A single SMS lure was enough to open a path into Activision’s internal systems. Activision confirmed that on December 4, 2022 its information security team addressed an SMS phishing attack against an employee that led to unauthorized access to workforce systems. According to BleepingComputer, secondary reporting via vx-underground screenshots indicated attackers held an employee Slack account by December 2 and messaged other employees in further phishing attempts. Contemporaneous press described the target as HR. Activision stated that after investigation no sensitive employee data, game code, or player data was accessed. Press and researcher accounts alleged employee roster details and game-planning or marketing materials. Public reporting does not establish a quantified record count, a named threat actor, or how any second factor behaved.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into Activision in December 2022?

Attackers got into Activision through company-confirmed SMS phishing of an employee that produced unauthorized access to internal systems. According to BleepingComputer, Activision said its information security team addressed the SMS phishing attack on December 4, 2022 and quickly resolved it. Public reporting does not establish which login factors the employee used, whether MFA was enrolled, or any technique beyond the SMS phishing path itself.

Was an Activision Slack account part of the breach?

Secondary reporting says yes: screenshots cited via vx-underground in BleepingComputer’s coverage indicated attackers had access to an Activision employee Slack account by December 2, 2022 and used that chat identity to try phishing other employees. That is account access after the SMS phishing path, not a separate malware story in the public record. Public reporting does not establish a full official forensic timeline beyond the company’s SMS phishing acknowledgment and that secondary Slack picture.

What data was actually exposed in the Activision SMS phishing incident?

Impact is contested. Activision’s spokesperson told BleepingComputer that a thorough investigation determined no sensitive employee data, game code, or player data was accessed. Press accounts, including Insider Gaming as summarized in that coverage, alleged exposure of employee details such as names, emails, phones, salaries, and work locations, plus game-planning or marketing materials. BleepingComputer noted shared game info appeared based on marketing materials and that the development environment was not affected. Public reporting does not establish a quantified affected-record count or company-admitted theft of salaries or full employee PII.

Did MFA fail during the Activision employee SMS phishing attack?

Public reporting does not establish that MFA was deployed on the hit account, that a second factor was phished, or that any MFA control failed on a named mechanism. The documented initial path is an SMS phishing attack that yielded usable access to workforce systems, with Slack access described in secondary reporting. Public reporting does not establish an OTP or push failure. A fix for phishable workforce login paths exists; the prevention write-up is on the companion site.

Why did a compromised Slack identity matter after the SMS phishing attack?

Once attackers reportedly held an Activision employee Slack session, that chat identity was trusted enough to solicit other employees in further phishing attempts, per the screenshots BleepingComputer described. That is the same credential-harvest class as the original SMS lure, now launched from inside the org’s messaging plane. MFA at a later login does not undo an already-open workforce session; containment is revoke, monitoring, and stopping the next coached credential hand-off. Public reporting does not establish how many peers were successfully reached from that Slack foothold.