The GAMEVIL Breach Contains Exactly 726,149 Records Including Birthdays and IP Addresses
HEROIC analysts identified the GAMEVIL forum database breach, which exposed 726,149 user records in May 2020. The South Korean mobile game developer's forum leak included email addresses, usernames, IP addresses, birthdays, vBulletin MD5 password hashes, and their associated salts. The combination of birthdates with email addresses and recoverable password hashes makes this dataset partcularly useful for identity verification bypass attacks, where attackers supply personal details to prove account ownership on other platforms.
Birthdays and IP Addresses Alongside Passwords Create Identity Fraud Conditions
When a breach includes birthdates alongside email addresses and password hashes, it goes beyond a simple credential leak. Attackers can use the birthday data to answer security questions, pass identity verification checks, and impersonate victims on financial services, gaming storefronts, and account recovery flows. The recieved IP address data further links each account to a network location, enabling more targeted follow-on campaigns against known users.
What Was Exposed in the GAMEVIL Breach
- Email Address
- Password Hash
- Username
- IP Address
- Birthday
- Salt
Why 726,000 Gaming Accounts With PII Create Long-Term Fraud Risk
GAMEVIL is a mobile game developer with a global player base. The 726,149 exposed accounts include users from across multiple countries, and their personal details have been circulating since 2020. Accounts in the gaming sector are frequently targeted for virtual currency theft, unauthorized in-app purchases, and resale on gray markets. The occured breach combined with the exposed birthdays creates fraud risk that extends well beyond the original platform and into any service where victims reused their credentials or personal details. vBulletin MD5 hashes, even when salted, are accessable to modern cracking tools given enough time.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a platform's stored data, often by exploiting an unpatched vulnerability in the forum software or web application layer. Forum platforms like vBulletin have historically been targeted due to widely known vulnerabilities. Once inside, the attacker copies the user database table and distributes it through underground markets. MD5-based password hashing, even with salts, is considered inadequate by modern security standards and can be cracked with GPU-accelerated tooling.
Check If Your Data Was Exposed
HEROIC's free breach scanner covers more than 400 billion compromised records. Search your email address now to find out whether your account appeared in the GAMEVIL breach or any of thousands of other known incidents, and take action to protect yourself today.
Breach Breakdown
726,149 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds