[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjao61vfbvd7l":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda48825193","dota2","Dota 2 Data Breach","dev.dota2.com","2016-07-10T00:00:00.000Z","2024-05-23T06:44:21.000Z","2026-07-09T21:42:38.505Z","2026-07-18T23:49:44.292Z","Website hack","https:\u002F\u002Fwww.helpnetsecurity.com\u002F2016\u002F08\u002F10\u002Fdota-2-dev-forum-breached\u002F",[15,17,18],"https:\u002F\u002Fwww.kaspersky.com\u002Fblog\u002Fdota-2-hack\u002F12767\u002F","https:\u002F\u002Fwww.pcworld.com\u002Farticle\u002F415983\u002Fofficial-dota-2-forum-hack-leaks-2-million-user-passwords.html",1907205,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Email addresses","IP addresses","Usernames","User IDs","Hashed passwords","Passwords","\u003Cp>The Dota 2 data breach is the forum data incident that occurred in July 2016 on dev.dota2.com, Valve's Dota 2 developer forum. The record contains 1,907,205 unique email addresses. Public breach records show that the incident took place on July 10, 2016, and that approximately two million forum accounts were affected. The verified data fields are email addresses, IP addresses, usernames, user IDs, and salted MD5 password hashes. Therefore, the Dota 2 data breach does not mean that the entire Dota 2 game or Steam accounts were compromised; the verified scope is the official developer forum membership data.\u003C\u002Fp>\n\u003Cp>This distinction is important for user security. If the email and password used on the forum account were reused on Steam or other gaming platforms, the risk could spread to other accounts; however, the record does not indicate that it directly contains Steam wallet, game inventory, payment card, or main game account data. The password field is reported not in plain text, but in salted MD5 hash form. Since MD5 is now considered weak, this protection is not strong; it has been reported that a significant portion of weak passwords at that time could be guessed. Therefore, reusing old forum passwords poses a serious risk.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types are email addresses, IP addresses, usernames, user identifiers, and salted MD5 password hashes. When email and username are together, an attacker may try to link the same person with different gaming forums, social profiles, or community accounts. The IP address can provide approximate network and location context. User identifiers technically serve to distinguish the account within the forum and can facilitate account matching when combined with other data fields.\u003C\u002Fp>\n\u003Cp>Password risk is particularly important. Salted MD5 hash is not a plain text password; however, it is weak according to modern password storage methods. Short, common, or reused passwords are predictable. If a forum password is repeated on Steam, email, game store, or other forums, attackers can try the same email and password pair. Therefore, the Dota 2 forum breach should not only be seen as an old forum incident; it should be evaluated in terms of game community identity and password reuse risk.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date is July 10, 2016. The record is associated with 1,907,205 unique email addresses; some reports may mention 1,923,972 records or approximately two million users. This discrepancy arises from the different measurement of the total forum record lines versus the number of unique emails. The main number used on this page is the number of unique emails used in the query. Although the incident has been added to the verified breach records in 2024, the breach itself is the 2016 forum incident.\u003C\u002Fp>\n\u003Cp>The scope should not be expanded. This record is not a verified violation for Steam accounts, Steam Guard, wallet balance, payment cards, in-game item inventory, or Dota 2 game servers. The affected area is the dev.dota2.com developer forum. The password field should also be considered as a salted MD5 hash, not a directly readable password. Nevertheless, due to the weakness of MD5, the risk of password reuse is high. These distinctions provide the user with both the correct security measures and the avoidance of unnecessary panic.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of users who had an account on the Dota 2 developer forum before 2016. People who have used the same username for a long time due to game modes, bug reports, tournament discussions, or developer forum threads are more easily identifiable. Using the same nickname on Steam, Reddit, game forums, or social platforms increases the risk of profile matching. The combination of email and IP address can be used for fake forum alerts or phishing messages themed around gaming communities.\u003C\u002Fp>\n\u003Cp>Players who use the same password in multiple places are also at risk. If an old forum password is still being used on currently active Steam, email, Discord, game store, or other forum accounts, the risk increases. Due to the social value of accounts in gaming communities, in-game items, friends lists, and reputation, attackers can use old data sets even years later. Therefore, the Dota 2 forum breach particularly requires checking old forum passwords and other game accounts linked with the same username.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used on the Dota 2 developer forum should no longer be active anywhere. If the same or similar password has been used on Steam, email, Discord, game stores, or other forums, it should be changed immediately. Steam Guard should be enabled on the Steam account, and two-factor authentication should be enabled on the email account. Without securing the email account, the recovery chain for game accounts is not considered safe. Even if access to the old forum is no longer available, it should be checked whether the same email and password combination exists elsewhere.\u003C\u002Fp>\n\u003Cp>Attention should be paid to fake messages themed around the gaming community. Messages related to your forum account, Dota 2 developer forum, old bug reports, tournament invitations, free items, or account verification should be examined. Instead of clicking on links, you should go directly to the relevant service. Username and IP address information can be used to personalize the message. In this case, since the payment card or game inventory is not verified, the focus should be on password and account recovery security rather than financial panic.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, gaming forums and main game accounts should be separated. Main email addresses and main game passwords should not be used on forum accounts. A password manager makes it easy to generate unique passwords for each forum and gaming service. Using the same username across communities provides recognition, but it also makes it easier for accounts to be linked after a breach. Strong verification, up-to-date recovery information, and regular session checks are required for important game and email accounts.\u003C\u002Fp>\n\u003Cp>From the perspective of platform administrators, the Dota 2 forum incident shows that the methods for storing passwords in older forum software need to be updated regularly. Strong, costly, and up-to-date password hashing methods should be used instead of weak methods like salted MD5. Even if forum and game accounts do not share the same infrastructure, a forum breach can affect the main game account if the user reused the password. Therefore, user notifications should be enabled, password reset processes should be carried out quickly, and old forum systems should be regularly audited.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in this record, your email address may have been among the 1,907,205 unique emails associated with the Dota 2 developer forum data breach. This match does not mean that your Steam account, in-game items, or payment information has been compromised. However, it indicates that fields such as email, IP address, username, and salted MD5 password hash may have been exposed. The first step is to identify where else you reused the forum password you used during the 2016 period.\u003C\u002Fp>\n\u003Cp>If your old Dota 2 forum password is still used on any account, change it. Enable additional verification on your Steam, email, and game community accounts. Be cautious of personalized messages coming from your old username. The correct approach to a Dota 2 data breach is not to exaggerate the incident as a violation of the entire Valve or Steam ecosystem, but to secure old password reuses and game community accounts according to verified data areas within the developer forum.\u003C\u002Fp>","","Dota 2 Data Breach (1.9 Million Reported Records)","Dota 2 Data Breach. 1.9 Million reported records were reported. Reported data: Email addresses, IP addresses, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdev_dota2_com.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Dota 2 Dev Forum","Gaming","United States"]