Desk live·
ForensicPost
Breaches/Aftermath/File 23-0124

Riot Games Refused a Ransom After League of Legends Source Code Was Stolen

Riot Games lost the source code for League of Legends, Teamfight Tactics and a legacy anti-cheat system to a social engineering attack, got a ransom email, and said so publicly: "Needless to say, we won’t pay." No user data was involved.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetRiot Games
ActorUnattributed
D. Kennedy10 min readConfidence: high3 sources reviewed

In January 2023 Riot Games disclosed a social engineering attack on its development environment. Source code for League of Legends, Teamfight Tactics and a legacy anti-cheat platform was exfiltrated, and the company said its ability to release content and ship patches was affected. It stated that no player data or personal information was compromised.

The company subsequently confirmed receiving a ransom email and said publicly that it would not pay. Reporting noted the principal risk of the anti-cheat disclosure as an increase in cheating.

Refusal Where The Company Bears It

This corpus supports non-payment consistently and keeps having to qualify the cases. At 23-0320 a manufacturer refused and the exposed data was contact details, which made the principle inexpensive. At 22-1024 and 22-0903 organisations refused and the published answer was other people’s medical records and children’s psychological assessments.

This is the case with neither problem. What was taken belonged to the company, the harm from publication falls on the company, and no third party was holding the risk of the decision. It is the only refusal in the database that is both costly to the refuser and costless to everyone else, and it is worth naming as the standard the others are measured against.

Source Code Is Leverage Of A Specific Kind

We filed stolen code at 22-0322, where an operation held Nvidia and Samsung material, and at 22-0825, where LastPass repositories described how production was protected.

Anti-cheat code is a third variety: its security depends substantially on opponents not knowing how it detects them. Publishing it does not expose a person or a credential — it degrades a system’s effectiveness permanently and gradually, in a way no notification letter or credit monitoring corresponds to.

The Development Environment, Again

The entry was social engineering into the environment where software is built rather than where it runs.

That is the same door as 22-0825, 22-1101 and 22-0412 — and at 23-0420 it was a supplier’s employee’s personal machine. Development environments hold the description of production and are consistently governed as though they hold nothing, which the corpus has now recorded often enough to treat as the rule rather than the exception.

How we reported this

Compiled from the company’s public statements and contemporaneous reporting, listed below. No ransom figure is carried — the demand amount was reported from the actor and is not adopted. No actor is named; none was authoritatively identified. Subsequent auction or resale claims circulated at the time and are not carried, having originated with parties advertising their own material. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Riot Games receives ‘ransom email’ for stolen source code following social engineering attackThe Record
  2. Riot Games says League of Legends, other games’ source code stolen in breachAxios
  3. Riot Games refuses to pay ransom to avoid League of Legends leakMalwarebytes
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary