How the Mortal Online Database Breach Exposed 680K Player Accounts
HEROIC analysts identified the Mortal Online breach as part of a broader review of gaming platform database exposures. In June 2018, the Swedish MMORPG Mortal Online suffered a serious database breach that ultimately exposed 680,137 player accounts. The stolen data included email addresses, unsalted MD5 password hashes, usernames, first and last names, IP addresses, and password salts. What made this breach partcularly alarming was the use of unsalted MD5 hashing, a method widely known to be weak and easy to crack even years before this incident occured.
Why Cracked Password Hashes Put You at Risk Right Now
When attackers get hold of unsalted MD5 hashes, they do not need sophisticated tools to reverse them. Freely available rainbow tables and hash-cracking software can recover the original passwords within minutes. Once those passwords are in hand, attackers test them across email providers, banking apps, and social media accounts. Because many people reuse passwords, a single cracked hash from a 2018 gaming breach can open doors to accounts that are accessable today. Names and email addresses in the same dataset make phishing attacks much easier to pull off as well.
What Was Exposed in the Mortal Online Breach
- Email Address
- Password Hash (unsalted MD5)
- Username
- First Name
- Last Name
- IP Address
- Salt
Why Gaming Breaches Have Long-Lasting Consequences
Many people use the same email and password combination across dozens of websites, including their bank, work email, and social media. A breach from a gaming site years ago can still fuel credential stuffing attacks today. Attackers compile old breach data into massive lists and run automated tools against popular services. Victims rarely know their credentials are being tested until an account is taken over, a fraudulent purchase is made, or their identity is used to open new accounts. The Mortal Online breach is a strong example of how seperate incidents from years past continue to drive real harm in the present.
How a Database Breach Works
A database breach happens when an attacker finds a way into a company's backend systems and extracts stored records. This can happen through unpatched software, weak admin credentials, or vulnerabilities in web application code. Once inside, attackers can copy entire tables of user data without triggering obvious alarms. In the case of Mortal Online, the data included hashed passwords that were stored without the added protection of salting, making them far easier to crack after the fact. The records then tend to circulate on private forums before eventually becoming part of large publicly available breach datasets.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner backed by a database of over 400 billion compromised records. If your email address appeared in the Mortal Online breach or any other incident, you can find out in seconds. Visit the HEROIC breach scanner to check your exposure and take steps to protect your accounts before attackers use your data against you.
Breach Breakdown
680,137 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds