Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
GameStop

GameStop Vendor Cyber Rating & Cyber Score

gamestop.com

GameStop offers games, entertainment products and technology through its e-commerce properties and stores.


GameStop A.I CyberSecurity Scoring

GameStop
Company Information
Website:https://www.gamestop.com
Employees number:17,069
Number of followers:164,254
NAICS:43
Industry Type:Retail
Homepage:gamestop.com
GameStop Risk Score (AI oriented)
Between 700 and 749
logo
GameStopRetail
Updated:
01/04/2026
745/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
GameStop Global Score (TPRM)
xxxx
logo
GameStopRetail
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

GameStop
GameStopModerate
Current Score
745Ba (MODERATE)
01000
4 incidents
-22 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
746Before Incident
MAY 2026
745Before Incident
APRIL 2026
745Before Incident
MARCH 2026
744Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
743Before Incident
DECEMBER 2025
764Before Incident
Cyber Attack
28 Dec 2025GameStop
Canva, Adyen, Atlassian, HubSpot, Epic Games, Moderna, GameStop, ZoomInfo, WeWork, Halliburton, Betterment, Sonos and Telstra: Over 100 Organizations Targeted in ShinyHunters Phishing Campaign

ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations

742After Incident
CRITICAL-22
CANADYATLHUBEPIMODGAMZOOWEWHALBETSONTEL1769527593
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations A recent cybercrime campaign attributed to the ShinyHunters group has targeted at least 100 organizations across multiple sectors, including software, finance, healthcare, and energy, according to cybersecurity firm Silent Push. Over the past 30 days, threat actors registered fake domains impersonating high-profile companies such as Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos, and Telstra. The attackers employed voice phishing (vishing) tactics to compromise single sign-on (SSO) accounts, particularly those using Okta and other identity platforms. Using specialized phishing kits, they intercepted credentials and manipulated victims into bypassing multi-factor authentication (MFA) by convincing them to approve push notifications or submit one-time passcodes (OTPs). Okta described the attacks as involving real-time session orchestration, where threat actors guided victims through the authentication process via verbal instructions. While Silent Push identified the infrastructure used in the campaign, it remains unclear whether the attacks successfully breached any systems. However, ShinyHunters has claimed responsibility for data breaches at companies like Betterment, Crunchbase, and SoundCloud, all of which confirmed incidents. The group allegedly stole millions of records from these organizations as part of the Okta SSO vishing campaign. Silent Push attributes the campaign to Scattered LAPSUS$ Hunters, a collective formed last year by members of Lapsus$, Scattered Spider, and ShinyHunters, based on observed tactics, techniques, and procedures (TTPs). The incident follows recent warnings from Google and others about rising vishing and phishing attacks targeting identity platforms.
INCIDENT DETAILS -
TYPE
Phishing (Vishing), Data Breach, Credential Theft
MOTIVATION
Data Theft, Financial Gain, Credential Harvesting
IMPACT
Data Compromised: Millions of records allegedly stolenSystems Affected: SSO accounts (Okta and other identity platforms)Identity Theft Risk: High (PII and credentials compromised)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII), Credentials, Business DataNumber Of Records Exposed: Millions (alleged)Sensitivity Of Data: High (PII, credentials)Data Exfiltration: Alleged (data sold on dark web)Personally Identifiable Information: Yes
NOVEMBER 2025
763Before Incident
OCTOBER 2025
763Before Incident
SEPTEMBER 2025
763Before Incident
AUGUST 2025
762Before Incident
JULY 2025
762Before Incident
JUNE 2017
688Before Incident
Breach
01 Jun 2017GameStop
GameStop

Gamestop Data Breach

638After Incident
CRITICAL-50
GAM959261123
A security breach has exposed the financial and personal data of Gamestop's online customers. Clients received postal letters from the corporation, which also stated that the credit card or bank card information of an unspecified number of online clients had been compromised. Hackers gained access to names, addresses, card numbers, expiration dates, and the three-digit card verification values (CVV2). The corporation claims that neither retail customers nor the PoS systems at the company stores were compromised by the security vulnerability."
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
NamesAddressesCard NumbersExpiration DatesThree-digit Card Verification Values (CVV2)
DATA BREACH
Financial DataPersonal DataSensitivity Of Data: HighNamesAddressesCard NumbersExpiration DatesThree-digit Card Verification Values (CVV2)
FEBRUARY 2017
729Before Incident
Breach
01 Feb 2017GameStop
GameStop

GameStop.com Data Breach

680After Incident
HIGH-49
GAM11312922
GameStop.com website suffered from a data breach incident in February 2017. The compromised information includes customer card number, expiration date, name, address and card verification value (CVV2), usually a 3-digit security code printed on the backs of credit cards. They immediately reported the incident to the bank that issued the card because payment card network rules generally state that cardholders were not responsible for unauthorized charges.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Customer card numberExpiration dateNameAddressCard verification value (CVV2)Payment Information Risk: High
DATA BREACH
Customer card numberExpiration dateNameAddressCard verification value (CVV2)Sensitivity Of Data: High
AUGUST 2016
798Before Incident
Breach
10 Aug 2016GameStop
GameStop, Inc.

GameStop Data Breach

723After Incident
CRITICAL-75
GAM428072725
The Washington State Office of the Attorney General reported a data breach involving GameStop, Inc. on June 5, 2017. The breach occurred due to unauthorized access to its computer network, potentially exposing the personal and financial information of 27,956 Washington residents between August 10, 2016, and February 9, 2017.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personal InformationFinancial Information
DATA BREACH
Personal InformationFinancial Information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for GameStop ?
?
What was GameStop's A.I Rankiteo Cyber Score in May 2026 ?
?
What was GameStop's A.I Rankiteo Cyber Score in April 2026 ?
?
What was GameStop's A.I Rankiteo Cyber Score in March 2026 ?
?
What was GameStop's A.I Rankiteo Cyber Score in February 2026 ?
?
What was GameStop's A.I Rankiteo Cyber Score in January 2026 ?
?
What was GameStop's A.I Rankiteo Cyber Score in December 2025 ?
?
What was GameStop's A.I Rankiteo Cyber Score in November 2025 ?
?
What was GameStop's A.I Rankiteo Cyber Score in October 2025 ?
?
What was GameStop's A.I Rankiteo Cyber Score in September 2025 ?
?
What was GameStop's A.I Rankiteo Cyber Score in August 2025 ?
?
What was GameStop's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on GameStop's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with GameStop ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view GameStop's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
GameStop Cyber Scoring History | Rankiteo