinking as an organization, and you try to say, where are attackers being successful? So when you think of enterprise security for game studios, what are the most critical threats that you're watching out for?
7:49You know, there are many threat or attack reports that come out or data breach reports that come out each year. Arctic Wolf has one as well. And if you look at these, you'll see that primarily attackers are successful in doing basically one of two things. Either attacking accounts. So you can think username, password, MFA, attacking that and getting access through that or attacking vulnerabilities. So looking at the code, looking at the configuration of cloud software, SaaS software, whatever it is, and being able to exploit those vulnerabilities and get in. So if you can really look at this and say, how do I protect identities at my company?
8:23And how do I make sure that we're patching and updating and not introducing vulnerabilities and misconfigurations? If you can do those things to the right level, you're going to protect your company. And you certainly won't be the low-hanging fruit where attackers will try to attack you. What are some other ways that the companies can be resilient? it. If you want to get really technical, we can talk about shift left. In other words, you want to like create games and systems that are secure. So you want to make sure you're baking security in from the very beginning. So when you're still like whiteboarding the design of what you're trying to do in the game, add a threat model to that process.
8:54From the very beginning, thinking about how could somebody take advantage of this? How could it go wrong? And by the way, you can also add anti-cheat in there at the beginning too, and help solve that problem at the very beginning. so you're not trying to tack it on at the end. And then when you have your detection and prevention methodologies out there, they're going to be much more effective because the underlying system itself is resistant to attack and resistant to cheating. Game developers are obviously digital first. When you think about the day-to-day work and collaboration that goes on behind the scenes at the enterprise level, I'm interested in how do workers collaborate?
9:27You're in an industry where you're working with people who are specialists and extraordinarily talented, but maybe like at one thing. And that guy lives in Aspen. And then, you know, the other guy lives in the forests of Oregon. And you've got to like connect all of these teams in different areas. How do you handle collaboration across environments like that? Yeah, so it's an interesting question. In security, we've been doing this for a long time, collaborating across time zones, using various tools, different SaaS apps or other applications to collaborate and communicate. And that means a lot of very sensitive information is being passed through these suites of software.
10:04And so if you can think of one thing like the browser, so much work happens right in the browser. And many companies just don't think of the security of that particular piece of software. If we dig into that a little bit, you know, are you hardening that piece of software? Are you making sure that everyone's using the same browser so you can have the same type of security across the entire organization? Are you making sure they're not syncing personal accounts that can bring in different extensions that they're using at home that do backups or copy? And now you have information going places you weren't thinking of.
10:37So really making sure that each one of those pieces of software is secured, especially the browser, is a really important consideration, especially if we're talking about companies that are collaborating with lots of remote employees and using software to do that. There is one third aspect to this, and it's actually illustrated by the story I told, and that is you've got to have a good security culture. You've got to train your people to be wary of social engineering attacks like phishing and be resistant to those. And, you know, you can have technologies to protect against it, but there's a reason why so many attackers use social engineering is because it's very, very successful.
11:11Because it's pretty easy to trick human beings.
11:16If you're leading a gaming company, your entire product is software, and that product is constantly being accessed, tested, and updated by your teams. The same goes for your IP. Designs, assets, code, marketing trailers, showing new characters, new content, and it all lives online. So how do you keep your own accounts from being used against you? So if I'm a CISO or I'm in charge of securing an organization, the number one thing that I would be focusing on is deploying strong, unfishable authentication to all of my employees. That's David Adrian, a security product manager for Chrome. I focus mostly on network security, but I help everything up and down the stack to make sure that we're building Chrome to be as secure as possible from the application to the network to the cloud.
12:03When I brought up ransomware attacks in gaming, he picked up on account security and how important it is to plan for what happens when an employee account is compromised. Game assets or designs are, I think, the crown jewels that gaming companies are trying to protect. And so I feel for them in this situation and that they need to figure out, like, how do we make this run fast? How do we get access to everyone that needs it? But also, how do we, you know, make sure that if someone bad gets in, they don't get everything. When things go wrong, they go wrong bad. And you risk all of your game assets getting encrypted and ransomware.
12:39And in many industries, the high value accounts are sort of the administrators of the organization who might have access to create new users. In the gaming industry, there might be a broader set of targets because any developer who can build the game likely has access to all of the assets for the game. And so if they're able to get in and they get access, let's say, as anybody who has access to the underlying game assets, there might not even need to be a lot of escalation of privileges. Sure, if they get an administrator, they could create their own account. But if they get a game developer, they might just be able to walk away with all of the assets for the game by default because the developers already have access to it.
13:21And so we zeroed in on the moment when an attacker breaks into a company account through a phishing link. The most common sort of attack factor is still phishing. It's not too hard to find who's working for some company and then try and figure out what their email is. And once you know their email, you can try and start phishing them. I think I had somebody tell me once that teaching people to not get phished is like teaching them not to fall in love. It's never going to happen. I would flip it around a little bit and say that trying to solve phishing with like phishing training, fake phishing emails, that type of thing, even if it works 99.99 % of the time, the 0.01 % that it doesn't is enough for everything to go wrong, right?
14:04We've seen one phishing attempt succeed, have impacts on everything ranging from gaming companies to elections. And so, sure, you can try and get your employees to hide their emails. You can append random digits to their emails. But at the end of the day, eventually something's going to leak and someone's going to get phished. So let's talk about phishing protection. Obviously, these people are going to get spear phished. It will happen. So what are some of the protections available to them? So the good news is that we have effective solutions against phishing. I think if I were a CISO or a CIO, like the number one thing that I would be doing is deploying strong, unofficial authentication.
14:46And while that seems kind of straightforward, like let's just authenticate the people that work for me and make sure they work for me. That is probably most of the challenge for a lot of security engineering teams is making sure that that can happen. The easiest context to deploy them is web browsers for enterprise users, where you have this source of truth where you can say, hey, I know what all my employees are. I'm going to ship them all some sort of token to plug into their computers, making sure that every work application that every employee goes through has to use one of these authentication methods and does it from a managed browser.
15:20And so if you can deploy those authentication methods and you can make all logins only go through a web browser and only use those authentication methods, you've solved phishing. With Chrome Enterprise Premium, organizations can access a centralized enforcement point for all of their endpoint security and controls. This allows for endpoint visibility across the entire enterprise network. IT and security teams can deploy advanced security capabilities like advanced DLP, like context aware access controls. and then you can get in-depth reporting for all of those features. And so deploying stronger authentication, that can actually be more user-friendly when done right in the sense that it lets people act how they would naturally and not have to try to treat every email adversarially like it might be a phishing email.
16:07Because with the right authentication, they'll actually be protected by default. So if you send them a phishing link and they get tricked by it, it doesn't matter and the login won't work for the attacker. To learn more about how the most trusted enterprise browser can help protect your organization, visit ChromeEnterprise.Google. Next time on Security Bookmarked, I'll talk strategy with J.F. Legault, Deputy Chief Information Security Officer at J.P. Morgan Chase. So it's really how do you think through the awareness for people with the most common types of attacks, but also how do you turn your entire workforce into early detection sensors?
16:50Security Bookmarked is a podcast from Bloomberg Media Studios and Chrome Enterprise. Subscribe in your podcast app so you don't miss our newest episode. I'm Kate Fazzini. Thanks for listening.
17:07In Kate CJ After트를 We After The We We Are Large Pa You
17:34You Thank you.
From the publisher
When a team of video game developers notice that their files have been moved, they find themselves in a race against time to save the company from ransomware. Adam Marrè, CISO at Arctic Wolf, explains how this cyberattack traced back to a single phishing email and unpacks the ramifications for gaming companies. Then David Adrian from Chrome lays out how leaders can use unphishable authentication methods to protect their teams.
This episode is sponsored by Chrome Enterprise.
See omnystudio.com/listener for privacy information.



