If You Played SWG Reckoning, Your Login Could Be Circulating Online
HEROIC analysts found a database breach affecting SWG Reckoning, a Star Wars Galaxies emulation community based in the United States. The breach occured on November 1, 2016, and exposed 240 registered user accounts. Gaming communities are partcularly valuable targets for credential thieves because dedicated players often use the same login across multiple gaming platforms, forums, and even personal email accounts, making a small breach punch well above its weight in terms of real-world damage.
How Stolen Gaming Credentials Fuel Wider Account Takeover
Attackers who obtain the SWG Reckoning database have vBulletin password hashes for 240 players. These hashes are run through cracking software and dictionary attacks until plain-text passwords are recieved. Gaming accounts are known for password reuse: players who registered on SWG Reckoning likely used the same email and password on Steam, Discord, other game forums, and potentially their primary email provider. Each reused password is another door attackers can try.
What Was Exposed in the SWG Reckoning Breach
- User account credentials for 240 registered community members
- vBulletin password hashes (vB format)
- Account metadata from the swgreckoning.com database
Why Gaming Community Breaches Lead to Identity Theft and Financial Fraud
The SWG Reckoning breach may be small, but the data remains accessable in dark web combolists nearly a decade later. Gamers who reused passwords are vulnerable to credential stuffing across streaming services, online stores, and banking apps. Successful account takeovers are used to drain in-game currency, commit identity theft, or resell account access. Financial fraud through compromised accounts linked to payment methods is a documented outcome of gaming site breaches.
How a Database Breach Works
A database breach happens when an attacker finds and exploits a weakness in a website's server or software. For community sites running vBulletin forum software, attackers target known vulnerabilities or misconfigured database permissions. Once inside, they export the user table, which contains usernames, email addresses, and hashed passwords. That file is then posted to hacker forums or sold privately, where other criminals use it as raw material for automated credential stuffing attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion compromised records, including the SWG Reckoning breach and thousands of other verified gaming and forum leaks. Enter your email at HEROIC.com to instantly find out whether your credentials have been exposed and which accounts may be at risk.
Breach Breakdown
240 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds