Desk live·
ForensicPost
Ransomware/Aftermath/File 23-1219

Rhysida Published 1.3 Million Insomniac Files Including Employee Passports

Rhysida demanded $2 million from Insomniac Games, was refused, and published around 1.3 million files. The reporting concentrated on leaked release plans; the same dump contained employees’ scanned passports and HR records.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetInsomniac Games
ActorRhysida
S. Rosler11 min readConfidence: high3 sources reviewed

In December 2023 the Rhysida operation compromised Insomniac Games, a Sony-owned studio, and demanded $2 million in bitcoin. The studio did not pay. Rhysida published the stolen material — reported as around 1.3 million files.

Reported contents include internal HR documents, scanned employee passports, screenshots of internal chat, non-disclosure agreements and contracts, alongside development roadmaps, budgets and details of unreleased projects. Insomniac subsequently notified affected employees.

Two Populations In One Dump

The published material contained commercially sensitive information belonging to a corporation and identity documents belonging to individual staff. The coverage was overwhelmingly about the former.

That is not a criticism of any particular outlet; unreleased game plans are legitimately newsworthy and a passport scan belonging to an animator is not. It is an observation about how this corpus’s own source material is generated. The desk builds files from reporting, and reporting follows interest, so the harm that is interesting gets recorded and the harm that is serious sometimes does not.

The Refusal Was The Company’s To Make

A studio owned by a large parent declining a $2 million demand is a defensible decision the corpus generally supports — payment buys a promise from a party whose business is breaking promises.

It is also the decision the desk records at 22-1024, 22-0903 and 23-1110: made by an organisation, paid for by individuals. The employees whose passports were published had no vote, and the sum in question was small relative to the parent company and large relative to their exposure.

Employee Data Is The Consistent Casualty

Staff records sit in the same file shares as everything else, are rarely segmented, and are almost never the reason an organisation is attacked.

We have recorded the same pattern at 23-0808, where an entire police workforce was exposed, and at 22-1104b. An employee has less choice about handing over a passport scan than any customer, no ability to take their data elsewhere, and appears in the incident record only as a footnote to the commercial story.

How we reported this

Compiled from contemporaneous reporting of the leak-site activity and of Insomniac’s notification to employees, listed below. This desk has not accessed any published material and no unreleased product detail is repeated here. No employee is named. Volume figures originate with the operation’s own listing and are carried as claims. Graded high on the sequence. Corrections: corrections@forensicpost.com.

Sources
  1. Insomniac Games alerts employees hit by ransomware data breachBleepingComputer
  2. Rhysida Ransomware Operators Hacked Insomniac Games and Demanded $2 MillionBitdefender
  3. Rhysida ransomware attack compromises Insomniac GamesSC Media
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary