← Game Title Watch · published 2026-08-15 · updated 2026-08-15

The fake playtest invite scam - what developers need to know

The documented pattern (Malwarebytes, Oct 2025): an attacker compromises accounts, then DMs that account's friends - often in game-dev and playtester circles - asking "can you test my game?" with a link to a convincing lookalike page. The download is a quiet loader; the new victim's account then spreads the next wave. Developers appear twice in this chain: your game's identity gets borrowed for the lure, and your community's trust is the distribution channel.

Why playtests specifically

Indie playtesting normalizes exactly the behavior the lure needs: strangers sending builds, itchy download links, pre-release secrecy, and social pressure to help a fellow dev. A community trained to say yes to "test my game?" is the target surface.

The defensive playbook

  1. Set a playtest convention and publish it: your builds come only from your official store page or a named service - never from DM links. One line in your Discord rules does real work.
  2. Tell testers what you will never do: send builds from cloud-drive links, ask for logins, or charge for beta access.
  3. If your title is used in a lure: run the off-platform sequence (host abuse + Safe Browsing + DMCA), and warn your community by naming your official pages - not the lure URL.
  4. If a community member got hit: they should change passwords from a clean device, revoke sessions, and warn their own contacts - the compromised account is the next wave's sender.
  5. Watch for the precursor: lure domains carrying playtest/beta vocabulary register before campaigns launch. Certificate-transparency monitoring sees them at issuance - that early window is the entire value of monitoring.

Common questions

Q: A "publisher" DMed me a build to evaluate. Same pattern?

A: Same mechanics in reverse - unsolicited build, pressure, cloud link. Verify the sender through the company's own site before opening anything.

Q: My tester community is private/invite-only. Are we still exposed?

A: Yes - the campaign spreads through compromised member accounts, which are already inside. The convention ("builds only from official pages") protects even closed groups.

Q: Players are asking whether a link is really my playtest. What do I tell them?

A: Point them at the free download-link check and at your official pages - and take the report: their sighting is often your first detection.

Check your own game now. The free scan looks for lookalike pages using your title, art, or description - no account, private report. Continuous monitoring: Game Title Watch from $9/month.

Related answers

Game Title Watch provides monitoring assistance, not legal advice. Findings are similarity signals that require your confirmation - they are not accusations about any website. Where an external service has flagged a page, we cite that flag; we never make such claims ourselves.