If You Played R2Games, 19 Million Passwords May Be Exposed
HEROIC analysts identified a database breach connected to R2Games, a free-to-play online game publisher, dated October 31, 2015. The breach exposed 19,129,431 records, including usernames, email addresses, IP addresses, and passwords protected with vBulletin (vB) hashing.
Why the R2Games Breach Is Dangerous
vBulletin's hashing method has known weaknesses that make cracking large batches of passwords realistic for anyone with the right tools. At over 19 million exposed accounts, even a modest crack rate produces millions of working email and password pairs, which attackers can use directly against R2Games accounts or test against other services.
What Was Exposed in the R2Games Leak
- Usernames
- Email addresses
- IP addresses
- Passwords, protected with vBulletin hashing
Why This Matters
Gaming accounts often carry real value, from purchased in-game currency to rare items, which makes them a direct target for account takeover beyond simple credential stuffing. If you played R2Games and reused that password anywhere else, from email to shopping accounts, this breach puts those accounts at risk too.
How Database Breaches Like This Happen
A database breach means an attacker gained direct access to R2Games's backend storage and extracted the user table in bulk. A breach of this scale, over 19 million records, reflects how quickly a single vulnerability in a widely used platform can expose an enormous number of accounts at once.
Check If You Are Affected
If you ever played an R2Games title, check your exposure today. HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including this one, in seconds.
Breach Breakdown
19,129,431 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds