NVIDIA confirms GeForce NOW data breach affecting Armenian users
Notify affected users and review authentication logs for suspicious activity.
Notify affected users and review authentication logs for suspicious activity.
Summary
NVIDIA confirmed that a data breach exposed user information for GeForce NOW customers in Armenia, caused by a compromise of infrastructure operated by a regional partner. The incident, which occurred between March 20 and 26, involved the GFN.am partner and did not affect NVIDIA’s own network. Exposed data included full names, email addresses, usernames, dates of birth, membership status, and 2FA/TOTP status, but no passwords were compromised and users registered after March 9 were safe. A threat actor using the ShinyHunters nickname posted the stolen data on a hacker forum and offered the full database for $100,000 in Bitcoin or Monero. GFN.am also manages GeForce NOW operations in Azerbaijan, Georgia, Kazakhstan, Moldova, Ukraine, and Uzbekistan, but no impact has been confirmed in those countries. NVIDIA is working closely with the partner to investigate and resolve the issue, and impacted users will be notified by GFN.am. The incident highlights the risk of third‑party infrastructure in cloud gaming services.
Key changes
- Breach limited to Armenian partner GFN.am infrastructure
- Exposed data includes full names, emails, usernames, DOB, membership status, and 2FA/TOTP status
- No passwords were exposed and users registered after March 9 were not impacted
- Threat actor ShinyHunters offered the database for $100k in Bitcoin or Monero
- Incident occurred March 20‑26; NVIDIA’s own network was unaffected
- GFN.am also operates in Azerbaijan, Georgia, Kazakhstan, Moldova, Ukraine, and Uzbekistan but no impact confirmed
- NVIDIA is collaborating with the partner to investigate and resolve the breach