[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3jgvplpo95jq1":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda48825124","bot-of-legends","Bot of Legends Data Breach","botoflegends.com","2014-11-13T00:00:00.000Z","2016-12-27T08:24:52.000Z","2026-07-09T17:06:46.755Z","2026-07-18T23:46:26.183Z","Third party breach","https:\u002F\u002Fbreaches.sencode.co.uk\u002Fbreaches\u002Fbotoflegends",[15,17],"https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fbot-of-legends-2014",238373,"known",null,"unknown","High",[24,25,26,27,28],"Email addresses","IP addresses","Passwords","Usernames","Website activity","\u003Cp>The Bot of Legends data breach stems from IP.Board forum records of the third-party League of Legends bot community known by the domain botoflegends.com. The incident was recorded on November 13, 2014, and the confirmed impact is 238,373 user accounts. This record should not be interpreted as a breach of official League of Legends or Riot Games accounts; the affected service is the bot and forum community associated with the game.\u003C\u002Fp>\n\u003Cp>The significance of the breach in terms of security is the simultaneous exposure of forum login information and user activity fields. The verified data classes are email addresses, IP addresses, passwords, usernames, and website activity. Passwords were reported to have been stored as salted MD5 hashes. While the use of salt makes some direct matches more difficult, MD5 is considered weak for current password storage expectations; the risk persists especially for reused or short passwords.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In this record, email addresses, IP addresses, usernames, password hashes, and website activity have been verified. When email and username are combined, the forum ID can be matched with other game, social media, or community accounts. IP addresses provide limited technical signals about connection region and past session habits. Website activity can reveal a user's presence or interests in the bot community.\u003C\u002Fp>\n\u003Cp>Passwords being stored in salted MD5 form does not mean that the plain text password is directly exposed; however, it is risky for users who choose weak passwords or reuse the same password on other accounts. In gaming communities, it is common for the same email and username to be used across many different platforms. Therefore, attackers may use old forum data to try on email accounts, game accounts, or social media accounts.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope for the Bot of Legends registry includes 238,373 accounts and five data classes: email addresses, IP addresses, passwords, usernames, and website activity. Date of birth, real name, phone number, physical address, payment information, game account content, or official game account password are not among the verified data classes for this registry. This distinction is important to avoid associating the breach with the wrong brand or account type.\u003C\u002Fp>\n\u003Cp>The incident concerns forum records on the IP.Board forum infrastructure. Therefore, the explanation should be limited to Bot of Legends forum membership data. It makes sense for users to take precautions for the security of their game accounts; however, the record does not directly prove that official game account data has been exposed. The number in the record indicates unique account impact and may not correspond to the same meaning as the raw forum lines.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>In the highest risk group, there are users who reuse the email, username, and password they use on the Bot of Legends forum on other games or social accounts. Membership in third-party bot communities may also be perceived as sensitive for some users in terms of reputation or account policy. Therefore, web activity and username fields can pose not only a technical account takeover risk but also a profile matching and targeted harassment risk.\u003C\u002Fp>\n\u003Cp>Passwords used on old gaming forums can be forgotten for years; however, the same password pattern may continue to exist on other accounts. If email accounts, game stores, forums, chat platforms, and social media accounts are protected with the same or similar passwords, the risk increases. IP address and username information can also help attackers prioritize which accounts to try.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who are matched should first identify the password they used on the Bot of Legends forum and any other accounts where the same password pattern is repeated. If the same or a similar password is still used on another account, it should be changed immediately. Email accounts, game accounts, game stores, social media, and chat platforms should be prioritized. Unique, long passwords stored with a password manager should be used for each account.\u003C\u002Fp>\n\u003Cp>Users should be careful against fake warnings themed around game account security or bot usage. Instead of logging in through incoming links, they should go directly to the relevant service, avoid opening unexpected files, and update account recovery information. Two-factor authentication should be enabled on critical game and email accounts, and old password variations used on forums should now be abandoned.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Bot of Legends incident shows that game forums and third-party tool communities also carry significant account security risks. Users should now regularly review game forums, bot communities, and old plugin sites that they no longer use. Accounts that can be closed should be closed, and for those that cannot be closed, a unique password should be used, and public usernames and profile information should be stripped of unnecessary details.\u003C\u002Fp>\n\u003Cp>Security in gaming communities is not limited to the main game account alone. When the same email, username, and password pattern are reused across different forums, a small community breach can turn into a larger account takeover risk. Users applying a password manager, multi-factor authentication, leaked password checks, and old account cleanup together provide long-term protection.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match with the email address in this record indicates that the user is included in the Bot of Legends forum dataset. The user should first identify the password they used on this forum and review other game or forum accounts opened with the same email and username. Even if the password is not remembered, old password patterns used in 2014 and earlier should be considered risky.\u003C\u002Fp>\n\u003Cp>The match does not indicate that the official game account has been directly compromised; however, the exposure of salted MD5 password hash, email, IP, username, and web activity together is enough of a security warning. Using a unique password, two-factor authentication, checking incoming game security messages directly from a trusted channel, and closing old forum accounts are steps that reduce the risk of account takeover and profile matching that could arise from the Bot of Legends breach.\u003C\u002Fp>","","Bot of Legends Data Breach (238.4 Thousand Reported Records)","Bot of Legends Data Breach. 238.4 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fbotoflegends_com.webp",false,{"name":36,"sector":37,"country":30,"website":9,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":20},"Bot of Legends","Gaming bot forum"]