The VNG Breach Quietly Exposed 25 Million Accounts With Full Details
HEROIC analysts identified a database breach tied to VNG, a Vietnamese online services company, exposing 25,080,873 records. The breach is dated to May 19, 2015. The exposed data includes email addresses, first and last names, usernames, phone numbers, password hashes, IP addresses, and birthdays. Passwords in this dataset were hashed using the outdated and unsalted MD5 algorithm.
Why This Much Personal Detail in One Breach Is Especially Dangerous
Most breaches expose a narrow slice of a person's identity. This one is different. Full name, phone number, birthday, email address, and IP address together form nearly a complete identity profile, and unsalted MD5 password hashes can be cracked quickly using widely available tools and precomputed lookup tables. When an attacker can pair a cracked password with a real name, phone number, and birthday, they have what they need to impersonate the victim convincingly, not just log into an old account.
What Was Exposed in the VNG Breach
- 25,080,873 total exposed records
- Email addresses
- First and last names
- Usernames
- Phone numbers
- Password hashes, using the unsalted MD5 algorithm
- IP addresses
- Birthdays
Why This Matters for VNG Users
Full name, phone number, and birthday are exactly the kind of details many companies use to verify a customer's identity over the phone or online. In the wrong hands, that combination can support identity theft, account recovery fraud, and SIM-swap attempts against a victim's phone number. Add a cracked password into the mix, and credential stuffing against other accounts becomes possible too, opening the door to account takeover and financial fraud well beyond the original VNG account.
How Unsalted MD5 Password Hashes Fall Apart
MD5 is a fast hashing algorithm that was never designed to resist modern cracking hardware, and without a unique salt added to each password before hashing, identical passwords produce identical hashes across the entire dataset. That means attackers can use precomputed tables to crack huge numbers of passwords at once rather than one at a time, which is exactly what makes a breach of this size so much more dangerous than a smaller, better-protected one.
Check If Your Information Was Exposed in This Breach
Breaches like this one continue to circulate on dark web forums long after they originally occurred, so it is worth confirming whether your information was part of this exposure. HEROIC's free breach scanner checks your email address against a database of more than 400 billion breached records, including this one, so you can find out quickly and take action if needed.
Breach Breakdown
25,080,873 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds