Gaming & Gambling — Cyber Threat Activity

Gaming and gambling holds no recorded incidents in our log, and the sector's real history sits almost entirely in vendor research instead. 14 groups carry a researched association with it, including APT41, Winnti Group, Earth Berberoka, DiceyF, Stormous and LAPSUS$, with 39 malware families linked through those actors. The sector is unusual because it is where a state-sponsored group has most clearly moonlighted for personal profit. Mandiant's analysis of APT41 describes an operator conducting Chinese state espionage against healthcare, telecommunications and higher education while separately using the same non-public tooling against the video game industry for its own gain: manipulating and stealing in-game virtual currency, taking game source code, and stealing code-signing certificates that were then reused to sign malware in unrelated operations. That last step is why gaming compromises matter well beyond gaming, since a stolen legitimate certificate buys trust on every platform that checks signatures. Game studios are also a supply-chain vector in their own right, with attackers reaching production environments and injecting malicious code into legitimate game files distributed to players. Gambling operators face a different mix, holding payment instruments, identity verification documents and high-value account balances, and running customer support functions that social-engineering crews target directly. Player accounts themselves sustain a large credential-theft economy that never appears in organisational incident data. Read the zero here as a limit of our collection, and the actor associations as published research on each group rather than attributions measured in our own corpus.

All sectors

Threat actors targeting Gaming & Gambling

Malware used against Gaming & Gambling

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Where these victims are

Recent incidents

Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions