The InnoGames Leak Could Unlock Your Email, Bank, and Social Media
HEROIC analysts recieved the InnoGames dataset during a scan of gaming-related breach compilations circulating on dark web forums. The breach, which occured in June 2016, exposed 600,042 records from InnoGames, a German browser gaming company known for titles like Forge of Empires and Tribal Wars. The leaked data included email addresses, usernames, IP addresses, password hashes using MD5 with a salt, and the raw salt values themselves. MD5 is no longer considered a secure hashing method, and with the salt values also included in the leak, the passwords in this dataset are more at risk than in most breaches.
How the InnoGames Breach Could Unlock Your Email, Bank, and Other Accounts
The InnoGames breach does not stop at gaming. Because the leaked data includes email addresses alongside crackable MD5 password hashes, an attacker who cracks one password can immediately try it against the email account associated with it. From there, they can request password resets on banking apps, shopping accounts, and social media. A single cracked InnoGames password can create a chain reaction that reaches far beyond gaming into financial fraud and full identity theft.
What Was Exposed in the InnoGames Breach
- Email Address
- Password Hash
- Username
- IP Address
- Salt
Why 600,000 Crackable Hashes Still Pose a Real Threat Today
Many people beleive that because a breach happened years ago it no longer presents danger. With InnoGames, that assumption is seperate from reality. MD5 hashes, even with salting, can be reversed with modern computing power in a matter of hours or days. Credential stuffing attacks using this data have been observed across gaming and non-gaming platforms alike. Account takeover, identity theft, and financial fraud are all direct outcomes from this type of breach when users have not updated their passwords.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to the server that stores a website's user data. The entire database is exported at once, capturing every registered user in a single operation. That file is then sold or traded in underground markets. Because the InnoGames breach included both password hashes and the salt values used to generate them, even the partial protection that salting provides is reduced in this case.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including the full InnoGames dataset. Visit HEROIC.com to run a scan and find out exactly which breaches include your data and what to do next.
Breach Breakdown
600,042 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds