Former Old School RuneScape dev gets jail time for stealing $400,000 from players — virtual gold stolen and sold on the black market before Jagex caught the culprit using hidden firewall tweaks
- ID
- 21939
- Status
- summarized
- Published
- 06 Sep 2026, 6:30 PM
- Fetched
- 06 Sep 2026, 7:38 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/video-games/former-old-school-runescape-dev-gets-jail-time-for-stealing-usd400-000-from-players-virtual-gold-stolen-and-sold-on-the-black-market-before-jagex-caught-the-culprit-using-hidden-firewall-tweaks
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 3.0
- Created
- 06 Sep 2026, 7:38 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
A former Old School RuneScape developer was sentenced to jail for stealing approximately $400,000 worth of virtual gold from players and selling it on the black market. Jagex detected the insider abuse through hidden firewall tweaks the developer had made to cover their tracks.
Why it matters
This is an insider-threat cautionary tale: a trusted developer with production access exploited game systems for personal gain and was caught through network-level forensic evidence. For founders and team leads, it reinforces the need for access logging, change tracking on infrastructure configs (including firewall rules), and segregation of duties — but the story is gaming-specific and not actionable for most builders.
Discussion angle
How would your team detect a rogue insider quietly modifying firewall rules or production configs to exfiltrate value — do you have change tracking and alerting on infrastructure-level changes, or only on application code?