Cloud Imperium Games, the studio behind the video game Star Citizen, filed a data breach notification with the California Attorney General’s office, listing a breach date of January 21, 2026. Unfortunately, the official notification document submitted for this filing appears to be a scanned image rather than searchable text, so we were not able to extract the specific details the company shared with affected individuals, including exactly how the breach happened. Because of that, the method of attack cannot be confirmed from this filing.
The filing does not include an aggregate number of people affected, and without readable text from the notice itself, we cannot say precisely who was impacted beyond noting that at least one California resident was affected, which is why the company was required to notify the state.
What information was exposed?
- The specific types of personal information involved in this breach were not disclosed in the readable portion of the filing.
- Because the source document could not be scanned for text, BreachLetter cannot confirm whether names, account details, payment information, or other identifiers were included.
- If you received a direct letter from Cloud Imperium Games, refer to that letter for the specific data types it lists, since it may contain details this filing does not show.
No information about free credit monitoring or identity protection services being offered was found in the readable portion of this filing.
What should you do now?
- If you have an account with Cloud Imperium Games or play Star Citizen, change your account password now and use a new, unique password you haven’t used elsewhere.
- Turn on two-factor authentication for your gaming account and any linked email address, if it isn’t already enabled.
- Watch out for phishing emails or messages pretending to be from Cloud Imperium Games, especially ones asking you to click a link, verify account details, or provide payment information.
- Check whether the same email and password combination is reused on other sites, and update those accounts too, since attackers often try stolen credentials across multiple platforms.
- Review your bank and payment card statements for any unfamiliar charges if you have ever purchased in-game currency, ships, or subscriptions through this company.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, particularly useful when the exact scope of an exposure isn’t fully clear.
- Keep a copy of any breach notification letter you receive directly from the company, since it may contain details, dates, or offers not reflected in this public filing.