Runescape
We've been tracking a significant uptick in credential stuffing attacks targeting online gaming platforms, a trend fueled by the increasing availability of stealer logs on Telegram channels. What really struck us about a recent leak wasn't the overall volume, but the targeted nature and the clear evidence of lists compiled specifically for Runescape accounts. The setup here felt different because it included not just usernames and passwords, but also recovery questions and associated email addresses, suggesting a more sophisticated data collection and compilation effort than typical stealer logs.
The Runescape Account Compilations Fueling Account Takeovers
This breach involves a compilation of data specifically targeting Runescape, the popular MMORPG. We discovered evidence of this compilation while monitoring several dark web forums known for trading gaming credentials. What caught our attention was the structured nature of the data and the clear targeting of Runescape accounts, including details that would facilitate account recovery. This matters to enterprises because it demonstrates the ongoing value of gaming accounts on the black market and the sophistication of threat actors in targeting specific platforms. This is a prime example of threat actors using compiled lists to automate account takeovers, highlighting the need for robust multi-factor authentication and account monitoring.
Breach Stats:
* Total records exposed: 700,000+
* Types of data included: Usernames, passwords (likely hashed, but potentially cracked), email addresses, recovery questions and answers.
* Sensitive content types: Potentially in-game assets, financial information associated with accounts (if linked for microtransactions), and PII if users used real information for account creation.
* Source structure: Mixture of formats, likely compiled from various stealer logs and potentially previous breaches. Some data appeared in a structured format, while other entries were raw text dumps.
* Leak location(s): Primarily Telegram channels and a popular hacking forum.
External Context & Supporting Evidence
Several online communities dedicated to Runescape have reported an increase in account hijacking incidents. One Reddit thread noted a spike in users reporting their accounts being accessed from unusual locations and in-game items being stolen. "One Telegram post claimed the files were 'freshly compiled from various sources, including leaked databases and stealer logs, and tested against Runescape login servers'," according to an archived quote.
According to reporting from BleepingComputer, credential stuffing attacks targeting gaming platforms are on the rise, fueled by the availability of leaked credentials and the relative ease of automating attacks. This incident aligns with that trend, demonstrating the effectiveness of compiled lists in targeting specific online services. A recent report from Akamai highlighted the gaming industry as a prime target for credential stuffing attacks, with Runescape being specifically mentioned as a frequent target.
Breach Breakdown
189,051 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds