Breach Intelligence Report 25 Jul 2022

If You Used RuneScape in 2013, This 189,051-Record Leak Matters

HEROIC
HEROIC Threat Intelligence Team
Ip Address Hash Type Email Username Passwords
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 189,051
Source Type Database
Origin Darkweb
Password Type vB

The RuneScape Data Breach: What HEROIC Found

HEROIC analysts identified a breach tied to RuneScape (runescape.com), dated to August 14, 2013. The exposed dataset totals 189,051 records and includes IP addresses, password hash type metadata, email addresses, usernames, and passwords hashed with the vBulletin (vB) algorithm.


Why This Is Dangerous If You Played RuneScape

If you created a RuneScape-related account around 2013, this leak concerns you directly. vBulletin password hashes are outdated and can be cracked in bulk with modern hardware, and once cracked, the username and email pairs in this dataset become a working login list. Gaming accounts often carry real value, in-game items, subscriptions, and linked payment methods, which makes them a practical target, and any reused password extends the risk to your email or financial accounts too.


What Was Exposed in the RuneScape Leak

  • IP addresses
  • Password hash type metadata
  • Email addresses
  • Usernames
  • Passwords (vBulletin hash format)

Why This Matters: Gaming Credentials Are a Real Target

Attackers actively trade and exploit gaming credentials because accounts often hold tradeable items, in-game currency, or linked purchase histories. Beyond the direct loss of an account, the bigger risk is credential stuffing: automated tools take the email and password pairs from breaches like this one and test them against banking, email, and social media logins, turning a single old gaming leak into a broader identity theft or financial fraud problem.


How a Database Breach Like This Happens

This incident is classified as a database breach, meaning the underlying user table was copied or extracted directly from the server, typically through a compromised system, an unpatched vulnerability, or a misconfiguration. That is different from a stealer log, which comes from malware on an individual's device. A database breach hits every account on the platform at once, which is why the same password hash format appears across the entire 189,051-record leak.


Check If You Are Affected

If you ever had a RuneScape-related account or reuse passwords across sites, it is worth checking your exposure now. HEROIC's free breach scanner checks your email address against more than 400 billion breached records, including this one, so you can find out in seconds whether you were affected.

Breach Breakdown

Domain N/A
Leaked Data IP Address, Hash Type, Email Address, Username, Passwords
Password Types vB
Date Leaked 25 Jul 2022
Check in 5 seconds

189,051 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,138 scanned today
Breach Rank #4,139 by affected users
Impact Score
8
sensitivity + scale + recency
Est. Financial Impact $1.4M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance