Search papers, labs, and topics across Lattice.
This study investigates the prevalence and nature of cybercrime within the video gaming ecosystem, utilizing a combination of qualitative and observational methods, including an online survey, interviews with victims, and analysis of public incident reports. The research identifies digital item theft as a primary motivation for attacks, while also highlighting how game-specific features, such as item trading and tournaments, inadvertently encourage risky player interactions. Notably, the findings reveal that existing security measures often fail to provide genuine protection, exposing vulnerabilities in customer support processes that cybercriminals exploit.
Digital item theft drives a significant portion of cybercrime in gaming, revealing how game mechanics can create unintended vulnerabilities for players.
The ubiquity of the video game industry and its large user base have transformed video games into complex social and economic ecosystems. Unfortunately, this growing popularity also attracts cybercriminals who deliberately exploit game-specific mechanisms to target players. Despite this growing threat, cybercrime in the gaming ecosystem has received little systematic attention in prior research. In this work, we present an empirical study of cybercrime affecting video game players, combining qualitative and observational analyses to characterize gaming-related attacks, identify common attack vectors and motivations, and examine player responses. Our study is based on an online survey with 57 international participants, semi-structured interviews with two confirmed victims of gaming-related cybercrime, and an analysis of 2,574 publicly available posts reporting cybercrime incidents across multiple online gaming platforms. Our findings indicate that the theft of digital items is a prevalent motivation for attacks. We further observe that gaming-related features and services, such as item trading, team voting, and tournaments, create incentives for players to engage in risky interactions. In addition, our results highlight the targeted exploitation of weaknesses in customer support processes and reveal that certain security mechanisms provide only a false sense of protection.