NVIDIA has told BleepingComputer that some GeForce NOW user information was exposed in a data breach, while saying its own operated services were not affected.
The incident appears to center on GFN.am, the regional GeForce NOW operator in Armenia. NVIDIA attributed the matter to systems run by a third-party GeForce NOW Alliance partner in Armenia, though the full scope beyond the partner’s own notice has not been independently verified.
According to NVIDIA’s statement, impacted users are expected to be notified by GFN.am. The company said it is supporting the partner’s investigation and response, but did not describe a breach of NVIDIA’s own network.
What GFN.am Says Was Exposed
GFN.am has published a notice describing a cybersecurity incident that it says occurred between March 20 and March 26. The regional operator said the exposed information may include limited personal data, depending on how a user registered for the service.
The notice identified the following categories:
- Full name, if the account was created or used through a Google account
- Phone number, if the user registered through a mobile operator
GFN.am also said account passwords were not exposed. The operator added that users who registered after March 9 were not affected, according to its notice.
That distinction matters for users deciding what to do next. If only names and phone numbers were exposed, the main practical risks are phishing, account impersonation attempts, spam, and social engineering rather than direct password compromise. Still, any breach involving identity or contact information can make follow-up scams more convincing.
Norton 360 Deluxe
A security suite with scam alerts, password tools, and dark web monitoring can help users watch for suspicious follow-up activity after personal information is exposed. It does not replace careful account review, but it can add another layer of visibility.
As an Amazon Associate I earn from qualifying purchases.
How the Breach Claim Surfaced
The disclosure follows a post on a hacker forum from an actor using the ShinyHunters name. The poster claimed to have breached the GeForce NOW service and stolen millions of user records.
That claim should be treated carefully. The person behind the post is believed to be an impersonator using the ShinyHunters name, and NVIDIA’s statement narrows the confirmed issue to a regional partner environment rather than NVIDIA-operated GeForce NOW services.
The forum post reportedly claimed the stolen data included full names, email addresses, usernames, dates of birth, membership status, and two-factor authentication or TOTP status. Those broader claims have not been confirmed by NVIDIA in the details provided, and GFN.am’s public notice described a narrower set of exposed information.
The actor also claimed to be selling the database for $100,000 in cryptocurrency. The post was later removed from the forum. It remains unclear whether it was removed by the seller, forum administrators, or for some other reason, and there is no confirmed public indication that a sale took place.
Why Partner Infrastructure Matters
GeForce NOW is NVIDIA’s cloud gaming service, allowing players to stream games running on remote hardware powered by NVIDIA GPUs. In some markets, regional Alliance partners operate local GeForce NOW services.
Those partner environments may involve their own customer records, billing systems, authentication workflows, and managed infrastructure. That can create a different risk profile from a breach inside NVIDIA’s own corporate or service network.
In this case, NVIDIA’s position is that the issue was limited to the Armenian partner’s systems. GFN.am is associated with GeForce NOW operations in Armenia, and NVIDIA’s support materials also list the operator in connection with several other countries in the region. No confirmed impact has been reported for those other countries based on the information provided.
What Affected Users Should Do
Users in Armenia who used GFN.am should watch for direct notification from the operator and treat unexpected messages with caution, especially if they mention GeForce NOW billing, account verification, refunds, or password resets.
Practical steps include:
- Be skeptical of emails or texts asking for account credentials or one-time codes.
- Go directly to the official service site instead of clicking links in unexpected messages.
- Review account security settings and enable two-factor authentication where available.
- Watch for phone-based phishing attempts if a mobile number may have been exposed.
- Use a unique password for gaming, email, and payment-related accounts, even if this incident did not expose passwords.
YubiKey 5 NFC Security Key
For important accounts that support security keys, a hardware key can reduce the risk of account takeover from phishing links or stolen codes. Users should confirm compatibility with their email, password manager, and gaming accounts before buying.
As an Amazon Associate I earn from qualifying purchases.
For buyers and security teams, the bigger lesson is third-party exposure. A service can avoid a breach of its own core infrastructure and still face user-impacting fallout through a regional operator or partner. That makes vendor oversight, breach notification terms, and data minimization especially important when customer information is handled outside the primary provider’s environment.


