[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2g237vdl8trme":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882516d","CrossFire","Cross Fire Data Breach","cross-fire","cfire.mail.ru","2016-08-08T00:00:00.000Z","2016-12-28T00:29:28.000Z","2026-07-29T11:40:53.262Z","Website hack","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fover-25-million-accounts-stolen-after-mail-ru-forums-raided-by-hackers\u002F",[15,17],"https:\u002F\u002Fwww.ibtimes.co.uk\u002Fhackers-steal-over-25-million-accounts-following-mail-ru-forums-breach-1577905",12865609,"known",null,"unknown","Critical",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>The \u003Cstrong>Cross Fire data breach\u003C\u002Fstrong> is a verified security incident dated 8 August 2016 that affected 12,865,609 forum accounts.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified Cross Fire dataset contained email addresses, usernames and passwords. Passwords were stored as \u003Cstrong>salted MD5 password hashes\u003C\u002Fstrong> rather than readable text, but MD5 is now considered inadequate for password protection, and a unique salt does not make a weak or predictable password safe. Attackers can test common choices offline and try likely results against other accounts created with the same email address or username. Pairing an email address with a forum identity also supports targeted phishing, fake support messages and cross-service account matching. Birth dates, IP addresses or phone numbers reported in other affected forums were not confirmed specifically for the Cross Fire corpus and are excluded from this record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>Three game forums hosted by Mail.ru were targeted during July and August 2016, and their databases were reportedly copied in early August. The cfire.mail.ru Cross Fire forum accounted for 12,865,609 accounts, while the other two forums contributed roughly 8.9 million and 3.2 million records. The figure of more than 25 million widely used in headlines was therefore the combined total, not the population of this Cross Fire record. Attackers were reported to have exploited known SQL injection weaknesses in old, unpatched vBulletin installations to reach the forum databases. Mail.ru said the exposed credentials were old passwords from game-project forums acquired over time, that its games and forums had since moved to secure integrated authorisation, and that the passwords were not connected to Mail.ru email accounts or the company's other services. This prevents a forum-password incident from being misrepresented as a compromise of the main email platform.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The greatest risk falls on people who registered with the Cross Fire forum before the incident and reused the same password elsewhere. Copied data can remain in circulation after a forum closes or its password is changed. If the username and email address also appear on other gaming communities, social networks or an email account, attackers can connect those profiles to one person. Recovering a weak password from an MD5-based hash enables automated credential tests against shopping, messaging, gaming and social-media services. Mail.ru's statement that the forum credentials did not belong to its email service is important, but it cannot prevent a user from having reused the same password on email. Fake prizes, account-verification notices, tournament invitations or penalty warnings can look more convincing when they include an old game identity and accurate breach details.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If a password used on the Cross Fire forum remains valid anywhere else, change those accounts immediately. Prioritise email, password managers, financial services, social networks and gaming accounts that use the same username. Create a \u003Cstrong>strong, unique password\u003C\u002Fstrong> for every service, enable multi-factor authentication wherever available, and prefer an authenticator app or hardware security key when possible. Review active sessions, recovery addresses, forwarding rules and recent sign-ins on associated email accounts, then sign out devices you do not recognise. Adding a number to the old password or changing one small section is not sufficient because automated attacks test predictable variations. Treat game rewards, reset notices and account-closure warnings as suspicious; type the service address into the browser instead of following a message link.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Using a password manager to generate a random credential for every account is one of the strongest ways to stop an old forum breach from spreading to other services. Close gaming and forum accounts that are no longer needed and, where possible, remove stored email, profile and recovery details first. Separating email identities by purpose keeps lower-trust community memberships away from critical accounts and reduces the value of future account matching. Store multi-factor recovery codes offline and avoid recovery answers based on facts visible on social media. Keep devices, browsers and extensions updated, remove software you no longer trust, and leave sign-in alerts enabled. Forum operators should retire unsupported releases, apply security patches promptly and protect passwords with modern, deliberately slow hashing methods. Historical breach monitoring remains useful because old datasets may be republished or combined with later incidents long after the forum disappears.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Check the email address used on the Cross Fire forum with a reputable breach-search service to learn whether it appears in this verified collection. A match does not prove that the password was recovered or that an account is currently controlled by someone else; it confirms that the email address was associated with exposed forum data and that reused credentials should be replaced. No match is not an absolute guarantee because records may be incomplete, a different email address may have been used, or data from the other forums may be held in separate collections. Never enter your email password into a breach-checking page and provide only the information required for the lookup. Review important accounts that use the same address for unexpected sign-ins, unsolicited reset requests or messages referring to an old gaming identity. If anything looks suspicious, change the password, revoke existing sessions and verify recovery settings.\u003C\u002Fp>","","Cross Fire Data Breach (12.9 Million Reported Records)","Cross Fire Data Breach. 12.9 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcfire_mail_ru.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":37,"websiteStatus":38,"websiteCheckedAt":39},"Cross Fire","Gaming forum","Russia","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20200616120003\u002Fhttps:\u002F\u002Fcfire.mail.ru","archived","2026-07-29T11:30:22.391Z"]