HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Hackers Steal Over 610,000 Roblox Accounts, Monetize Elite Profiles

A Ukrainian‑linked hacking group exfiltrated credentials from more than 610 k Roblox accounts, including 357 elite accounts, and earned $225 k by selling access. The operation used infostealing malware disguised as game‑enhancement tools, highlighting third‑party software risk for youth‑focused platforms.

LiveThreat™ Intelligence · 📅 May 01, 2026· 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

Hackers Steal Over 610,000 Roblox Accounts, Monetize Elite Profiles

What Happened – Between October 2025 and January 2026 a criminal group compromised more than 610 k Roblox accounts, including 357 high‑value “elite” accounts, and generated roughly $225 k by selling access. The attackers distributed infostealing malware masquerading as game‑enhancement tools to harvest login credentials.

Why It Matters for TPRM

  • Credential theft on a popular youth‑focused platform demonstrates the risk of third‑party software bundled with games.
  • Sale of compromised accounts creates a downstream threat to any services that accept Roblox credentials for authentication or payment.
  • Large‑scale account theft can damage brand reputation and trigger regulatory scrutiny over data protection for minors.

Who Is Affected – Gaming & interactive entertainment platforms, especially those serving children and teens; any downstream services that integrate Roblox login or payment APIs.

Recommended Actions

  • Audit all third‑party tools and extensions distributed to users for malicious code.
  • Enforce mandatory MFA for all privileged Roblox‑related accounts and encourage it for end‑users.
  • Implement credential‑leak monitoring and block known compromised passwords.
  • Update incident‑response playbooks to include rapid account‑recovery workflows for high‑value user assets.

Technical Notes – Attack vector: malware disguised as game‑enhancement utilities (infostealer). No specific CVE cited. Stolen data: usernames, passwords, session cookies, and payment‑related metadata. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/04/hackers-stole-hundreds-of-thousands-of-roblox-accounts-heres-what-to-do

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.