Capcom confirmed that hackers stole information during a ransomware attack detected on November 2, 2020. Its final public investigation, issued April 13, 2021, traced the initial access to an older backup VPN device at Capcom U.S.A. and revised the company’s cumulative count of people with verified compromised personal information to 15,649. A separate estimate of approximately 390,000 people referred to the maximum number whose information might have been compromised—not a confirmed victim count.
What happened in the Capcom attack?
Capcom said it detected internal network connectivity problems on November 2, 2020, shut down systems, and confirmed a ransomware attack that encrypted data on company devices. Its investigation later found that attackers had gained access in October through an older backup VPN device maintained at Capcom U.S.A., the company’s North American subsidiary. The attackers reached devices in U.S. and Japanese offices; Capcom said information was stolen and some devices were subsequently infected with ransomware.
Capcom said the older VPN remained in place as an emergency backup during network strain associated with the COVID-19 situation in California, despite newer VPN devices being available. The company reported that it had removed the older device. The investigation was conducted with external specialists, completed in March 2021, and its findings were published on April 13.
What information did the attackers access?
Capcom listed names, addresses, phone numbers, email addresses, and human-resources information among personal-data categories potentially involved. It also reported that data taken included corporate material such as sales reports, financial information, game-development documents, and business-partner information. The report does not mean every category applied to every affected person, or that every listed type of information was verified compromised in the same way.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Capcom said encrypted files affected access to systems including email and file servers. The company reported finding a threatening message from a group calling itself Ragnar Locker and contacting Osaka Prefectural Police. Capcom said it did not contact the threat actor and did not know a ransom demand amount; it found no ransom amount in the message file.
How many people were affected?
Capcom’s figures changed as it investigated. The confirmed totals are counts of people whose personal information the company verified as compromised; the larger potential figure is an estimate of possible exposure, not a verified count.
| Capcom statement | Verified personal information compromised | Potential exposure |
|---|---|---|
| January 12, 2021 update | 16,415 people cumulatively, according to Capcom’s update. | Up to approximately 390,000 customers, business partners, and other external parties, according to Capcom. Lost logs meant the potential total could not be specifically ascertained. |
| April 13, 2021 final report | 15,649 people cumulatively, according to Capcom’s revised figure. | Capcom said the potential-compromise figure was unchanged from the January update. |
In its January update, Capcom also removed about 18,000 North American Capcom Store and esports records from an earlier estimate after finding no evidence that those records had been compromised. The difference between the January and April verified totals reflects the figures Capcom published at those respective points in its investigation; it is not a reason to treat the approximately 390,000 potential maximum as confirmed victims.
Were payment details or online play affected?
Capcom said credit-card information was not at risk because online transactions were handled by a third-party provider on a separate system. It also said the affected network areas were unrelated to the online systems used to play or purchase Capcom games. These are Capcom’s statements about the systems involved in this incident, not a broader assurance about every Capcom account or service.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
What did Capcom say about misuse and its response?
In its April 2021 report, Capcom stated: “Further, the company has not been able to confirm any damages, etc. resulting from actual misuse of the compromised information at this point in time.” That statement describes what the company could confirm when it issued the report; it does not establish that misuse never occurred afterward.
Capcom reported that it cleaned compromised devices, rechecked VPN-device safety, reviewed business accounts, and strengthened VPN and device management, including long-term log storage. It also said it introduced continuous security operations center (SOC) monitoring and endpoint detection and response (EDR), and established a security oversight committee with external specialists. These were company-reported measures in the 2021 report, not an independent assessment of Capcom’s security today.
Quick Recap
Best Value
Rank #4
Sources
- Capcom, April 13, 2021: final investigation report
- Capcom, January 12, 2021: personal-information update
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




