NVIDIA says its own GeForce NOW operated services were not affected; the incident was tied to GFN.am, an Armenia based Alliance partner. Reportedly exposed data may include names, email addresses, phone numbers, dates of birth, usernames or nicknames, and possibly membership or 2FA related metadata [1][6][8][12].

Create a landscape editorial hero image for this Studio Global article: NVIDIA GeForce NOW GFN.am Data Breach: What Happened and What Users Should Do. Article summary: NVIDIA says this was not a breach of NVIDIA operated GeForce NOW systems; reporting says the incident was tied to GFN.am, its Armenia based Alliance partner.. Topic tags: nvidia, geforce now, data breach, cybersecurity, cloud gaming. Reference image context from search candidates: Reference image 1: visual subject "Monitor email accounts for unusual login attempts or phishing messages. Be cautious of unsolicited calls or SMS messages referencing GFN.AM." source context "NVIDIA Data Breach Reportedly Exposes Personal Information of GeForce Users" Reference image 2: visual subject "Users connected to the Armenian partner service should watch for notifications from GFN.am and be cautious of phishing emails using NVIDIA or" so
Early reports made the incident sound like a breach of NVIDIA’s global GeForce NOW platform. The clearer picture is narrower: NVIDIA told BleepingComputer that its investigation found no impact to NVIDIA-operated services and that the issue was limited to systems run by a third-party GeForce NOW Alliance partner based in Armenia .
That narrower scope does not make the incident harmless. For users who accessed GeForce NOW through GFN.am, reports say personal account details may have been exposed, even though passwords were not . The main risk now is follow-on abuse: phishing, fake support messages, password-reset attempts, and attacks against accounts where the same identity details or passwords were reused.
A hacking group known as ShinyHunters claimed it had breached GeForce NOW and obtained a large user database for sale . NVIDIA later pushed back on the broader framing, saying the issue was limited to GFN.am, a third-party GeForce NOW Alliance partner in Armenia, and that NVIDIA-operated services were not affected
.
GFN.am has been described in reporting as an authorized NVIDIA GeForce NOW cloud gaming service provider . Reports citing GFN.am’s disclosure say unauthorized database access dated back to March 9, 2026, was discovered on May 2, and was publicly disclosed on May 5
. Another report describes the incident window as March 20–26
. Because those timelines do not match, the exact public breach window should be treated as unresolved unless a user-specific notice says otherwise.
The exposed information reportedly included personal account details such as full names, email addresses, phone numbers, dates of birth, usernames, or GFN.am nicknames . Some reports also mention membership or account status, and 2FA-related metadata in the claimed data set
.
The most important limitation is that available reports say account passwords were not exposed . That lowers the risk of direct password compromise from this incident, but it does not eliminate risk. Names, emails, phone numbers, dates of birth, usernames, and account-status details can still make phishing messages and account-recovery scams more convincing
.
NVIDIA’s statement framed the confirmed impact as tied to an Armenia-based partner’s infrastructure, not NVIDIA’s own network . At the same time, reports say GFN.am’s GeForce NOW service has also covered Azerbaijan, Georgia, Kazakhstan, Moldova, Ukraine, and Uzbekistan
.
The safest test is account path, not just geography. If your GeForce NOW registration, billing, local service access, or account notice points to GFN.am, treat yourself as potentially affected until you receive clear official guidance. Some reports say accounts registered on or before March 9, 2026 were affected and accounts created after that date were not . Because another report gives a March 20–26 incident window, users should not rely on that cutoff alone
.
Check official notifications directly. NVIDIA reportedly said impacted users would be notified by GFN.am, and reports also say GFN.am planned to directly notify affected users . Do not click links in unexpected emails, texts, or social messages claiming to offer breach help; go directly to official NVIDIA or GFN.am channels.
Reset your GFN.am or GeForce NOW password if you used the GFN.am service. Reports say passwords were not exposed, so this is a precaution rather than proof that your password is public . It is especially important if the password was reused anywhere else.
Remove password reuse on other accounts. If the same password was used for email, gaming, payment, cloud, or social accounts, change those passwords too. Start with the email account tied to GFN.am because email access can be used to reset other services.
Enable two-factor authentication where available. Some reports say the claimed data included 2FA status or related metadata . Turning on 2FA for email, gaming, payment, and cloud accounts reduces the value of stolen personal details and reused passwords.
Watch for targeted phishing. Because exposed fields reportedly include names, email addresses, phone numbers, dates of birth, usernames, nicknames, and account details, attackers may be able to personalize fake support messages . Be suspicious of messages about refunds, urgent verification, breach compensation, locked accounts, or password resets.
Monitor account activity. Look for unfamiliar logins, password-reset emails, new devices, changed recovery details, and unexpected payment activity. If your phone number was exposed, be extra cautious with verification-code texts, carrier-account messages, or calls asking for identity confirmation .
There is no verified public total for the number of affected users in the available sources. ShinyHunters reportedly claimed a large or millions-scale database, but that figure comes from the threat actor’s claim and should not be treated as independently confirmed .
It is also not clear from the available reporting whether the full claimed data set was sold or widely distributed. Until NVIDIA or GFN.am provides more precise user-level information, affected users should assume exposed personal details could be used for phishing and account-recovery attempts.
The key distinction is that NVIDIA says its own GeForce NOW-operated services were not breached, while systems run by GFN.am, an Armenian GeForce NOW Alliance partner, were the focus of the incident . If you used GeForce NOW through GFN.am, secure the account, eliminate password reuse, enable two-factor authentication, and treat any unexpected breach-related message as suspicious.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
NVIDIA says its own GeForce NOW operated services were not affected; the incident was tied to GFN.am, an Armenia based Alliance partner.
NVIDIA says its own GeForce NOW operated services were not affected; the incident was tied to GFN.am, an Armenia based Alliance partner. Reportedly exposed data may include names, email addresses, phone numbers, dates of birth, usernames or nicknames, and possibly membership or 2FA related metadata [1][6][8][12].
The practical response is to verify official notices, remove password reuse, enable two factor authentication, and treat unexpected breach support messages as phishing risks.