HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

AI Chat Bots Infiltrate League of Legends Friend Requests to Push Adult Content Links

League of Legends players are receiving AI‑generated friend requests that lead to flirty Discord chats and paid OnlyFans links. The campaign shows how AI can scale social‑engineering, highlighting gaps in user awareness and access‑control policies that SOC 2 audits must address.

LiveThreat™ Intelligence · 📅 August 08, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

AI Chat Bots Infiltrate League of Legends Friend Requests to Push Adult‑Content Links

What Happened — Players of Riot’s League of Legends have reported receiving friend requests from newly‑created or stolen accounts immediately after a match ends. The bots open a flirty conversation, move the dialogue to Discord, and ultimately share a paid‑subscription (OnlyFans) link. The script is identical across dozens of accounts, indicating an AI‑generated, large‑scale social‑engineering operation.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 A‑5 (Security) and CC 6.2 (System Operations) require documented controls against unauthorized access and social‑engineering attacks; this campaign shows a gap in user‑awareness and access‑control enforcement.
  • Continuous‑compliance programs must capture evidence of security‑awareness training and policy adherence to demonstrate due diligence during audits.
  • The incident illustrates the need for real‑time monitoring of outbound communications (e.g., friend‑request patterns) as audit‑ready evidence of control effectiveness.

Who Is Affected – Gaming platforms, esports communities, and any consumer‑facing SaaS that supports in‑app friend or chat requests (e.g., entertainment, media, and social‑gaming vendors).

Recommended Actions

  • Update security‑awareness curricula to include AI‑driven social‑engineering scenarios specific to gaming and community platforms.
  • Enforce MFA and device‑binding for all privileged or high‑visibility accounts; flag throwaway accounts with no match history.
  • Deploy automated monitoring of friend‑request spikes and outbound link sharing; retain logs as SOC 2 evidence.
  • Review and tighten outbound communication policies (e.g., disallow unsolicited external links from in‑app messages).

Source: Malwarebytes Labs

Technical Notes – The bots use AI‑generated text and image‑generation to personalize flirtation scripts, then employ prompt‑injection techniques to evade detection. No known CVE; the vector is a mis‑use of Riot’s friend‑request feature and subsequent migration to Discord. Source: same as above

📰 Original Source
https://www.malwarebytes.com/blog/ai/2026/08/ai-chat-bots-are-sliding-into-league-of-legends-friend-requests

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →