The fake playtest invite scam - what developers need to know
The documented pattern (Malwarebytes, Oct 2025): an attacker compromises accounts, then DMs that account's friends - often in game-dev and playtester circles - asking "can you test my game?" with a link to a convincing lookalike page. The download is a quiet loader; the new victim's account then spreads the next wave. Developers appear twice in this chain: your game's identity gets borrowed for the lure, and your community's trust is the distribution channel.
Why playtests specifically
Indie playtesting normalizes exactly the behavior the lure needs: strangers sending builds, itchy download links, pre-release secrecy, and social pressure to help a fellow dev. A community trained to say yes to "test my game?" is the target surface.
The defensive playbook
- Set a playtest convention and publish it: your builds come only from your official store page or a named service - never from DM links. One line in your Discord rules does real work.
- Tell testers what you will never do: send builds from cloud-drive links, ask for logins, or charge for beta access.
- If your title is used in a lure: run the off-platform sequence (host abuse + Safe Browsing + DMCA), and warn your community by naming your official pages - not the lure URL.
- If a community member got hit: they should change passwords from a clean device, revoke sessions, and warn their own contacts - the compromised account is the next wave's sender.
- Watch for the precursor: lure domains carrying playtest/beta vocabulary register before campaigns launch. Certificate-transparency monitoring sees them at issuance - that early window is the entire value of monitoring.
Common questions
Q: A "publisher" DMed me a build to evaluate. Same pattern?
A: Same mechanics in reverse - unsolicited build, pressure, cloud link. Verify the sender through the company's own site before opening anything.
Q: My tester community is private/invite-only. Are we still exposed?
A: Yes - the campaign spreads through compromised member accounts, which are already inside. The convention ("builds only from official pages") protects even closed groups.
Q: Players are asking whether a link is really my playtest. What do I tell them?
A: Point them at the free download-link check and at your official pages - and take the report: their sighting is often your first detection.
Check your own game now. The free scan looks for lookalike pages using your title, art, or description - no account, private report. Continuous monitoring: Game Title Watch from $9/month.
Related answers
- A fake website is impersonating my game
- Indie game impersonation monitoring - what it is and who needs it
- Is this game download link safe to click?
Game Title Watch provides monitoring assistance, not legal advice. Findings are similarity signals that require your confirmation - they are not accusations about any website. Where an external service has flagged a page, we cite that flag; we never make such claims ourselves.