NVIDIA GeForce NOW Partner Breach
Coverage from BleepingComputer, TechRadar, and others
Articles
5
Active Days
8
The Topic

A breach of GFN.am infrastructure exposed personal information belonging to some GeForce NOW users in Armenia. NVIDIA says its own systems were not affected, while GFN.am reported that passwords were not compromised and that users who registered after March 9, 2026 were not affected. The incident highlights how regional partners with separate authentication and customer databases can create localized exposure for major technology services.
First Article: 05/05/26
Latest Article: 05/12/26
Summary
- GFN.am, a regional GeForce NOW partner, was the affected operator rather than NVIDIA-operated infrastructure.
- Reportedly exposed data included names, email addresses, usernames, phone numbers, dates of birth, membership status, and 2FA/TOTP status.
- The affected population was reported as GeForce NOW users in Armenia; no impact was confirmed in other countries served by GFN.am.
- GFN.am placed the incident between March 20 and March 26 or March 28, 2026, depending on the report.
- Users who registered after March 9, 2026 were reported as unaffected, and passwords were not exposed according to GFN.am.
- A forum listing offered alleged records for $100,000 in cryptocurrency, but the ShinyHunters attribution was disputed and the post was later removed.
- GFN.am was responsible for notifying affected users and reported containment and security-hardening measures.
History
The update adds a more detailed account of what GFN.am says was exposed and sharpens the scope of impact, including a new claim that only Armenia was affected and that later accounts were unaffected. It also introduces the underground-forum sale claim and disputed ShinyHunters attribution, which reframes the incident as a localized breach plus extortion-style publicity.
