Breach Intelligence Report 05 Dec 2024

The RuneScape Boards Leak Means Old Passwords Could Still Work

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash Username Ip Salt
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 211,632
Source Type Database
Origin Darkweb
Password Type VB

The RuneScape Boards Data Breach: What HEROIC Found

HEROIC analysts identified a breach tied to RuneScape Boards, a now-defunct RuneScape fan forum, dated to August 1, 2013. The exposed dataset totals 211,632 records and includes email addresses, usernames, IP addresses, salt values, and passwords hashed with the vBulletin (VB) algorithm. Public reporting on this incident described roughly 224,000 affected users.


Why This Is Dangerous: Old Passwords Rarely Get Retired

Salting a password hash makes it harder to crack in bulk, but it does not make cracking impossible, especially with vBulletin's dated hashing scheme and modern cracking hardware. The real danger here is behavioral, not technical: most people never go back and change a password on a forum they used over a decade ago. If that RuneScape Boards password is still sitting on an active email account or financial login somewhere, this leak is a live threat regardless of how old it is.


What Was Exposed in the RuneScape Boards Leak

  • Email addresses
  • Password hashes (salted vBulletin)
  • Usernames
  • IP addresses
  • Salt values

Why This Matters: Credential Stuffing Doesn't Care About the Calendar

Attackers do not distinguish between a fresh breach and a decade-old one when building credential stuffing lists. Automated tools test every available email and password combination against banking, email, and social platforms regardless of the original breach date. A 2013 forum leak is just as useful to an attacker today as it was the day it happened, provided the credentials still work somewhere.


How a Database Breach Like This Happens

This incident is classified as a database breach, meaning the forum's member table was extracted directly from its server, typically through a software vulnerability or a compromised administrator account. Forums running vBulletin during this period were common targets because of widely known exploits in outdated versions of the software.


Check If You Are Affected

If you were ever a member of RuneScape Boards or a similar gaming forum, it is worth confirming your exposure. HEROIC's free breach scanner checks your email address against more than 400 billion breached records, including this one, so you can find out in seconds and retire any old passwords still in use.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Password Hash, Username, IP Address, Salt
Password Types VB
Date Leaked 05 Dec 2024
Check in 5 seconds

211,632 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,138 scanned today
Breach Rank #3,941 by affected users
Impact Score
8
sensitivity + scale + recency
Est. Financial Impact $1.5M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance