[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1mv9e4kcbsbpb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825146","clash-of-kings","Clash of Kings Data Breach","f.elex.com","2016-07-14T00:00:00.000Z","2019-07-27T22:03:03.000Z","2026-07-29T11:40:53.262Z","Third party breach","https:\u002F\u002Fwww.welivesecurity.com\u002F2016\u002F07\u002F25\u002Fclash-kings-forum-hacked-1-6-million-account-details-put-risk\u002F",[14,16,17],"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002F1-6-million-account-records-stolen-in-clash-of-kings-hack","https:\u002F\u002Fgamesbeat.com\u002Fclash-of-kings-forum-hacked-data-leaked-on-1-6m-accounts\u002F",1604957,"known",null,"unknown","Critical",[24,25,26,27,28,29],"Email addresses","IP addresses","Passwords","Usernames","Social media profiles","Auth tokens","\u003Cp>The Clash of Kings data breach is related to the unauthorized access of user data belonging to the official forum of the popular mobile strategy game in July 2016. This record is tracked across 1,604,957 affected accounts. The incident concerns forum user data rather than the in-game payment system or main game servers. This distinction is important because forum accounts often contain identifying information such as player name, email address, IP address, and password hash, whereas in-game purchases or payment card information are not among the verified data categories in this record.\u003C\u002Fp>\n\u003Cp>The verified main data types are email addresses, IP addresses, usernames, and passwords. The password field is tracked as an MD5 hash; since MD5 is considered weak according to modern security standards, the risk increases if users have used the same password on other accounts. Some external news reports have also mentioned profile information linked to Facebook and access tokens. Therefore, social media connection risk should be considered as a limited additional heading; however, fields such as payment information, official ID, or real name should not be included in the verified scope for this record.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In the Clash of Kings forum breach, email addresses, usernames, IP addresses, and password hashes were exposed together. The email address and username allow attackers to find accounts and send targeted messages. While the IP address does not provide an exact home address, it can give clues about the user's connection region, provider, or session history. In the context of a gaming forum, this information can be used to craft personalized fake events, gifts, account verification, or clan invitation messages for players.\u003C\u002Fp>\n\u003Cp>Storing password hashes with MD5 is the most significant technical risk in this incident. MD5 is a fast-calculating method that is now considered weak; especially short, common, or reused passwords can be quickly guessed. If a user has used the same password on email, gaming accounts, social media, game stores, or other forums, the breach may not be limited to the forum account. For users with social media contact information, an additional risk is matching the gaming forum identity with the social media profile.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified accounts for this record is 1,604,957, and the event date is marked as July 14, 2016. The scope is defined by email addresses, IP addresses, usernames, and password hashes belonging to Clash of Kings forum users. Some publications have mentioned social media-linked fields such as Facebook profile data or access tokens; therefore, social media profiles and access tokens are considered a limited additional risk in the data categories. It should not be assumed that these fields are present for every user.\u003C\u002Fp>\n\u003Cp>In this record, payment card, bank account, real name, physical address, phone number, in-game purchase history, or official identification information is not a verified data class. The impact of forum violations on in-game accounts depends on user behavior: the risk increases if the same password or same email was used, and if a different password was used, the likelihood of direct account takeover decreases. In the explanation, forum data should not be confused with in-game payment or main game account data. The actual risk to the user should be communicated through password reuse, gaming community identity, and social media connections.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The individuals at the highest risk are players who use the password they used on the Clash of Kings forum on other accounts as well. Game accounts, email accounts, social media accounts, and game store accounts should be checked first. People who reuse their player name in different games or forums also carry the risk of profile matching. An attacker can search for the same username and find accounts on other platforms and prepare more personalized phishing messages.\u003C\u002Fp>\n\u003Cp>The risk for users whose IP addresses are visible is more about privacy and targeting rather than direct sensitive identity theft. Connection region and online gaming habits can be used for fake support messages or regional campaign announcements. Users with Facebook-linked areas may also face the risk of associating their gaming forum identity with their social media profile. This situation can particularly lead to a loss of privacy for users who want to keep their nickname separate from their private life.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used on the Clash of Kings forum should no longer be considered secure. Users should first set new and unique passwords for their forum and game accounts, and then for all accounts where the same or similar password was used. The email account is a priority because password reset links for game and forum accounts mostly go to the email. Using a password manager makes it easier to create different and long passwords for each service.\u003C\u002Fp>\n\u003Cp>If login is made with a social media account, connected applications and session permissions should be checked. Unknown or no longer used connections should be removed. Users should be cautious of links in messages themed around Clash of Kings, game rewards, account verification, free resources, event coupons, or clan invitations. No game support should ask for the user's current password or verification code within the message. Suspicious messages should be additionally checked through the official application or known domain.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Although game forums often appear separate from the main game account, they are part of the security chain due to the use of the same email and password. In the long run, players should use different passwords for every game, forum, and social media account, and enable multi-factor authentication where possible. If nicknames are reused across different platforms, the risk of profile matching increases; users should reduce these repetitions if they want to separate their private life from their gaming identity.\u003C\u002Fp>\n\u003Cp>For game companies and community managers, keeping forum software up to date, storing password hashes with strong methods, and tightly securing social media login links are of critical importance. Old forum infrastructures can become a weak link for large player communities. From the users' perspective, the most practical strategy is not to see the forum account as a low-value account, but to evaluate it as part of an identity chain that protects in-game assets and social media profiles.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match found in this record indicates that the relevant email address is among the accounts associated with the Clash of Kings forum data breach. A match does not mean that payment information or real identity documents are included in the verified scope of this record. Verified risk is related to email, IP address, username, password hash, and for some users, social media linked fields. The user should first determine where else the same password has been used.\u003C\u002Fp>\n\u003Cp>After password changes, the login history on email accounts, game accounts, and social media accounts should be checked. Unknown sessions should be closed, connected apps should be reviewed, and security alerts should remain enabled. Messages promising in-game gifts, free resources, or account verification should be verified through official channels even if they appear legitimate. Even if this incident was an old forum breach, its effects can continue many years later due to password reuse and username matching.\u003C\u002Fp>","","Clash of Kings Data Breach (1.6 Million Reported Records)","Clash of Kings Data Breach. 1.6 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ff_elex_com.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":40,"websiteStatus":41,"websiteCheckedAt":42},"Clash of Kings","Mobile game forum","China","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20181227233754\u002Fhttp:\u002F\u002Ff.elex.com\u002F","archived","2026-07-29T11:30:22.391Z"]