Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteYes. GameStop disclosed in 2017 that customer information from some online orders may have been obtained by an unauthorized third party. The potentially affected orders were placed or attempted on GameStop.com from August 10, 2016, through February 9, 2017. The information may have included names, addresses, card numbers, expiration dates and CVVs.
What happened in the GameStop breach?
GameStop’s June 2, 2017 customer notice said an investigation had found that information associated with certain online orders may have been obtained by an unauthorized third party. The potentially affected activity included both completed and attempted orders on GameStop.com.
A U.S. congressional hearing record described the website payment processor as the route through which the data was taken. Wisconsin’s Department of Agriculture, Trade and Consumer Protection also archived a notice reporting that card data was offered for sale. Those reports concern the 2017 incident; they do not establish that GameStop intentionally took customers’ card information.
Which orders and dates were affected?
- Potential order window: August 10, 2016, through February 9, 2017.
- Date GameStop identified potential exposure: April 18, 2017, according to the company’s June 2 notice.
- Who should pay attention: People who placed or attempted to place an online order on GameStop.com during that window.
The notice does not say that every order in the period was affected, nor does it identify a verified number of affected customers.
#1 Best Overall
What information may have been exposed?
GameStop said the information associated with an order may have included the customer’s name, address, payment-card number, expiration date and security code (CVV). The notice uses “may have been obtained,” so it does not establish that every listed field was taken for every customer.
The incident involved payment and order information. The available primary-source materials do not establish that account passwords or other identity documents were exposed in this incident.
What should you do if you placed an order during that period?
- Contact the card issuer first. Tell the issuer you may have used the card for a GameStop.com order in the affected period and ask it to check for suspicious activity. Follow its instructions about blocking or replacing the card.
- Report unauthorized transactions promptly. Use the number on the card or the issuer’s official app or website, and follow its dispute process.
- Review statements and transactions. Check recent activity on the affected card and continue reviewing statements for unfamiliar charges. If the card is still open, keep monitoring it as the issuer advises.
- Review your credit reports. Look for unfamiliar accounts or other activity you did not authorize. If you see something suspicious, contact the relevant lender or credit bureau using its official channels.
GameStop’s notice advised affected customers to contact their card issuer, report unauthorized charges, and review card statements and credit reports. The issuer can advise whether replacement is appropriate for your specific card and circumstances.
Which response helps with which risk?
| Action | What it addresses | When to prioritize it |
|---|---|---|
| Contact the card issuer; block or replace the card if advised | Further use of the potentially exposed payment card | First, especially if you see an unfamiliar transaction |
| Report and dispute unauthorized charges | Transactions you did not make | As soon as you notice them |
| Review card statements | Unrecognized activity on the affected card | Ongoing, including after a replacement card is issued |
| Review credit reports | Signs of broader identity or credit-account misuse | Alongside card monitoring, and again if suspicious activity appears |
Was there a confirmed number of victims or financial loss?
The GameStop notice and other primary-source material identified for this incident do not provide a verified total of affected customers or a dollar amount of losses. A report that card data was offered for sale is not, by itself, a count of customers whose data was accessed or evidence of a specific amount of fraud.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Does this mean GameStop is currently experiencing another breach?
No conclusion about a new incident follows from the 2017 notice. GameStop’s fiscal-2025 Form 10-K describes cybersecurity controls and says the company was not aware of a recent attack that had materially affected it as of that filing. That statement is limited to the filing’s disclosure and timeframe; it does not change what customers should do about a card used during the 2016–2017 exposure window.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

