The Deathly Souls Breach Gave Hackers What They Need to Drain Accounts
Deathly Souls was a US-based online community centered on the RuneScape gaming universe. On March 19, 2012, the site suffered a database breach that exposed 15,313 user accounts. The stolen records included email addresses, usernames, IP addresses, hashed passwords, and hash type data. Passwords were stored using vBulletin's hashing format, which has been widely cracked by modern tools over the years since this breach occured.
Why Deathly Souls Breach Is Dangerous
The combination of email addresses, usernames, hashed passwords, and IP addresses in one dump gives attackers multiple angles of attack. vBulletin password hashes from 2012 have largely been cracked already. Once cracked, those credentials get tested automaticaly against email providers, gaming platforms, and social media accounts. IP addresses from this era also help attackers connect historical identities to current online profiles, making targeted attacks more precise.
What Was Exposed in the Deathly Souls Leak
- Email Address
- Username
- Passwords
- IP Address
- Hash Type
Why This Deathly Souls Data Puts You at Risk
RuneScape communities attracted dedicated players who often used the same username and password across multiple gaming forums and accounts. If you were a Deathly Souls member and reused that email and password on other services, those accounts have been at risk for over a decade. The data has been circulating on dark web forums since 2012, meaning it has been available immediatly to anyone running credential stuffing campaigns against other platforms.
How Database Breaches Work
In a database breach, an attacker gains unauthorized access to a site's backend and extracts user records. At Deathly Souls, the attacker exploited a vulnerability in the vBulletin forum software and pulled every registered user's email, username, IP address, and hashed password. That data was then distributed on dark web forums where it continues to be traded and resold, appearing in new credential stuffing lists years after the original incident.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including data from the Deathly Souls dump. Search now to see if your account was part of this breach, and update any passwords you've reused since 2012.
Breach Breakdown
15,313 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds