RuneHQ Forum Breach: 11,369 RuneScape Player Accounts Exposed
HEROIC's DarkHive intelligence system uncovered the RuneHQ data breach, exposing 11,369 records from the popular RuneScape fan site. The breach occured in March 2008 when the RuneHQ forum database was compromised, exposing email addresses, usernames, IPB-hashed passwords, and IP addresses. RuneHQ served as one of the most comprehensive guides and community hubs for RuneScape players, meaning the affected accounts belong to dedicated members of the gaming community who may have used the same credentials across multiple gaming services.
Why This Is Dangerous
IPB (Invision Power Board) password hashes from 2008 use MD5-based schemes that are highly vulnerable to modern cracking tools. Attackers using GPU-accelerated cracking rigs can process IPB hashes at high speed, particularly for common passwords used by gaming community members. Once cracked, these credentials target RuneScape accounts directly, since many players used the same email and password combination across thier game accounts, forum accounts, and other gaming platforms. RuneScape accounts with valuable in-game items and gold become immediate targets for takeover when forum credentials match game login details.
What Was Exposed
- Email Address
- Username
- Passwords (IPB hash)
- IP Address
- Hash Type
Why This Matters
Gaming community breaches carry unique risks because players often share their forum identity with their in-game identity. RuneHQ members who used the same username and password on the official RuneScape game client faced direct account compromise risk. IP addresses in this dataset reveal where players were located and logged in from, providing attackers with geolocation data useful for social engineering. The RuneScape economy was one of the most active virtual economies of that era, making compromised accounts financially valuable targets. Credential reuse between gaming forums and non-gaming services like email providers means the breach extends well beyond the gaming world.
How Database Breaches Work
Fan sites and gaming community forums running on Invision Power Board software were common targets in the mid-2000s because the platform had known vulnerabilities in older versions that allowed SQL injection attacks. Once attackers exploited these vulnerabilities, they dumped the entire user database including all account credentials. IPB's MD5-based hashing without adequate salting made password recovery relatively straightforward for common passwords. The extracted database was then shared across hacking forums where users interested in RuneScape account theft would extract and crack the credentials to target game accounts directly.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like RuneHQ. Visit heroic.com to scan your email address and find out if your information was exposed. If you were a member of the RuneHQ community before 2008 and recieve a positive result, change your RuneScape account password immediatley if you still have that account active, and update any other accounts where you used the same credentials as your RuneHQ forum login.
Breach Breakdown
11,369 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds