r/gachagaming • u/WolfOphi FGO | BA | AL | AK | HBR | SB • Sep 01 '25
(Global) News Nexon's full statement about Blue Archive hack, how it happened and where it comes from
Nexon just released a statement about yesterday's hack
https://forum.nexon.com/bluearchive-en/board_view?board=3028&thread=3123126
in addition to the 840 for yesterday's update they will also provide more compensation rewards
545
u/zzkigzz48 Sep 01 '25
So the hacker only did it for the fun of the game?
Holy based.
209
u/Dabage Uma Musume, Azur Lane Sep 01 '25
Nexon is lucky that the hackers did something that was largely harmless since this seemed like a massive vulnerability. 9/10 times if it was done by other hackers they would have done much more damage to the game.
82
u/TamakiOverdose Sep 01 '25
It depends, some do and alert companies to strength their systems because they're consumers themselves. Usually the ones that cause harm are teens who learned how to hack and want money or to make people mad for fun.
12
u/No_Foundation_6129 Sep 02 '25
As long as the databases and backups are not compromised,
meaning player emails / information isn't leaked and sold,
Devs should be fine.
Unless they saved all their source code in a single location :(
Imagine having to redevelop the entire game from scratch 😳
Player progress and entire accounts may be lost if the data is taken / deleted.
Lawsuits too if player information is sold online.
But yeah, if the hacker could edit the CDN endpoint destination, he/she could have more access than it seems.
Good thing it's a friendly white hat.
30
u/FrengeReddit Sep 02 '25 edited Sep 02 '25
Grey hat*. A white hat would have just reported the vulnerability to the company directly instead of giving them a panic attack by meming. >_>
Unless they already tried to report it and got no response, that happens sometimes lol.
2
u/Asgard033 Sep 03 '25
Unless they already tried to report it and got no response, that happens sometimes lol
Reminds me of McDonalds lol
11
u/Antares428 Sep 01 '25
Yeah if it was something more nefarious, they'd be so much shit. Imagine if they completely cleared everyone's account. These companies take snapshots of accounts usually before each major update, so at worst, a few weeks worth of progress would be gone, and tens of thousands of transactions would need to be redone.
23
u/ByeGuysSry Sep 01 '25
The post mentions that players' accounts and game data were untouched during the hack (as that would be a different hack altogether)
5
273
Sep 01 '25
20
u/Old-Helicopter1689 Replaying NIKKE rn - OHHH YEAAAH!!! Sep 02 '25
We got 'er, boys. Time for some PUNISHMENT!
2
94
u/Utvic99 Sep 01 '25
Yuuka lost a lot of hair after this incident, legends say that Koyuki is now locked up in the maximum security Seminar prison in a cell surrounded by top class Millennium drones and cameras in the room
Together with Noa, who's punishing her as we speak.
22
u/a__new_name Trickcal, Zenless, WuWa Sep 02 '25
An actual fan art of that process exists on other websites.
62
u/querynope GI | HSR | ZZZ | UMPD Sep 01 '25
So it was indeed a whitehat hacker. Nexon got lucky.
Also surprised -but grateful- for the very detailed explanation
107
u/six_artillery Sep 01 '25
So it was a grey hat hacker
Hacker clearly plays the game (specifically used Koyuki which is in-character and linked to a Koyuki roleplay yt account)
Specifically picked Aug 31 which is Hatsune Miku's birthday and apparently the BA producer's birthday. Miku also propagated the cafe
Got a bunch of memes and fan art
Players got free pyros for doing nothing
Nexon/Yostar benefit for basically being forced to close an unforeseen vulnerability
261
u/WolfOphi FGO | BA | AL | AK | HBR | SB Sep 01 '25
I'm surprised they gave a full detail of how it happened.
Knowing Nexon's reputation, I would have thought they would have just said "sorry, we're going to increase our security, here are rewards." but they gave more information
119
u/AyyDisFaker Sep 01 '25
For this game they really go all out regarding explanations on things like this. It's sometimes to the point where you'd think they are over explaining something.
84
u/Utvic99 Sep 01 '25
Tbf the sudden massive maintenance coupled with the fact that a lot of players witnessed the Koyuki incident firsthand. I have a feeling they were pretty much forced to make such a statement, whether they wanted to or not
26
u/Caekie Sep 01 '25
The last 5 years or so of Nexon have been very different from the Nexon we all knew if from the mmorpg era. They are quite different atleast in the na/global division
19
u/HibikiAss Forever Utamacross fan Sep 02 '25
Nah, nexon global for maplestory still the same. We still clown them for 3 community manager that can't make anything clear
15
1
u/Creocist Sep 02 '25
I think Nexon just saw how Blue Archive fans took down a government organization and made a mental note to never upset or disappoint them.
Cause just recently they've been doing shit like stealing other influencers' faces with AI to advertise their game. If something like this happened to BA, the players might straight up kill them.
15
u/Croaker_392 Sep 01 '25
I'm guessing Google and Apple wouldn't be satisfied by a basic "we're sorry" message and they had to make a very detailed report (much more than what we got).
6
u/PokeHustler3 Sep 01 '25
it is importance to be transparent in this situation for trust factor. this is like a bank informing you that your saving acct isnt affected from the vulnerabilities.
2
u/reprehensible523 Sep 02 '25
Transparency here is a good thing. "Servers got hacked" undermines trust in the company's payment processing. Did your CC info get leaked? If you replace your credit card, should you spend money on their game again?
Clear communication rebuilds trust.
0
u/redevmods Sep 02 '25
They didn’t actually give a full explanation though, they left out one of the most important parts. The cafe student data is not stored in the CDN, but instead is stored with all the other user data, and they have provided no explanation to how that was changed besides the fact that no game databases were affected (according to them).
247
u/NekohimeOnline Sep 01 '25
Lol so hacker, I didnt get into the specifics but, the hacker clowned around, displayed some memes of their favorite character, and then did nothing else? And everyone got rewards for it? That sounds kinda... fine? Am i missing something?
359
u/LeMeMeSxDLmaop Sep 01 '25
yea u r missing the fact that this breach in security couldve easily been horrendous if the hacker wasnt based as fuck
so obviously they would release some form of communication abt it, tho a statement of this degree is certainly unexpected but also very welcome
51
u/Utvic99 Sep 01 '25
I feel like these hackers also help Nexon patch game exploits before actual damage could be done. I am grateful for the hacker not being a pos either way 🙏
27
u/nonresponsive Sep 01 '25
I mean, there's also the fact that companies are smarter about storing/securing their data or at least should be. Just because a company gets hacked, doesn't mean they can access important information.
It's possible this was always the hacker's goal, but also maybe it was the only thing they could do.
44
u/EH042 Sep 01 '25 edited Sep 01 '25
I would honestly love to have more hackers like this, the possibilities are endless, think about it:
Nikke gets hacked and all characters are replaced for Doro versions of themselves.
Brown Dust 2? Syke! Now it’s Yuridoro 2!
Dissidia Final Fantasy: Opera Omnia? Bam! The game is back on air! Now with Rikku added to everyone’s accounts and a Genesis banner up!
8
u/Ronnie21093 Sep 01 '25
Honestly, it makes me wonder if the person who did it found this exploit and decided to inform Nexon about it through a public and harmless display.
4
u/Nacon-Biblets Sep 02 '25
How could it have been horrendous? They say right there in the post that accounts, game data, and payments are stored on a seperate database.
3
u/Abyssal_Specter Sep 04 '25
Imagine that instead of creating Koyukis and such, they distribute CP throughout the game, or some disturbing gore scenes. that certainly doesnt touch any of the game data, but what do you think it would do to the game?
2
u/redevmods Sep 02 '25
They said they the databases weren’t affected, not that they couldn’t have been. If the hacker was actually malicious, they most likely would be able to gain access to and steal from some of, if not all of them.
3
u/rainzer Sep 02 '25
could be that the hacker told them about the vulnerability and they didn't do anything about it
18
u/yukiaddiction Granblue Fantasy Sep 01 '25
It's not really fine.
This hacker is most likely "Script Kiddies" level which is equal to "beginners" if we use video games ranked.
This is actually a huge issue if these kinds of hackers already can access that level of server? Who knows what else can happen if the game gets an eye on by more malice professional hackers.
This is actually pretty huge if you care about Cyber Security or working in a profession related to it.
17
u/Funlife2003 Sep 01 '25
This, exactly. As someone who's focusing on that field for their career, this seems like a really bad case in terms of what it means for the strength of their system.
2
u/cidrei Sep 02 '25 edited Sep 02 '25
If my understanding is correct, its more akin to a site that keeps all their accounts in-house, but has all their images stored third-party. Someone can hack the third-party and change all the pictures, but the accounts themselves were never at risk. If I'm understanding correctly.
In either case, it's bad. Maybe just not catastrophically so. EDIT: I agree it does represent a poor level of network security, so hopefully that was limited to just the CDN.
0
u/Human_Ad_2025 I need Suna maid skin 😭 Sep 01 '25
I see this a lot in this case. Like they need to thank the hacker, he had all the tools to nuking the server and make modifications to the we don't know many accounts at his disposal. Nexon needs to tighten his security and make real changes to his cyber security department. An "innocent" joke to the community could probably be a warning to the future.
14
u/Druplesnubb Sep 01 '25 edited Sep 01 '25
Doesn't Nexon's statement say that all of the account information is stored in a separate database? Do you think they are lying?
-3
u/yukiaddiction Granblue Fantasy Sep 02 '25
It's not Just about information though.
Hackers can easily install either backdoor or virus into files to cause player damage.
6
u/sirbucelotte Sep 01 '25
This is most probably an user who found the exploit and tried to contact them about it without success, them used the exploit to warn them about it in a more direct way, and It worked flawlessly, they even stated that theyre gonna start a bug bounty in the future to help it with tighten security.
1
19
u/FemmEllie Sep 01 '25
Well it's a good thing that the person who did this was seemingly just a memer and not malicious, but nevertheless the fact that someone was able to do this is a bad look for their security. We're very lucky it wasn't someone with more sinister motives that did this, but this is already a bad proof of concept for the future that it is doable.
48
u/Irru HSR | Uma | PTN | Trickcal Sep 01 '25
Redirected to Netherlands where the game isn’t even on the app stores is kimda funny
16
u/Samalik16 Sep 01 '25
We want revenge for locking us out when we have a legal and inviting market 💢💢
17
u/JoeyKingX Sep 01 '25
Good Irony that it redirected to a server in the Netherlands (since the game IP blocks dutch players)
17
u/MetaThPr4h Arknights Sep 01 '25
Bro was low on pulls on the current banner so planned all of this to reach the spark via compensation mails fr.
73
u/Jueyuan_WW Sep 01 '25
This gotta be edited... A company being so clear, concise and honest about something like this... You have to be lying lol
60
u/NatiBlaze Sep 01 '25
It seems with the improvement of the new translators that don't fuck with text as much, they also got great EN PR person because this mess definitely was communicated well to us
21
8
17
u/ChanceNecessary2455 Sep 01 '25
This could've ended worse. Imagine the compensation if there were actual damage on players' account. Good thing the hacker wasn't THAT malicious.
Now for the future ones, idk, but nobody will reject free apologems from "harmless" hacking.
9
3
u/MillionMiracles iDOLM@STER Sep 02 '25
I'm assuming the hacker tried reporting the vulnerability and got no response, so they did this to force their hand. Hopefully they don't get in trouble.
2
u/cidrei Sep 02 '25
Nexon also gave 840 pyro (7 pulls) for the maintenance time itself, in addition to the listed compensation.
1
3
u/KnowingMyself94 Sep 03 '25
hacked blue archive
has the power of the sun on top of your palm
does nothing but give my cafe hundreds of Koyuki
free rewards for nothingburger
Based hacker? Based hacker.
1
1
1
1
u/jeboi_058 Sep 02 '25
That IP address gotta be a VPN, BA isn't even available in the Netherlands(due to gambling laws, not the game content)
1
u/zappingbluelight Sep 03 '25
NGL, I thought the whole thing was a promotion, can't believe they actually got hacked.
0
-23
u/RUS12389 Sep 01 '25
People who say that what Hacker did was harmless, do you really expect a company to truthfully tell if hacker got some important information, especially if it's about user's private details? Maybe things really were harmless, maybe Nexon is hiding something, we will never truly know. But I wouldn't trust a company's statement.
16
u/sirbucelotte Sep 01 '25
Pasting the comment i made before:
This is most probably an user who found the exploit and tried to contact them about it without success, them used the exploit to warn them about it in a more direct way, and It worked flawlessly, they even stated that theyre gonna start a bug bounty in the future to help it with tighten security.
The use of Koyuki for the memes, The CEO/Suzumi/Hatsune Miku birthday to do it, the long detailing on the statement and the way it moved Nexon to tighten their security and even start a bug bounty program, is actually a good ending for all of this. And the whitehat hacker wouldnt involve the Internet Security Department of Korea for nothing, he could be hunted for the Korea police for just putting Koyuki in the frontpage if he doesnt come clear and said what exploit he found
18
u/Samalik16 Sep 01 '25
They would be legally required to notify of breaches like that. That means their customer base would be compromised
-46
-22
u/Mathster0598 Sep 01 '25
Nexon taking L's
Nothing New.
I expect more security breaches from now on from more malicious bad actors given they've already been exposed to be negligent.
Anime girl now, accounts stolen later.





797
u/KnightMareValtiel Sep 01 '25
Im honestly surprised how the Hacker really did something "harmless" as to put Koyukis everywhere and nothing else lol Pretty fit for our pink gremlin