A Hacker Wiped Secret Neighbor Players — Then Demanded the Game Disappear
- The Mess: A hacker gained administrator-level access to the backend of Secret Neighbor, wiped player profiles and progression, and launched what the developers described as a coordinated attack against the game’s servers and infrastructure.
- The Damage: Players lost progression across platforms, while the attack was serious enough for developer Hologryph and publisher tinyBuild to temporarily take the entire game offline.
- The Fix: The companies are working with backend provider PlayFab to recover deleted data, close the security gaps behind the breach and restore the service. They say no personal player information was compromised.
Most game hackers want money.
Some want accounts.
Some want skins.
This one apparently wanted the game gone.
Secret Neighbor, the multiplayer spin-off of Hello Neighbor, was temporarily taken offline after a hacker gained administrator-level access to its backend systems and started deleting player data.
The attacker didn’t just knock the servers offline.
They went after the players.
The Progression Was the Target
According to Hologryph and tinyBuild, the attacker wiped:
- player profiles
- in-game progression
- other backend data
The companies also described the incident as a coordinated attack against Secret Neighbor’s server systems and infrastructure across all platforms.
For players, that’s a particularly ugly kind of breach.
Your account may still exist.
The game may eventually come back.
But the hours spent unlocking, progressing and playing can disappear.
The Hacker Wanted the Game Removed
The attacker reportedly didn’t stop after deleting data.
Hologryph and tinyBuild said the individual threatened to continue targeting Secret Neighbor and its backend systems until the game was removed from sale across all platforms.
That’s a strange motivation.
No public ransomware demand.
No giant cryptocurrency payment.
No leaked customer database.
Just an apparent demand to make the game disappear.
And when that didn’t happen, the attacker allegedly started deleting things.
Admin Credentials Changed Everything
The key detail is the access level.
The attacker obtained credentials with administrative access to the game’s backend.
Once that happens, the attack stops looking like a typical DDoS incident.
Administrative access means the attacker can potentially interact with the systems that actually store and manage player information.
And that is exactly what makes this incident more interesting than another gaming outage.
The attacker didn’t merely block players from using the service.
They allegedly reached the data underneath it.
Every Platform Got Hit
Secret Neighbor exists across multiple platforms.
The backend attack therefore had consequences beyond one PC server.
Reports indicate the game was taken offline while the companies investigated and attempted to contain the incident.
That’s the uncomfortable reality of modern gaming.
The game on your console may look local.
The progression isn’t.
The saves aren’t always local.
The inventory isn’t.
The backend owns much of the game.
And whoever owns the backend owns a frightening amount of the player’s digital experience.
No Personal Data Was Reportedly Stolen
There is at least one piece of good news.
Hologryph and tinyBuild said they had no indication that personal player information was compromised.
The incident appears focused on the game’s backend and player progression rather than a confirmed theft of customer data.
That distinction matters.
A wiped game profile is frustrating.
A leaked identity, payment record or authentication database is a much bigger long-term problem.
At least for now, the companies say the latter did not happen.
PlayFab Is Helping Recover the Damage
The developers are working with PlayFab, which provides backend services for the game, in an attempt to recover deleted player data.
The relevant authorities were also notified.
There is no confirmed timeline for when Secret Neighbor will return to normal service.
And recovery may be the hardest part.
Taking a compromised service offline is relatively simple.
Restoring deleted progression without accidentally restoring attacker changes is another problem entirely.
Gaming Backends Are Real Attack Surfaces
This story is a useful reminder that games are now cloud applications.
They have:
- authentication systems
- databases
- APIs
- administrative panels
- cloud infrastructure
- service credentials
- third-party backend providers
In other words:
They have the same attack surface as plenty of enterprise applications.
The difference is what attackers can destroy.
Instead of financial records, they can wipe player progression.
Instead of manufacturing systems, they can take a multiplayer game offline.
The technology is different.
The security failure often isn’t.
Bugstoday Opinion
There is something uniquely cruel about this attack.
A ransomware gang steals your data.
A DDoS attack takes your game offline.
This attacker allegedly went directly for the thing players spent their time building.
Their progress.
Hours.
Achievements.
Unlocks.
Gone.
And the attacker reportedly wasn’t even demanding money.
They wanted the game removed.
That’s a reminder that not every cyberattack has a financial motive.
Sometimes the attacker has admin credentials and a personal grudge.
And unfortunately for everyone else, that’s enough.
Bugstoday verdict: when your game’s backend gets compromised, players don’t care whether the attacker stole a database or exploited an API. They care that everything they earned just vanished. Protecting game infrastructure is no longer just about uptime. It’s about protecting the time players have invested.
Today’s Bugs. Tomorrow’s Breaches.




