The RuneScape Boards Leak Means Old Passwords Could Still Work
The RuneScape Boards Data Breach: What HEROIC Found
HEROIC analysts identified a breach tied to RuneScape Boards, a now-defunct RuneScape fan forum, dated to August 1, 2013. The exposed dataset totals 211,632 records and includes email addresses, usernames, IP addresses, salt values, and passwords hashed with the vBulletin (VB) algorithm. Public reporting on this incident described roughly 224,000 affected users.
Why This Is Dangerous: Old Passwords Rarely Get Retired
Salting a password hash makes it harder to crack in bulk, but it does not make cracking impossible, especially with vBulletin's dated hashing scheme and modern cracking hardware. The real danger here is behavioral, not technical: most people never go back and change a password on a forum they used over a decade ago. If that RuneScape Boards password is still sitting on an active email account or financial login somewhere, this leak is a live threat regardless of how old it is.
What Was Exposed in the RuneScape Boards Leak
- Email addresses
- Password hashes (salted vBulletin)
- Usernames
- IP addresses
- Salt values
Why This Matters: Credential Stuffing Doesn't Care About the Calendar
Attackers do not distinguish between a fresh breach and a decade-old one when building credential stuffing lists. Automated tools test every available email and password combination against banking, email, and social platforms regardless of the original breach date. A 2013 forum leak is just as useful to an attacker today as it was the day it happened, provided the credentials still work somewhere.
How a Database Breach Like This Happens
This incident is classified as a database breach, meaning the forum's member table was extracted directly from its server, typically through a software vulnerability or a compromised administrator account. Forums running vBulletin during this period were common targets because of widely known exploits in outdated versions of the software.
Check If You Are Affected
If you were ever a member of RuneScape Boards or a similar gaming forum, it is worth confirming your exposure. HEROIC's free breach scanner checks your email address against more than 400 billion breached records, including this one, so you can find out in seconds and retire any old passwords still in use.
Breach Breakdown
211,632 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds