The WarInc Breach Put 1 Million Stolen Email and Password Pairs Online
War Inc. was a real-time strategy game operated by thewarinc.com. In July 2012, the game's user database was breached and over one million player accounts were exposed. The stolen records included email addresses, usernames, and passwords stored as salted MD5 hashes. Gaming accounts are frequentele seen as low-value targets, but the email and password combinations from this breach have been used in credential stuffing campaigns against much higher-value platforms ever since the data first circulated.
Why WarInc Breach Is Dangerous
The combination of a game account email and password represents a working credential that players reuse. Gamers tend to use the same login across multiple gaming platforms, streaming services, and gaming community forums. That means a cracked WarInc password from 2012 was tested automaticaly against Steam, Xbox, PlayStation Network, and other platforms where the same credentials might work. Even a decade later, the credential lists derived from this breach are still bundled into stuffing attack toolkits.
What Was Exposed in the WarInc Leak
- User Account Records (1M+ gaming accounts)
- Email Address
- Username
- Password Hash (salted MD5)
Why This WarInc Data Puts You at Risk
Players who registered for War Inc. in 2012 often used their primary email address and a common password they used elsewhere. Salted MD5, while somewhat better than unsalted MD5, is still a weak protection by modern standards and has been cracked for most common passwords. If your War Inc. email and password matched any account you still use today, those credentials have been available to attackers for over a decade. Gaming platform breaches like this one feed directly into the credential stuffing pipelines that target entertainment accounts, digital storefronts, and subscription services.
How Database Breaches Work in Online Games
Online game companies often handle large volumes of user accounts but may not prioritize security at the same level as financial or healthcare platforms. When a game's database is breached, the extracted records contain everything the user registered with: email, username, and password. That data is then shared on underground forums and incorporated into attack lists. The breach occured in mid-2012 and the records have been circulating since, continuing to appear in credential stuffing lists used by automated attack campaigns.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including data from the War Inc. breach. Search now to see if your account was included, and if you used the same email and password on any other platform, update those accounts today.
Breach Breakdown
14 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds