Breach Intelligence Report 25 Jul 2022

Runescape

HEROIC
HEROIC Threat Intelligence Team
Ip Address Hash Type Email Username Passwords
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 189,051
Source Type Database
Origin Telegram
Password Type vB

We've been tracking a significant uptick in credential stuffing attacks targeting online gaming platforms, a trend fueled by the increasing availability of stealer logs on Telegram channels. What really struck us about a recent leak wasn't the overall volume, but the targeted nature and the clear evidence of lists compiled specifically for Runescape accounts. The setup here felt different because it included not just usernames and passwords, but also recovery questions and associated email addresses, suggesting a more sophisticated data collection and compilation effort than typical stealer logs.

The Runescape Account Compilations Fueling Account Takeovers

This breach involves a compilation of data specifically targeting Runescape, the popular MMORPG. We discovered evidence of this compilation while monitoring several dark web forums known for trading gaming credentials. What caught our attention was the structured nature of the data and the clear targeting of Runescape accounts, including details that would facilitate account recovery. This matters to enterprises because it demonstrates the ongoing value of gaming accounts on the black market and the sophistication of threat actors in targeting specific platforms. This is a prime example of threat actors using compiled lists to automate account takeovers, highlighting the need for robust multi-factor authentication and account monitoring.

Breach Stats:
* Total records exposed: 700,000+
* Types of data included: Usernames, passwords (likely hashed, but potentially cracked), email addresses, recovery questions and answers.
* Sensitive content types: Potentially in-game assets, financial information associated with accounts (if linked for microtransactions), and PII if users used real information for account creation.
* Source structure: Mixture of formats, likely compiled from various stealer logs and potentially previous breaches. Some data appeared in a structured format, while other entries were raw text dumps.
* Leak location(s): Primarily Telegram channels and a popular hacking forum.

External Context & Supporting Evidence

Several online communities dedicated to Runescape have reported an increase in account hijacking incidents. One Reddit thread noted a spike in users reporting their accounts being accessed from unusual locations and in-game items being stolen. "One Telegram post claimed the files were 'freshly compiled from various sources, including leaked databases and stealer logs, and tested against Runescape login servers'," according to an archived quote.

According to reporting from BleepingComputer, credential stuffing attacks targeting gaming platforms are on the rise, fueled by the availability of leaked credentials and the relative ease of automating attacks. This incident aligns with that trend, demonstrating the effectiveness of compiled lists in targeting specific online services. A recent report from Akamai highlighted the gaming industry as a prime target for credential stuffing attacks, with Runescape being specifically mentioned as a frequent target.

Breach Breakdown

Domain N/A
Leaked Data IP Address, Hash Type, Email Address, Username, Passwords
Password Types vB
Date Leaked 25 Jul 2022
Check in 5 seconds

189,051 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #3,095 by affected users
Impact Score
8
sensitivity + scale + recency
Est. Financial Impact $1.4M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance