Hackers breach Roblox security to access user information

(Image credit: Roblox)

Popular online game Roblox has suffered a security breach after a hacker bribed a company employee to gain access to the company's back end customer support panel.

This allowed them to lookup other users' personal information and give out virtual in-game currency, with the hacker able to see other users' email addresses, change their passwords, remove two-factor authentication from their accounts, ban users and more. The hacker shared screenshots with the news outlet which included the personal information of some of Roblox's most high profile users including YouTuber Linkmon99.

While the hacker could have looked up information on many users, they only accessed a handful of accounts. In an online chat with Motherboard, the hacker said that “I did this only to prove a point to them”.

Gaining access to other user's online accounts and in-game items through social engineering and bribery is bad enough but the fact that many of Roblox's users are children complicates things even further.

Roblox hack

In addition to viewing user data, the hacker was also able to reset passwords and change other user data as well based on the screenshots of the customer support panel shared with Motherboard. According to the hacker, they changed the password for two accounts and sold their items. 

The hacker first began their infiltration of Roblox's platform by paying an insider to perform data lookups for them. However, this progressed a step further when the hacker targeted a customer support representative for even greater access to the company's systems.

The hacker even went as far as to try and claim a bug bounty from Roblox which was denied as they didn't actually find a vulnerability but instead used social engineering and bribery to access its systems.

Following the hack, Roblox addressed the issue and individually notified the small number of users who were affected. The company also reported the hacker's actions to the bug bounty platform HackerOne as an additional measure.

Via Motherboard

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)