Data Breaches

Partner Breach, Not NVIDIA Core, Exposed GeForce NOW Users

The breach matters because the exposed data sits with a regional operator, not NVIDIA’s own platform. That changes the control point for cleanup and notice, and it means a vendor-wide breach response is the wrong mental model here.

NVIDIA says the incident was limited to a third-party GeForce NOW Alliance partner in Armenia and that NVIDIA-operated services were not affected. The partner says the incident ran from March 20 to 26 and exposed names, email addresses, phone numbers, dates of birth, and usernames; it says no passwords were exposed.

For users of the Armenia service, the risk is identity and account-targeting exposure, not takeover of NVIDIA’s core cloud gaming network. The bigger pattern is that regional partners can hold customer data and operate their own systems, so a breach can be real, contained, and still sit outside the vendor’s central environment.

1 source · May 8

Timeline

Sources

Part of the PlainSec briefing for 2026-05-08

Every edition of this story: Partner Breach, Not NVIDIA Core, Exposed GeForce NOW Users