CD Projekt Red Ransomware: The Source-Code Auction That Failed

📋 Key Takeaways
  • What happened
  • How it worked
  • Impact and numbers
  • Timeline
  • Why it still matters in 2026
6 min read · 1,104 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

On 9 February 2021, the studio behind The Witcher and Cyberpunk 2077 announced it had been hit by ransomware — and the attackers had already auctioned its source code. The hackers’ ultimatum to CD Projekt Red read like an in-game quest terms reversal: cooperate, or your unfinished games and internal documents leak. The studio refused to pay, and the incident became the definitive case study of ransomware against a creative company.

Quick Answer
In February 2021, ransomware actors (HelloKitty strain, with the data-theft layer claimed by multiple groups) encrypted CD Projekt Red’s networks and stole source code for Cyberpunk 2077, The Witcher 3, Gwent, and an unreleased version of The Witcher 3 with ray-tracing. The attackers left a ransom note offering an “arrangement” and threatening Source auctions; CDPR publicly refused on 10 February 2021, restored from backups, and the stolen code went to auction anyway — selling for reportedly ~$1M+ in cryptocurrency before the auction vanished. The durable lesson: for creative and IP-driven businesses, ransomware is a data-theft extortion problem first and an encryption-availability problem second; backups fix downtime, but only law enforcement and hard data-handling hygiene touch the leak.

What happened

The intrusion surfaced on 9 February 2021 when CD Projekt Red told the SEC (via a Polish press release) that it had identified compromised systems, encrypted devices, and stolen data. The attackers’ note — which CDPR itself published on Twitter — gave the studio 48 hours, offered to withhold leaked material from “your contacts in the press,” and demanded an unspecified deal for both the decryption of systems and non-release of source code and internal documents (HR, legal, accounting). The stolen set reportedly included full source for Cyberpunk 2077 and The Witcher 3 (including a next-gen ray-tracing build then in development), Gwent card-game code, and internal corporate documents.

CDPR refused to negotiate, announced it had begun restoring data from backups, and involved law enforcement. Almost immediately, the code appeared at auction: first on the Exploit malware-market forum, with a starting bid around $1M and “blitz” buyouts reportedly around $4-7M; an alleged buyer surfaced claiming to have paid, then the auction and threads evaporated. Meanwhile the “HelloKitty” ransomware brand claimed the encryption, though the data-theft side carried fingerprints of Kokomo/other affiliate behaviour, and fragments of the stolen material (documents, code snippets) surfaced on leak sites through 2021. No complete verified public dump of the games ever materialised — a standing curiosity of the case.

The studio shipped things through it: the February 2021 patch cadence for Cyberpunk 2077 continued, though the studio confirmed work-from-home disruption and a hard reset of some internal infrastructure. Financially, CDPR survived; reputationally, the episode is remembered as the moment the games industry realised game-dev pipelines — with decade-spanning codebases, outsourced studio meshes, and sprawling perforce repositories — are prime extortion targets.

How it worked

Full technical forensics were never published, but the incident’s shape aligns with the standard 2021 affiliate playbook: initial access via stolen credentials or an unpatched edge service, internal recon, data staging and exfiltration before encryption, then dual extortion — encryption plus leak threat — with auctions as the pressure mechanism.

CDPR network (Feb 2021)
   access (credentials/edge - not publicly detailed)
   -> recon: locate source repositories (Perforce), file shares, HR/legal docs
   -> EXFILTRATE FIRST (auction inventory)
   -> deploy HelloKitty ransomware -> encrypt workstations + servers
   -> leave ransom note: source + docs, 48h, "press contacts" threat
        |
CDPR: public refusal (Feb 10) - restore from backups
   attacker:auction on Exploit forum -> bids ~$1M+ -> vanishes
   fragments leak through 2021; full dump never verified

Two aspects deserve shelf-space. First, the auction mechanism itself: selling exclusive stolen IP to third parties (often competitors or re-sellers) monetises data that has no liquid market — an evolution beyond the leak-site model. Second, the target economics: game studios hold irreplaceable artefacts (source for unshipped titles) whose value decays slowly, giving attackers longer leverage timelines than typical corporate data. Both now standard considerations in entertainment-industry threat modeling.

data-hmmnm-seam="2">

Impact and numbers

Metric Value Source
Public disclosure / refusal 2021-02-09 / 2021-02-10 CDPR press releases + tweet
Ransomware strain HelloKitty (encryption); data-theft actor layered industry analysis (Emsisoft, others)
Stolen IP scope Cyberpunk 2077, The Witcher 3 (+next-gen build), Gwent source; internal documents auction listings/CDPR statements
Auction figures starting bid ~$1M; buyout reportedly $4–7M; alleged sale then disappearance Exploit forum posts (via reporters)
Recovery approach Backups; no ransom paid CDPR statements
Complete public dump Never verified leak-site monitoring through 2021
data-hmmnm-seam="3">

Timeline

Date Event
2021-02-09 CDPR discloses ransomware; publishes attackers’ note
2021-02-10 Studio refuses demands; restoration from backups begins
2021-02-11 Stolen code auction appears on Exploit forum (~$1M start)
2021-02 (late) Auction vanishes; alleged buyer claims purchase
2021 (year) Document fragments leak; full game code never surfaces publicly
data-hmmnm-seam="4">

Why it still matters in 2026

CDPR set the template answer for an extortion target with unique assets: refuse publicly, restore independently, accept the leak risk. It worked — no verified full dump ever landed — but only because the stolen material’s commercial market was thin. Modern variants of this story (game studios, media archives, AI model weights in 2024–2026) face thicker stolen-goods markets, which is why IP-intensive firms now pre-position legal takedown capacity and watermark their internal artefacts. The strategic frame is in our ransomware decade retrospective; incident-playbook mechanics live in the CISO response checklist and the first-24-hours playbook.

data-hmmnm-seam="5">

Detection and hardening takeaways

  • Segment source-control from corporate IT. Perforce/GitLab repositories holding crown-jewel IP deserve their own identity boundary, MFA, and egress-controlled enclave.
  • Assume exfil-before-encrypt. Detection windows centre on staging: unusual archive creation, bulk reads of repository storage, and off-hours data movement to cloud storage.
  • Rehearse the no-ransom path. Backups, legal counsel, and comms need a pre-agreed script for the hour after refusal — CDPR’s calm execution is the model.
  • Watermark and canary internal artefacts. Traceable code builds and document canaries turn any later leak into evidence and early warning.
  • Plan auction response legally. Pre-agree takedown counsel and forum-monitoring relationships; speed decides whether an auction gains traction.

FAQ

Did the full Cyberpunk source code ever leak?

Not verifiably. The auction winner — if the sale was real — never published, and no complete, authenticated dump appeared on leak sites through 2021. Fragments and internal documents did circulate. The incident is a rare case of stolen crown-jewel IP effectively staying bottled.

Why did CDPR publish the ransom note?

Transparency as strategy: publishing the note signalled to employees, partners, and players that the studio would not pay, pre-empting weeks of speculation and removing the attackers’ information advantage. It also publicly framed the incident as extortion, which shaped the legal and law-enforcement response.

What is HelloKitty ransomware?

A RaaS strain first observed in 2020, named after its lock-screen theme, used by affiliates against mid-size targets; in CDPR’s case it handled encryption while the data-theft/auction side showed multi-actor fingerprints. The brand churned through 2021 via rebrands and forum takedowns — typical lifecycle for RaaS labels.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.