67,468 Real Names. One Database Dump. The mmokings Breach Had Your Full Identity.
HEROIC analysts recieved and confirmed a database dump tied to mmokings, an Australian online marketplace for in-game currency and virtual items. The breach occured on April 30, 2016 and exposed 67,468 user records. What makes this dataset particularly concerning is the inclusion of real names alongside email addresses and MD5 password hashes. Unlike many gaming forum breaches that only include usernames, this one gives attackers both your identity and your login credentials, making phishing and social engineering attacks far more convincing and targeted.
What Attackers Can Do With Your Name, Email, and Password Hash
When a breach contains first names, last names, and email addresses together, attackers can craft phishing messages that address you by name and reference your actual account. This makes fake emails much harder to recognize as scams. On top of that, MD5 password hashes are among the easiest to crack with modern tools. Once the password is recovered, it gets tested across other platforms you might use. Victims who are seperate from this community but reused credentials are still at risk from identity theft, account takeover, and financial fraud.
What Was Exposed in the mmokings Breach
- Email Address
- Username
- First Name
- Last Name
- Password Hash (MD5 format)
Why Real Names in a Breach Make Every Scam More Dangerous
Most people beleive they can spot a phishing email. But when an attacker already knows your name, your email provider, and possibly the password you tend to use, the message they send looks nothing like a generic scam. It looks like a legitimate security alert or account notice. This is partcularly true for breaches like mmokings that expose personal identity information alongside credentials. The combination opens the door to targeted fraud, account takeovers, and in some cases, full identity theft.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to the back end of a website, usually by exploiting an unpatched software vulnerability or weak server configuration. Online marketplaces like mmokings store customer details in structured databases so they can manage accounts, orders, and logins. Once an attacker copies that database, every record in it, including names and passwords, is immediately available to them and can be sold or used in attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion records, including the mmokings database, to tell you whether your email address appears in any known data breach. Check your exposure in seconds and find out if your credentials are already being used against you.
Breach Breakdown
67,468 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds