// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Roblox

DISCLOSED 2026-09-20 · STOLEN CREDS · 610,000 RECORDS EXPOSED

A data breach involving Roblox accounts has exposed 610,000 accounts, including rare in-game items and purchase histories. The attack vector was session token theft, highlighting the growing threat of this method in gaming account compromises. The breach has resulted in high brand reputation impact due to public disclosure of large-scale account theft.

The record

What we know

Disclosed
2026-09-20
Attack vector
Stolen Creds
Sector
Gaming
Records exposed
610,000
Domain
roblox.com
Data classes exposed
account credentialspurchase historiesin-game items
ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · partial · opinion

A positive-security model could have prevented unauthorized access by blocking the use of stolen session tokens, as it would only allow known-good authentication states. However, if the token theft occurred via social engineering or malware on the user's device, the allowlist model might not have stopped the initial compromise.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the Roblox disclosure. It updates if new public reporting emerges. All tracked breaches →

Roblox just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →