DragonNest
We've been tracking a noticeable uptick in database leaks targeting online gaming communities, often fueled by credential stuffing attacks and resale of stolen account data. What really struck us about this particular incident wasn't the size of the breach, but the age of the game involved and the dedicated community still active around it. The data had been circulating quietly on a few obscure forums, but we noticed a sudden spike in mentions across several Telegram channels known for trading gaming assets and compromised accounts. The setup here felt different because the database appeared relatively untouched, suggesting it hadn't been widely exploited previously.
The DragonNest Data Dump: 1.6M Accounts Exposed from the 2017 Breach
A database purportedly belonging to the online role-playing game DragonNest has resurfaced, containing over 1.6 million user accounts compromised in a 2017 breach. The game, originally released in 2010, still maintains a dedicated player base. This resurgence highlights the long tail risk associated with older breaches where the initial impact may have been limited, but the data can still be valuable years later for account takeover attempts.
Our team first detected chatter about the database on March 8, 2024, across several Telegram channels associated with buying and selling stolen gaming accounts. The unusual aspect here was the specific mention of the DragonNest database, which hadn't been actively traded in public forums for years. Further investigation revealed a leaked database file shared on a lesser-known hacking forum, seemingly originating from the 2017 breach that was previously reported by several gaming news outlets.
This incident caught our attention because it underscores a recurring theme: older breaches, often forgotten, can resurface and pose a renewed threat. The data had been circulating quietly, but the recent spike in mentions across Telegram channels suggests a renewed interest, potentially driven by attackers looking for easy targets or attempting to brute-force accounts on other platforms using the leaked credentials. This matters to enterprises now because it demonstrates the persistent risk of old breaches and the importance of continuous monitoring for leaked credentials, even those associated with seemingly defunct services.
- Total records exposed: 1,672,339
- Types of data included: Email addresses, usernames, hashed passwords (primarily MD5), security questions and answers, IP addresses, dates of birth.
- Sensitive content types: Potentially PII from security questions/answers.
- Source structure: SQL database dump.
- Leak location(s): Telegram channels, private hacking forums.
- Date of first appearance: 2017 (original breach), resurfaced in March 2024.
Gaming news sites reported on the original breach in 2017. For example, MMOBomb covered the breach, noting the potential for phishing attacks and account compromise. The use of MD5 hashing for passwords, while common at the time, is now considered weak and easily crackable, further increasing the risk to affected users. This breach also aligns with a broader trend of attackers targeting older online games with active communities, as these often represent easier targets with less robust security measures compared to modern AAA titles. The open-source tool, "Hashcat," is often used to crack MD5 hashes, making the DragonNest credentials a prime target for attackers. One Telegram post claimed the files were "a goldmine of untouched accounts ready for reselling".
Breach Breakdown
435,585 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds