[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f32yvcxxv9oq9r":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":32,"seoTitle":33,"seoDescription":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"6a452308a20f867c8ba8e74c","divine-skins","Divine Skins Data Breach","divineskins.gg","2026-03-13T00:00:00.000Z","2026-03-15T05:18:40.000Z",null,"2026-07-02T04:54:06.978Z","2026-07-19T00:02:58.431Z","Gaming custom skins account and purchase data breach","",[],105814,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30,31],"Email addresses","Purchases","Usernames","\u003Cp>The Divine Skins data breach was confirmed on March 13, 2026, with the exposure of user records associated with the League of Legends skin service. The record covers 105,814 unique email accounts. The verified data types include email addresses, usernames, and purchase history. It was reported that some systems of the service were accessed without authorization, contents in the skin database were deleted, and user communication records along with purchase information were exposed. Passwords, payment cards, phone numbers, physical addresses, or game account access keys are not included in the verified data classes of this record; nevertheless, the gaming community and purchase context generate a high risk for fake support and refund fraud.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data types listed in this record are the fields Email addresses, Purchases, and Usernames. When the email address and username are found together, attackers can identify the player's identity within the community and investigate forums, games, streaming, or chat accounts where the same username is used. Purchase history makes fake returns, fake download links, fake license renewals, fake cosmetic updates, or fake account support messages more convincing. Since passwords and payment cards are not verified, the incident should not be presented directly as payment theft; however, past purchase information increases the risk of targeted phishing, as it shows that the user genuinely interacted with the service. In gaming communities, trust is usually established through the username and past transaction context, so this dataset can be valuable for social engineering.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main metric is 105,814 unique email accounts. Data classes are limited to email, username, and purchase information. Game account passwords, Divine Skins account passwords, payment card numbers, bank accounts, phone numbers, addresses, identification documents, or game client access keys have not been verified in this record. Purchase history is not the same as actual payment card data; it can show which product or service users have interacted with, but it does not mean the card number has been exposed. Although the event has been announced in the service's community channel, this record is based only on verified personal fields. Therefore, the risk description should be framed not as the account password being compromised, but as the possibility of generating fake support, fake download, and fake refund messages through email and username.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk consists of those who use Divine Skins, are interested in League of Legends special appearance services, use the same username across different gaming communities, and have previously made purchases. The risk of matching increases if the username is the same as on social media, streaming platforms, or chat accounts. People with a purchase history may be targeted with fake refund, fake account credit, fake premium access, or lost skin recovery messages. Younger players, users who participate in community events, and those who frequently use mod\u002Fskin download links are at higher risk.If the same email address appears in other game leaks, attackers can combine the username, game preferences, and past purchase information to create more convincing account takeover attempts. Community managers and content creators should also be cautious of brand impersonation messages.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, make sure you use a unique password for Divine Skins and associated game\u002Fcommunity accounts. Even if the password field is not verified, fake login, fake account support, or fake refund messages can be sent using your email and username. Before clicking on links in messages containing purchase refunds, custom skin restoration, account credit, free skins, new download links, or security verification, manually open the official website address. Pay special attention to file download links; game mods and custom skin files can be used to distribute malware. If you use the same username elsewhere, review your profile visibility and security settings. Enable multi-factor authentication on your game account, email account, and store accounts where you make payments.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In gaming communities, usernames, email addresses, and purchase history generate context for a long time. Users should avoid repeating the same username across games, forums, chat, and streaming platforms, or at least use different names on high-risk accounts. Using separate email aliases for third-party mods, custom skins, or download services reduces the likelihood of future leaks being linked to main accounts. Purchase and refund messages should only be checked through known account panels, and file downloads should be limited to trusted sources. Access to user purchase history should be restricted by service providers, old records should be minimized, and community announcements should be delivered through signed and verifiable channels. User training should particularly cover scenarios involving fake support, fake refunds, and fake download links.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>LeakData check shows whether your email address is included in the Divine Skins leak. A positive result does not mean that your password or payment card has been exposed; it indicates a confirmed risk relation between the email address, username, and purchase history. User actions include checking game accounts that use the same email and username, changing similar passwords, being cautious of fake refund and download messages, and not opening file links without verification. If the same email address also appears in other game, forum, or store leaks, the risk increases; attackers may combine the purchase context in this record with passwords or social profiles from other leaks. Therefore, regular breach checks serve as a practical early warning to protect identity and account security in gaming communities.\u003C\u002Fp>","Divine Skins Data Breach (105.8 Thousand Reported Records)","Divine Skins Data Breach. 105.8 Thousand reported records are reported. Reported data: Email addresses, Purchases, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdivineskins_gg.webp",false,{"name":38,"sector":39,"country":16,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"Divine Skins","Gaming"]