Star Citizen developer discloses January breach that exposed user account details

by

In a website notice by Cloud Imperium Games, the company said attackers gained limited access to backup systems on January 21 2026 and accessed basic account information for an undisclosed number of users.

KEY FACTS

  • Incident Attackers accessed backup systems
  • Date January 21 2026
  • Data impacted Basic account details including name and date of birth
  • Credentials No passwords or payment data in affected systems

Discovery occurred on January 21 2026. The intrusion was a systematic and sophisticated attack that resulted in unauthorised read only access to some backup systems. No data injection or modification took place.

Impacted data includes basic account details such as metadata, contact details, username, date of birth and name. The disclosure did not provide a number of affected accounts.

The affected systems did not store payment information or credentials. No passwords were impacted and no financial or payment information was accessible from the compromised systems.

The company is monitoring systems and taking steps to detect whether any accessed data is released publicly. There are no indications so far that the accessed data has been leaked online.

WHY IT MATTERS

Exposed personal details can be used for phishing and social engineering attacks. The undisclosed number of affected accounts increases uncertainty for users and investigators.