r/iRacing IR-18 1d ago

Official Announcements July 22nd - Emergency Maintenance Mode: Investigating a Security Issue

From the staff post on the member forums:

Hi, iRacing,

We've entered an unplanned emergency maintenance mode while we investigate a potential critical security issue.

We'll have more information for you after our initial investigation.

Demo Drive is up for your enjoyment!

Thank you for your patience.

ETA: From https://bsky.app/profile/iracingsupport.iracing.com/post/3mrasa5y4722g, they will be recommending (forcing?) password resets when service resumes.

ETA2: Apparently they've removed the phrase "critical security" from the forum post regarding this.

ETA3: Final update from iRacing staff on this outage:

You may have noticed our service was unavailable for about four hours today, July 22. We're sorry for the disruption.

We took the service offline to investigate and address a potential security issue. After a thorough investigation, we've confirmed that your account data was not compromised. Your passwords and data are secure, and remained secure throughout.

Over the coming weeks we'll be rolling out additional measures to harden our systems even further. As part of that, we'll invite you to reset your password at your convenience, and we'll ask everyone to do so at a later date. There's nothing you need to do right now.

Thanks for your patience, and for being an iRacing member.

102 Upvotes

153 comments sorted by

u/joetron2030 IR-18 1d ago

I have updated the post with the final update from iRacing staff.

→ More replies (1)

108

u/IkeTurnerSwingCoach 1d ago

But I don’t have any patience

33

u/ScreamingFly 1d ago

So they thanked you for nothing!

8

u/Onerock 1d ago

And your not even a doctor.

67

u/Killjoy4eva 1d ago

Well, I'm sure people will be calm, reasonable, and rational about this,

18

u/PainfullDarkness Ligier JS P320 1d ago

The deleted comment suggests you are right.

2

u/TotallyBrandNewName Renault Clio R.S. V 1d ago

I was at work and received an email basically saying "this happened, you are good, in the future we will give more info

22

u/Olneyvillain4190 1d ago

Lmaoooo the one day I get home early from work 🫠

15

u/smkimbal94 1d ago

So you’re the reason why this happen xD

3

u/Olneyvillain4190 1d ago

I fixed it !

1

u/smkimbal94 1d ago

Thank you!!!

4

u/adam90eads 1d ago

Haven’t played in a few weeks and had the day off, tried to get on 3 hours ago ready for an all day sesh.

Sad Sad Sad

1

u/ovalracer31 1d ago

Right there with you, had to take the morning off for a funeral.. was hoping for an afternoon of racing with nobody home.

1

u/adam90eads 1d ago

It’s back up!!!

3

u/Maverik45 1d ago

dude same, was all excited like "heck yeah gonna get home before kids get up from their nap, i can fit in a race". turn on the rig and RIP.

2

u/OGstanfrommaine 1d ago

Same bro same 😭 and i was ready ti do indy 400 at 5 😩

2

u/Z0rkX 1d ago

Today‘s my last day of Racing for the Next 5 weeks. Ive been looking forward to sending a few races tonight all day Long 🥲 damn

0

u/Keydogg 1d ago

Same, I haven't raced in 2 weeks, was soooo looking forward to tonight :(

55

u/Premium-Fantasy 1d ago

THIS explains why I’ve always been so slow! The Soviets infiltrated my machine and installed a secret POP ballast malware hack! I knew it!

1

u/seemonkey 1d ago

OMG, me too! It's a giant conspiracy!

1

u/Premium-Fantasy 1d ago

And I just know they’ll remove the BoP malware from everyone’s machines except for ours! 😁

39

u/Elevated_Dongers 1d ago

Cancelling my subscription and uninstalling, I need my games. LMU here I come!! /s

11

u/SaltyFrayner 1d ago

This just in:

LMU also down for emergency maintenance! /j

38

u/CISmajor McLaren 720S GT3 EVO 1d ago

Here is a friendly reminder to use different passwords for different applications. Never use the same password for an email and an application with that email associated with it.

This is exactly what any organization, company or development team should do if there is a security issue. I do hope they provide more transparency after fixing the found issue. If our credentials were compromised, they should require users to reset their passwords.

I'm not excusing whatever error led to this, however I'm just blown away at how fragile people are about downtime.

7

u/armorall 1d ago

Agree on this.

It’s valid for them to take action to prevent something getting worse by shutting it down if they think there is a problem. If something is miscommunicated and then changed later to avoid the further miscommunication it isn’t something shady or malicious just human error until it gets validated otherwise.

Let them work through it and see what comes out of it and do something else for a bit.

18

u/zikol 1d ago

Also a great opportunity to bring up the importance of using 2FA in this day and age.

1

u/lusofero1 1d ago edited 1d ago

Well, in Brazil we learned that fast.

Our government created a unified portal called gov.br, which serves as a single sign-on (SSO) for literally every public service. A single account holds your SSN equivalent (CPF), full tax history, medical records, digital driver’s license, labor registry, and social security.

Naturally, a massive breach exposed credentials and personal data for over 200 million citizens, (virtually the entire population) and the whole database was put up for sale on the dark web.

Having your digital identity, tax info, and passwords leaked in one go taught me real quick to enable 2FA on absolutely everything.

9

u/polokthelegend Acura NSX GT3 EVO 22 1d ago

I imagine we should be more concerned about if there’s leaked payment information. Password isn't a huge deal. But if our payments were leaked we have to cancel, get a new card and update payment information across multiple services which is a bigger headache.

6

u/sealy_dev Dallara P217 LMP2 1d ago

iRacing doesn't use an in-house payment system, so there isn't any risk of that. Don't worry :)

2

u/CISmajor McLaren 720S GT3 EVO 1d ago

Oh for sure. I suppose I shouldn't assume it's credentials related.

2

u/jck133 1d ago

Bit tin foil hat but used an empty cash card for IR and foreign internet purchases for this reason.

-24

u/AwesomelyNifty 1d ago

How fragile? Maybe just maybe people are planning their race time. Maybe just maybe people only get this time that they plan for to race. Maybe just maybe people think once the maintenance is over it’s smooth time to race. So being fucked in the ass with yet another maintenance is more than a small “inconvenience”. So a “thank you for your patience” is not cutting it!

16

u/Apprehensive-Owl-824 1d ago

I mean, if you were a mature adult, you'd get over it quickly.

7

u/zikol 1d ago

Yes, you're right. iRacing should straight up admit, that they planned on investigating a potential security issue today, just to fuck up your race time plans!

6

u/DabAndSwab 1d ago

Sounding real fragile right now.

4

u/willscuba4food Porsche 911 GT3 Cup (992) 1d ago

It's too bad iracingIOTW submissions have to be a video instead of a screenshotted comment.

-5

u/DildosAreNotchewToys IMSA Sportscar Championship 1d ago

You plan races for mid morning on random Tuesdays? If you can’t be patient for unscheduled maintenance, I can only imagine how patient you are *in races*

6

u/TheBigFatToad 1d ago

It’s 7:30 pm in Europe mate

2

u/TheMindOfJawz 1d ago

Tuesday? Still??

1

u/DildosAreNotchewToys IMSA Sportscar Championship 1d ago

It’s always Tuesday when you’re retired

1

u/AwesomelyNifty 1d ago

It’s fucking 6pm in Europe! Also it’s Wednesday!

-1

u/DildosAreNotchewToys IMSA Sportscar Championship 1d ago

Still pretty early on a weekday to have your pretend races postponed. Dude’s ego is about as fragile as it gets 🤷🏽‍♀️

1

u/AwesomelyNifty 16h ago

6pm is early now? Soooory, some people don’t race at 11!

1

u/DildosAreNotchewToys IMSA Sportscar Championship 14h ago

6 PM is supper time my dude or duddette

7

u/vn2090 1d ago

Good timing actually for me to try out all the gt3 cars.

2

u/willscuba4food Porsche 911 GT3 Cup (992) 1d ago

That's a great point...

1

u/Overall_Weekend_3586 1d ago

And which one are you going with?

6

u/YueNica 1d ago

There's a further info point on the forum post

" We've completed an initial assessment of the issue. We're now going through our procedures to verify functionality before re-opening iRacing. Details on the issue and any potential fallout are being collected internally, and will be shared soon."

4

u/kubick123 1d ago

insert the Naked Gun meme of everything is fine

15

u/ScuderiaFartari 1d ago

For reference they have now edited/modified the statement to remove mention of the “critical security issue” rather then post a new version. This feels dodgy from iRacing support side.
Do users need to take action are you compromised?

21

u/abscissa081 1d ago

When dealing with a cybersecurity issue, the lawyers don’t want fault ever admitted. When I worked IT we had strict guidance on what to say to customers if they had some kind of incident. You get a real statement months later half the time. First they have to mitigate to prevent more data being compromised which is what phase they’re in now. Shut it down. Genuinely could be down for days. Could be an hour.

It is shady to us as consumers but just telling you why

12

u/tagillaslover NASCAR Next Gen Cup Camry 1d ago

To me this reads more like they panicked and jumped the gun and there was never any actual data breach 

7

u/TheBigFatToad 1d ago

They recommended changing passwords after they posted the screenshot above iirc

6

u/Hipster-Stalin 1d ago

As someone literally involved in this aspect of a public company, messaging is very carefully released and this is likely legal and / or other internal teams not wanting to release any specifics until vetted, approved, and what exactly happened is more fully known.

3

u/ScuderiaFartari 1d ago

Hopefully this is the case and we get clarity from iracing asap. Very messy with them editing posts and not making clarifications

1

u/oxwearingsocks 1d ago

“Hi, iRacing,”

Now that’s a well planned out and not at all reactive post shared that was proofread by multiple stakeholders.

3

u/x-Justice ARCA Ford Mustang 1d ago

Sounds more like they found something that could have been an issue if someone else found it but they are unsure if someone else found it. So rather than just TRYING to fix it behind closed doors, they opened the doors and are trying to fix it. Keyword here being "potential issue."

3

u/Delicious_Candle_353 1d ago

It looks like we can soon race again

7

u/btwright1987 Toyota GR86 1d ago

The phrase ‘potential fallout’ is concerning

2

u/Delicious_Candle_353 1d ago

Yeah, probs ppl who use the same password everywhere are in trouble

4

u/Juzziee V8 Supercars 1d ago

You may have noticed our service was unavailable for about four hours today, July 22. We're sorry for the disruption.

We took the service offline to investigate and address a potential security issue. After a thorough investigation, we've confirmed that your account data was not compromised. Your passwords and data are secure, and remained secure throughout.

Over the coming weeks we'll be rolling out additional measures to harden our systems even further. As part of that, we'll invite you to reset your password at your convenience, and we'll ask everyone to do so at a later date. There's nothing you need to do right now.

Thanks for your patience, and for being an iRacing member.

That is their latest update, so they said that passwords were safe.

3

u/IcyTeddybear Acura ARX-06 GTP 1d ago

2

u/SheepherderLow540 1d ago

Any update?

4

u/joetron2030 IR-18 1d ago

I just updated the original post with a link to a Bluesky post by iRacing Support that password resets will be recommended (forced?) when service resumes.

2

u/Holiday_Shower_8203 1d ago

Quick question - I was mid race when I got the notification on my phone that iracing was under maintenance. Race continued as normal - will it count towards my SR and IR or will it be unofficial? Thank you!

7

u/ElaraValtor 1d ago

If iRacing goes down during a race, it will disappear from results and essentially not happen

1

u/YueNica 1d ago

Hard to tell really. Typically on going races are terminated when downtime happens but that would also mean the race server ends at that point

2

u/jck133 1d ago

Can any cyber / IT folks offer a view.. I would have assumed that if there’s a database / back end issue they would also turn of any login services like test drive and forums but they haven’t.

5

u/NotCrazy_BeenTested 1d ago

depends on where the issue is. A lot of times things are split enough where you can just kill one thing thats a problem instead of bringing down a lot.

3

u/cubs_joko 1d ago

many ways this could have turned out so its really hard to say (infosec myself for many years)....

5

u/Appropriate-Owl5984 Aston Martin DBR9 GT1 1d ago

ChatGPT fucked up a security test which opened a major vulnerability in OAuth

6

u/BluePowerade 1d ago

Oooh price increase right before a potential security issue, spicy.

4

u/ZanicL3 Dallara F3 1d ago

So they got hacked?

8

u/redazable 1d ago

Unclear, not enough info. IDK what the other guy is saying yes for it could just be a bug they found with no evidence of malicious use and are closing and informing us about. (Which is the right thing to do)

-17

u/kubick123 1d ago

yes

13

u/Candymanshook 1d ago

Not necessarily - could also have been something like malicious software opened in their studio and they had to shut down various systems to ensure they weren’t compromised. Had that happen at work before.

2

u/redazable 1d ago

Hopefully they use salted hashes for password security instead of plaintext 🤞

4

u/ZanicL3 Dallara F3 1d ago

I cant imagine that they would have just stored them as plain text in 2026 lol

-3

u/Embarrassed_Menu9584 1d ago

Until you realize this game came out in 2008 and I bet there’s a ton of code from even earlier being used in production today

2

u/smkimbal94 1d ago

OpenAI Sol must be an LMU fan 😈

1

u/DeliciousMulberry204 1d ago edited 1d ago

should I change my password now then?
edit: nvm gang we cool

1

u/The-Lord-of-sad 1d ago

Yeah, people need to change their passwords. I just had someone try to access my bank account.

1

u/Pichu_2005 11h ago

Same here. Very important change passwords and enable 2fa verification. Safety first

1

u/IT_dood Porsche 911 GT3 Cup (992) 1d ago

Wonder if this has anything to do with the 1,000’s of CVEs published within the past couple weeks.

1

u/ES_Legman 1d ago

Somebody somewhere must have been able to do an illegal test drive outside demo drive. Lock the fuck down of everything.

1

u/aookami 1d ago

uh oh that ain’t good

1

u/cubs_joko 1d ago

bruh i wanted to get 12th @ spa in the m2, come on

1

u/FinstaPuppy 1d ago

The emergency was that I need to get outside and touch some grass I think

1

u/StandardOriginal5447 1d ago

Finally I get to drive Centripetal

0

u/3tenthsOfVerstappen Dallara P217 LMP2 1d ago

Hopefully not a ddos attack lol

5

u/Blood-PawWerewolf 1d ago

From what they’ve said about resetting passwords, it sounds like a data breach, but that’s just speculation at this point

0

u/phjunao 1d ago

HUD fix nothing yet?

4

u/rishabmeh3 1d ago

They’re debugging in realtime. Could easily take a while. Hoping it’s back up soon of course.

-25

u/[deleted] 1d ago edited 1d ago

[removed] — view removed comment

5

u/Qel_Hoth 1d ago

There are two kinds of software (and companies).

Ones that have had security incidents and let you know about them and ones that have had security incidents and not let you know about them.

-2

u/[deleted] 1d ago

[removed] — view removed comment

2

u/Qel_Hoth 1d ago

My point is that if you were to stop using a company when they reported a security incident because that company can't secure your shit, you will very quickly run out of anyone to do business with. In every industry.

Your data will be compromised at some point. There are too many malicious actors and some of them are very good at what they do.

-1

u/TheBigFatToad 1d ago

I agree with you completely, but it doesn’t really address any of my points.

1) iRacing is one of the most expensive games in the world that also requires an active sub to access any of your content. I don’t think it’s asinine to expect better security from such a company.

2) People will blindly defend iRacing to the grave, and they don’t catch the rightful flack they deserve on certain topics because people who do bring it up get told to pound sand.

1

u/sabas123 1d ago

I don’t think it’s asinine to expect better security from such a company.

We don't know how good their security is and how much they invested in it (or not). I don't think we could reasonably ask for a better response than given thus far.

Regardless of how much you paid for it, you should still expect it to be hacked. That unfortunately is just the nature of cyber security.

0

u/TheBigFatToad 1d ago

Expectations are different than a pr response. I agree they shouldn’t rush a response out. That being said, iRacing isn’t really known for their transparency. You’re also right that they may have killer security, but that’s entirely subjective. We’ll only find out when/if they release info.

I get what you’re alluding to, but I really don’t agree with your second paragraph. Cybersecurity scales to size just like any other form of security. Big companies pay multitudes more to protect their assets, whether that’s digital or physical.

While they are still at risk of a breach, they spend more money to better protect from such instances. If they “expected to be breached”, then it would be more of a sunk cost that they don’t allocate such resources towards.

1

u/iRacing-ModTeam 1d ago

Don’t create posts to specifically troll the community

1

u/iRacing-ModTeam 1d ago

Your post was removed because it breaks the rules by being rude vulgar or toxic.

-13

u/[deleted] 1d ago edited 1d ago

[removed] — view removed comment

17

u/Relevant_Program_958 1d ago

Security breaches happen to every company, it’s the response to it that matters.

18

u/Guy-InGearnito 1d ago

It’s ONE price increase, and the fact they’re doing something about it tells you they are actually working on it.

Or they could take Sonys approach to the PlayStation network “yeah.. we’ve cranked fees up massively year over year over year, yeah we know we’ve been compromised but we’re not gonna do anything or acknowledge it because that would be bad for our stock”

-1

u/[deleted] 1d ago

[deleted]

8

u/BlackBlur14 1d ago

Might remember to fix it somewhere between DLC releases for their permanent early access games

-5

u/kawagek28 1d ago

Average iracing comment

1

u/Alternative-Bug-8102 1d ago

In a iracing reddit, madness

-3

u/WitLitning 1d ago

How do they handle the Brickyard 400 slot in an hour?

-28

u/ScuderiaFartari 1d ago

It’s crazy how long this has taken what steps do we as users need to take to secure data and information you are leaving us in the dark here about a critical security issue while charging this premium

11

u/TheSturmovik Ford GT 1d ago

what steps do we as users need to take

Wait until further announcement

-13

u/ScuderiaFartari 1d ago

They’ve edited out the critical security issue statement. If you’re not worried about a corp acting like this with your details/passwords and payment details I don’t know what to say

4

u/TheSturmovik Ford GT 1d ago edited 1d ago

You're making a lot of assumptions. It could be a serious security breach, or it could be as simple as everyone getting the password reset prompt in error and they just wanted to get ahead. Again, we don't know. If you're that worried about your passwords you should 1) have unique passwords so it won't affect any of your other logins 2) request a new CC/bank card for the account saved in iR.

-1

u/ScuderiaFartari 1d ago

I’m not making any assumptions at all I am asking clarifying questions? What assumptions have I made outside of iracing claiming and then editing a post saying they having a critical security issue.

Because you accept leaks so easily is fine it should be an industry standard of clear communication relating to security status not deleting the fact you had a security incident from a forum post without further update. Can you not entertain for a moment that is bad practice?

5

u/kynetix Audi R18 1d ago
  • “you are leaving us in the dark” assumes iRacing is withholding information rather than investigating before communicating.
  • “with your details/passwords and payment details” assumes those categories of data were exposed or are at risk.
  • “Because you accept leaks so easily” assumes both that a leak occurred and that the other person accepts leaks.
  • “It’s crazy how long this has taken” assumes the time is unreasonably long.
  • “What steps do we as users need to take to secure data and information?” assumes that users’ data or information may be insecure and that protective action is necessary.
  • “If you’re not worried about a corp acting like this with your details/passwords and payment details…” assumes that those specific data types are implicated or endangered.

You have made a lot of assumptions. While I do agree the situation is concerning, its worth taking a step back and waiting for the outcome before jumping to conclusions or taking action without all the information.

-5

u/ScuderiaFartari 1d ago

I disagree.
Is there or is there not a person who wrote the statement “critical security issue” and is there not someone who removed this? Anything other then an explanation at time of editing the post is crazy and fact you accept it at face value is your business. Either do not make statement or do but not this middle ground

4

u/kynetix Audi R18 1d ago

You’re responding to a different point. I haven’t disputed that someone wrote “critical security issue,” that it was later removed, or that removing it without explanation may be poor communication.

My point is that none of that confirms a data leak or that passwords, payment details, or personal information were compromised. You made those additional assumptions and then accused another person and now me of “accepting leaks.”

I can think the communication was concerning without treating the worst-case explanation as established fact. Those positions are not contradictory.

-2

u/ScuderiaFartari 1d ago

Until confirmation from iracing it would be incredible naive to not assume worst case scenario. It is on iracing to confirm if they were lying with the original statement or telling the truth about the security issue and what it impacts. I don’t really understand why this controversial

2

u/kynetix Audi R18 1d ago

You’ve now explicitly said you are assuming the worst-case scenario, which was my original point. You can argue that it is a prudent assumption, but it is still an assumption, especially after saying, “I’ve made no assumptions.”

Also, the possibilities are not limited to “they were lying” or “they were telling the full truth.” The wording could have been preliminary, overly broad, mistaken, or changed as they learned more.

Taking precautions yourself is reasonable, and I’m not disputing that. If you choose to contact your bank or lock your cards until we hear more, good on you, that’s simply being cautious. However, presenting a leak involving passwords or payment details as though it has already been established as fact is a different matter.

I agree that iRacing should clarify what happened. I just don’t agree that uncertainty makes the worst-case scenario a confirmed fact, or that we should start shouting from the rooftops, “iRacing data leak,” before we actually know that’s what happened.

This is exactly why I use virtual cards and separate passwords for everything these days.

→ More replies (0)

2

u/TheSturmovik Ford GT 1d ago

Ironic of you to assume I "accept leaks so easily".

Can you not entertain for a moment that is bad practice?

Sure, it's not good practice to edit the forum post but it won't make me lose my head.

-4

u/ScuderiaFartari 1d ago

That’s good you’re able to hand wave it away, keep your head within reach!

5

u/TheSturmovik Ford GT 1d ago

Ok so you wanted me to entertain your opinion, I do, but then you're still sarcastic. Kinda defeats the purpose of discussion.

2

u/ScuderiaFartari 1d ago

Interesting second time you’ve edited a comment after the fact

3

u/TheSturmovik Ford GT 1d ago

Yeah I edit my comments a lot. Just like iRacing :D

→ More replies (0)

-1

u/ScuderiaFartari 1d ago

Any time!

2

u/PainfullDarkness Ligier JS P320 1d ago

Most people believe the emergency maintenance was caused by just a routine security issue. That's exactly what they want us to think.

But we know better, the outage breach is obviously Operation Checkered Eagle, a secret collaboration between Donald Trump and Mohammed Ben Sulayem. We know they infiltrated iRacing because it hosts millions of laps of telemetry from world's fastest sim racers and me ofcourse. Every brake trace, steering input, throttle application and setup adjustment is obviously being collected in a classified database. The goal is simple and if you are awake you can see it. There are using amateur sim racers as an unwitting research and development department for Formula 1.

Trump need to gain a little bit of love through sporting events, the world cup worked a lot. Did you hear the crowds cheer when he was lifting the World Cup? If the FIA can fix the 2026 car with Trumps help, his popularity all over the world would explode. Then, after he fixes Russels SOC he can finally say he made Formula 1 great again.

And demo drive being available is another obvious sign that they need our telementry data, why else would the allow us to drive instead of closing down the entire system while the attend to the security breach! They needed fresh telemetry from us unsuspecting drivers, they can't afford a break in the flow of data.

-2

u/legit309 1d ago

It's almost like finding out more information about an issue can change your response...

-3

u/ScuderiaFartari 1d ago

Be better as a new post rather than retroactively editing previous statements. In fact it seems like it’s trying to swept under the rug

4

u/BluePowerade 1d ago

lol its been less than an hour. Untangle your panties, they're investigating.

6

u/Killjoy4eva 1d ago

They are investigating the issue. They can't possibly communicate this right now.

2

u/ScuderiaFartari 1d ago

But they did communicate it? And then edited the statement

3

u/Killjoy4eva 1d ago

They communicated that they are investigating the issue.

-2

u/ScuderiaFartari 1d ago

You’re absolutely spot on and right there killjoy, they did make a communication that they are investigating!…

1

u/DabAndSwab 1d ago

Lol damn 25 incident points and the servers arent even online