Case file · EA 2021

How the EA hack happened: a $10 stolen cookie and a lost-phone story

Published 2026-09-29 · 5 min read · Missing control: Verify identity before issuing MFA tokens

The break-in at Electronic Arts reportedly started with a $10 purchase: a stolen login cookie that let intruders into the company's internal Slack chat.[1][2] This case file covers how a friendly message to IT support turned that foothold into about 780 gigabytes of game source code, how the extortion attempt played out, and the one control that would have stopped it at the help desk.

What happened

On June 10, 2021, hackers began advertising what they said was a haul of data taken from Electronic Arts, the maker of FIFA, Madden and Battlefield. They claimed about 780 gigabytes, including source code for FIFA 21 and its matchmaking servers and code and tools for Frostbite, the engine that runs many EA games, and they priced it at $28 million.[3][5] Security researchers said pieces of the code had first been offered for sale in early May.[4]

EA confirmed the intrusion. The company said no player data was accessed, that it had no reason to believe player privacy was at risk, and that it had already made security improvements and was working with law enforcement.[2][5]

The hackers then explained to reporters how they had done it. They said they bought a stolen cookie for $10, used it to get into an EA Slack workspace, and then persuaded IT support to give them a way past the company's multifactor login.[1][2][4]

Buyers were scarce. Other criminal groups showed little interest in game source code, so the group tried to extort EA directly. When EA did not pay, the hackers released a first 1.3 gigabyte sample of FIFA 21 code on July 14, 2021, and posted the full archive on an underground forum on July 26.[5]

How they got in

A cookie is a small file your browser keeps so a website remembers you are already logged in. If someone copies it off an infected computer, they can sometimes use it to appear as that person without knowing the password. Stolen cookies are traded in bulk on criminal marketplaces, and the hackers said the one they bought opened a Slack workspace used by EA staff.[1][5]

Slack access alone did not reach EA's code servers. For that, the network required a second login factor, the kind of one-time code or token normally tied to an employee's phone. So the intruders, posing as an employee, messaged IT support and said they had lost their phone at a party. Support issued a multifactor token. By the hackers' account it worked twice, and the tokens let them onto EA's corporate network and to the systems that held source code.[1][2][3]

Note what was not needed: no clever break-in of EA's servers. A believable story in a trusted chat channel did the heavy lifting, and a help desk trying to be helpful did the rest.

What it cost

EA said the incident would not affect its games or its business, and no customer records were taken.[2] The damage was to its intellectual property. Source code for a best-selling game and its engine was dumped publicly, which security writers warned could help people build cheats or probe EA's games and servers for weaknesses.[3][5]

The hackers failed to get the $28 million they asked for, and EA did not pay the later extortion demand.[5] No arrests have been publicly reported in the sources reviewed for this case file, and the people behind it have not been named by authorities.

The missing control

The missing control: verifying identity before resetting or issuing multifactor credentials. The help desk accepted a lost-phone story from a chat account and handed over a new second factor, without confirming the requester through a separate, trusted channel.

Multifactor login exists to stop exactly this kind of intruder, who has one piece of an employee's identity but not the rest. A reset process that trusts the chat message defeats the whole point. If support had called the employee back on a phone number already on file, checked with their manager, or required a live video check with ID before issuing a token, the story would likely have fallen apart. Security experts commenting on the case recommended the same thing: confirm the request through a second communication channel before granting access.[4]

What to do in your business

Watch the case
How a Ten-Dollar Purchase Cracked Open EADrops 2026-11-10
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Game World Observer: Hackers only needed $10 and cookies to hack Electronic Arts and steal 780 GB of data
  2. SlashGear: The EA hack was worryingly simple
  3. GameSpot: Hackers obtain 700GB of EA's data and source code using stolen cookies
  4. CyberScoop: Hackers used Slack to break into EA Games
  5. The Record: Hackers leak full EA data after failed extortion attempt