A significant security incident occurred earlier this year involving Rec Room's friend-finder feature, which allowed users to link their phone contacts to their accounts. In January, an individual exploited this feature to associate the phone numbers of hundreds of thousands of players with their usernames, creating a database that could expose real-world contact information.
The Seattle-based company announced plans to shut down the social gaming platform on June 1, marking the end of a decade-long operation. However, the recent breach has raised concerns about user safety, as Rec Room has not informed those affected, leaving them vulnerable to potential harassment or phishing attempts.
In response to inquiries, Rec Room confirmed the unauthorized activity and stated that it disabled the friend-finder feature and banned the user responsible. A review conducted by an external legal and forensics firm concluded that no further regulatory notification was necessary, as the feature only linked usernames to phone numbers without revealing sensitive account information.
Rec Room emphasized its commitment to user safety, asserting that it has implemented strong measures to protect user data and that its privacy settings are functioning correctly.