Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hackers Claim Theft of Epic Games Private Repositories, Company Yet to Confirm Breach

Hackers Claim Theft of Epic Games Private Repositories, Company Yet to Confirm Breach

By: Jordan Vector Cybersecurity Expert

Last updated: July 29, 2026

Human Written
Hackers Claim Theft of Epic Games Private Repositories, Company Yet to Confirm Breach
  • A threat actor is advertising a purportedly massive amount of Epic Games private repositories.

  • The seller claims the alleged archive consists of thousands of files from Unreal Tournament, Unreal Engine, as well as internal developer tools.

  • They provided no evidence to prove whether the information is legit, and Epic Games hasn’t officially acknowledged any data breach.

Someone posted on a dark web forum claiming to have source code and internal repositories from Epic Games. They claimed the source code for Unreal Engine version 5.8.0 is part of the alleged haul, plus 330,000 files in a compressed archive.

Unreal Engine is among the most popular game development engines worldwide and is behind many games and enterprise visualization applications. Presently, there is no independent evidence of any breach of Epic Games. No reputable threat intelligence company has verified the files.

What the Threat Actor Claims

The underground forum post claims the archive contains access to several private Epic Games repositories. The seller says the collection includes the Unreal Engine 5.8.0 source code with roughly 224,000 files.

Other alleged contents include Unreal Tournament repositories, Maya rigging tools, Unreal Zen Storage Server, hair and fur grooming tools, and a user-generated content moderation project.

The threat actor also claims Epic engineers were using Claude Code with Model Context Protocol (MCP). However, they never posted any samples, no screenshots, logs, or even technical evidence to support their claim. Also, for now, these assertions haven’t been independently verified.

Why Source Code Exposures are Risky 

A real leak of private source code? That’s often a big deal for hackers because they can study it and find weak spots. And it’s not the code itself alone. Those internal developer tools show exactly how everything is built and tested. They’re basically a blueprint, it tells attackers where to hit and how to break in, making future attacks a lot easier.

However, source code leaks do not necessarily mean the attackers would find any exploitable vulnerability. Usually, security experts have to discover some coding errors and understand if they’re exploitable.

Moreover, it’s important to note that source code leaks are very different from customer data leaks. The process of finding vulnerabilities is being accelerated by AI tools. Anthropic has launched a security tool designed to help identify software weaknesses. The current claims focus on developer repositories rather than user information. This isn’t a ransomware group claiming they stole personal data.

Epic Already Uses Controlled Source Access

Epic Games lets licensed developers access the Unreal Engine source code via GitHub. It requires developers to connect their Epic account to GitHub and agree to Epic Games’ licensing terms.

It’s not really “open source” in the real sense, but source-available. It’s kinda like you can see and use the code, but only if you abide by Epic’s rules. This necessarily means that Epic’s licensing agreements control who gains access.

The alleged forum post claims to contain repositories not intended for public distribution. These include internal development projects and engineering tools.

Without validation, it remains unclear whether the files are genuine private repositories, outdated copies, fabricated content, or material previously available through legitimate developer access.

Claude Code Mention Raises Questions

One of the more eye-catching parts of the advertisement is the claim that Epic engineers used Claude Code with MCP. There is no evidence that this statement has any link to any alleged compromise.

Epic has publicly released projects related to AI-assisted development, including tooling for Claude Code integration with Unreal Engine. Public references alone don’t count as evidence of a breach.

No Public Confirmation From Epic

As of publication, Epic Games has not issued a public statement confirming a security incident related to the alleged source code dump. No known security researchers have authenticated the files. No trusted threat intelligence firm has published a technical analysis confirming the seller’s claims.

That leaves several possibilities. The data could represent an authentic breach, recycled material from earlier developer access, fabricated samples designed to attract buyers, or a mixture of legitimate and fake content.

Cyber criminals usually use exaggerations and even fabricate claims to inflate the value of their listing. Underground marketplaces are notorious for hosting listings of incomplete, old, duplicate, or completely fake data.

What Organizations Should Watch

Game studios and organizations that build software on Unreal Engine do not need to assume immediate risk based solely on the forum post. They should take the following criteria into account:

  • An official announcement by Epic Games
  • Validation of the information by independent security experts
  • Publication of verifiable file samples
  • Signs that any leaked code has any vulnerabilities not known before.

If it turns out that the repositories are authentic, then Epid would likely look into the extent of exposure. They’ll then release guidance on how developers should approach it.

For now, the alleged Epic Games source code leak remains exactly that—an allegation. Until further proof surfaces, consider this posting on underground forums to be a mere rumor about a cybercrime.

This is especially important as many posts on underground forums usually mix real stolen data with marketing hypes to attract buyers.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.