The Tunngle Breach Happened in 2015. 7.6 Million Records Are Exposed.
HEROIC analysts identified 7,693,118 exposed records tied to a Tunngle data breach dated August 31, 2015. Tunngle was a virtual LAN gaming network that let players connect to online multiplayer games over the internet. The exposed data includes names, email addresses, IP addresses, and password hashes, and it took years for this breach to surface widely after its original date.
Why the Delay Between the Tunngle Breach and Its Discovery Matters
This breach is dated back to 2015, yet it was not added to HEROIC's breach records until years later. That gap is common with older services, especially ones that quietly shut down or stopped actively monitoring their systems. Attackers know that older breaches tend to fly under the radar because most people assume a service they stopped using long ago is not worth worrying about. That assumption is exactly what makes this kind of delayed exposure dangerous. Passwords and personal details from 2015 are still valid attack material today if they were ever reused on a current account.
What Was Exposed
- Email addresses
- IP addresses
- Salt values
- First names
- Last names
- Password hashes (SHA1)
Why This Matters
With more than 7.6 million records involved, this is a large scale exposure of full names, email addresses, and password hashes together. SHA1 is an older hashing algorithm that, unlike modern methods, can be cracked relatively quickly with today's computing power, especially when combined with the salt values that were also exposed. Once cracked, these passwords become usable for credential stuffing attacks against other accounts, and the combination of a real name with an email address and IP address gives attackers enough detail to attempt identity theft or highly targeted phishing.
How a Database Breach Exposes Names and Password Hashes Together
This incident is classified as a database breach, meaning the data was extracted directly from Tunngle's stored records rather than gathered through malware on individual computers. Breaches like this typically happen when attackers exploit a vulnerability in the platform's backend, gain access through compromised administrative credentials, or find a database left exposed without adequate protection. The presence of salted SHA1 password hashes shows Tunngle made some effort to protect user passwords, but that protection weakens significantly once the hashes and their matching salts are both in attacker hands.
Check If You Are Affected
If you ever created a Tunngle account for online gaming, it is worth checking whether your information appears in this breach. HEROIC's free breach scanner searches more than 400 billion leaked records to show you where your email address, name, or password may have been exposed. Run a free scan today to see your full exposure and secure any accounts using a password from this breach.
Breach Breakdown
7,693,118 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds