On 9 February 2021, the studio behind The Witcher and Cyberpunk 2077 announced it had been hit by ransomware — and the attackers had already auctioned its source code. The hackers’ ultimatum to CD Projekt Red read like an in-game quest terms reversal: cooperate, or your unfinished games and internal documents leak. The studio refused to pay, and the incident became the definitive case study of ransomware against a creative company.
In February 2021, ransomware actors (HelloKitty strain, with the data-theft layer claimed by multiple groups) encrypted CD Projekt Red’s networks and stole source code for Cyberpunk 2077, The Witcher 3, Gwent, and an unreleased version of The Witcher 3 with ray-tracing. The attackers left a ransom note offering an “arrangement” and threatening Source auctions; CDPR publicly refused on 10 February 2021, restored from backups, and the stolen code went to auction anyway — selling for reportedly ~$1M+ in cryptocurrency before the auction vanished. The durable lesson: for creative and IP-driven businesses, ransomware is a data-theft extortion problem first and an encryption-availability problem second; backups fix downtime, but only law enforcement and hard data-handling hygiene touch the leak.
What happened
The intrusion surfaced on 9 February 2021 when CD Projekt Red told the SEC (via a Polish press release) that it had identified compromised systems, encrypted devices, and stolen data. The attackers’ note — which CDPR itself published on Twitter — gave the studio 48 hours, offered to withhold leaked material from “your contacts in the press,” and demanded an unspecified deal for both the decryption of systems and non-release of source code and internal documents (HR, legal, accounting). The stolen set reportedly included full source for Cyberpunk 2077 and The Witcher 3 (including a next-gen ray-tracing build then in development), Gwent card-game code, and internal corporate documents.
CDPR refused to negotiate, announced it had begun restoring data from backups, and involved law enforcement. Almost immediately, the code appeared at auction: first on the Exploit malware-market forum, with a starting bid around $1M and “blitz” buyouts reportedly around $4-7M; an alleged buyer surfaced claiming to have paid, then the auction and threads evaporated. Meanwhile the “HelloKitty” ransomware brand claimed the encryption, though the data-theft side carried fingerprints of Kokomo/other affiliate behaviour, and fragments of the stolen material (documents, code snippets) surfaced on leak sites through 2021. No complete verified public dump of the games ever materialised — a standing curiosity of the case.
The studio shipped things through it: the February 2021 patch cadence for Cyberpunk 2077 continued, though the studio confirmed work-from-home disruption and a hard reset of some internal infrastructure. Financially, CDPR survived; reputationally, the episode is remembered as the moment the games industry realised game-dev pipelines — with decade-spanning codebases, outsourced studio meshes, and sprawling perforce repositories — are prime extortion targets.
How it worked
Full technical forensics were never published, but the incident’s shape aligns with the standard 2021 affiliate playbook: initial access via stolen credentials or an unpatched edge service, internal recon, data staging and exfiltration before encryption, then dual extortion — encryption plus leak threat — with auctions as the pressure mechanism.
CDPR network (Feb 2021)
access (credentials/edge - not publicly detailed)
-> recon: locate source repositories (Perforce), file shares, HR/legal docs
-> EXFILTRATE FIRST (auction inventory)
-> deploy HelloKitty ransomware -> encrypt workstations + servers
-> leave ransom note: source + docs, 48h, "press contacts" threat
|
CDPR: public refusal (Feb 10) - restore from backups
attacker:auction on Exploit forum -> bids ~$1M+ -> vanishes
fragments leak through 2021; full dump never verified
Two aspects deserve shelf-space. First, the auction mechanism itself: selling exclusive stolen IP to third parties (often competitors or re-sellers) monetises data that has no liquid market — an evolution beyond the leak-site model. Second, the target economics: game studios hold irreplaceable artefacts (source for unshipped titles) whose value decays slowly, giving attackers longer leverage timelines than typical corporate data. Both now standard considerations in entertainment-industry threat modeling.
Impact and numbers
| Metric | Value | Source |
|---|---|---|
| Public disclosure / refusal | 2021-02-09 / 2021-02-10 | CDPR press releases + tweet |
| Ransomware strain | HelloKitty (encryption); data-theft actor layered | industry analysis (Emsisoft, others) |
| Stolen IP scope | Cyberpunk 2077, The Witcher 3 (+next-gen build), Gwent source; internal documents | auction listings/CDPR statements |
| Auction figures | starting bid ~$1M; buyout reportedly $4–7M; alleged sale then disappearance | Exploit forum posts (via reporters) |
| Recovery approach | Backups; no ransom paid | CDPR statements |
| Complete public dump | Never verified | leak-site monitoring through 2021 |
Timeline
| Date | Event |
|---|---|
| 2021-02-09 | CDPR discloses ransomware; publishes attackers’ note |
| 2021-02-10 | Studio refuses demands; restoration from backups begins |
| 2021-02-11 | Stolen code auction appears on Exploit forum (~$1M start) |
| 2021-02 (late) | Auction vanishes; alleged buyer claims purchase |
| 2021 (year) | Document fragments leak; full game code never surfaces publicly |
Why it still matters in 2026
CDPR set the template answer for an extortion target with unique assets: refuse publicly, restore independently, accept the leak risk. It worked — no verified full dump ever landed — but only because the stolen material’s commercial market was thin. Modern variants of this story (game studios, media archives, AI model weights in 2024–2026) face thicker stolen-goods markets, which is why IP-intensive firms now pre-position legal takedown capacity and watermark their internal artefacts. The strategic frame is in our ransomware decade retrospective; incident-playbook mechanics live in the CISO response checklist and the first-24-hours playbook.
Detection and hardening takeaways
- Segment source-control from corporate IT. Perforce/GitLab repositories holding crown-jewel IP deserve their own identity boundary, MFA, and egress-controlled enclave.
- Assume exfil-before-encrypt. Detection windows centre on staging: unusual archive creation, bulk reads of repository storage, and off-hours data movement to cloud storage.
- Rehearse the no-ransom path. Backups, legal counsel, and comms need a pre-agreed script for the hour after refusal — CDPR’s calm execution is the model.
- Watermark and canary internal artefacts. Traceable code builds and document canaries turn any later leak into evidence and early warning.
- Plan auction response legally. Pre-agree takedown counsel and forum-monitoring relationships; speed decides whether an auction gains traction.
FAQ
Did the full Cyberpunk source code ever leak?
Not verifiably. The auction winner — if the sale was real — never published, and no complete, authenticated dump appeared on leak sites through 2021. Fragments and internal documents did circulate. The incident is a rare case of stolen crown-jewel IP effectively staying bottled.
Why did CDPR publish the ransom note?
Transparency as strategy: publishing the note signalled to employees, partners, and players that the studio would not pay, pre-empting weeks of speculation and removing the attackers’ information advantage. It also publicly framed the incident as extortion, which shaped the legal and law-enforcement response.
What is HelloKitty ransomware?
A RaaS strain first observed in 2020, named after its lock-screen theme, used by affiliates against mid-size targets; in CDPR’s case it handled encryption while the data-theft/auction side showed multi-actor fingerprints. The brand churned through 2021 via rebrands and forum takedowns — typical lifecycle for RaaS labels.
