[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f94p8j39b2ysg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":33,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882519e","duowan","Duowan.com Alleged Data Exposure","duowancom","duowan.com","2011-01-01T00:00:00.000Z","2016-11-07T12:53:19.000Z","2026-07-02T11:54:02.599Z","2026-07-18T23:50:03.881Z","Alleged database leak","https:\u002F\u002Fsynscan.net\u002Fbreaches\u002Fduowancom",[16,18],"https:\u002F\u002Fwww.troyhunt.com\u002Fhandling-chinese-data-breaches-in-have-i-been-pwned\u002F",2639894,"known",null,"email_identifiers","Critical",[25,26,27],"Email addresses","Passwords","Usernames","\u003Cp>The Duowan.com data breach is an old but still risky account data leak concerning users of a China-based gaming community. The record is considered an incident dated January 1, 2011, and is associated with 2,639,894 accounts. The most important point about this incident is that the data has not been classified as fully verified. While available indicators support that the data contains real user information, due to domain, service name, user habits, and language barriers in old breaches originating from China, it may not be possible to verify all details of the incident with the same certainty.\u003C\u002Fp>\n\u003Cp>For this reason, the Duowan.com record should be evaluated on two levels: On one hand, a dataset containing email address, username, and plaintext password carries a serious account takeover risk; on the other hand, the text should not imply the existence of additional unverified fields. The fact that the incident is dated does not eliminate the risk. A plaintext password means that an attacker can attempt the password directly without needing to go through the hash-cracking stage. If the same password was used on other services, a 2011 game account could still pose a threat today to email, social media, game store, or forum accounts.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>For Duowan.com, the verifiable data classes are email addresses, usernames, and passwords. The fact that passwords are found in plain text makes this breach more risky than just a profile information leak. In hashed password incidents, the attacker would need to crack the password, while in plain text password breaches, brute force and reuse attacks can proceed much more directly. If the user used the same password with their email address on other services, this combination can be used for credential testing.\u003C\u002Fp>\n\u003Cp>The username field should not be neglected either. Nicknames in gaming and forum communities can be reused across different platforms for years. When an attacker sees the email, username, and password together, they not only try the account but may also attempt to match it with other online profiles belonging to the same person. This makes targeted phishing messages, fake account alerts, and links sent under the pretext of an old game account more convincing.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record is a secure scope 2,639,894 account record. The incident is considered to have occurred around the 2011 period and is recorded in the system as of January 1, 2011. In older China-sourced datasets, the exact day of the incident, the method of attack, or an official statement by the company may not always be available. Therefore, Duowan.com’s statement should not include a definitive technical attack scenario, and a limited but careful evaluation should be made based on the existence of the dataset and the verifiable fields it contains.\u003C\u002Fp>\n\u003Cp>In this record, full name, phone number, physical address, IP address, payment card, private message, in-game purchase history, or device information are not verified data classes. The number of rows may appear differently in some secondary archives; however, the main record count shown to the user should be maintained as 2,639,894. The record should not be considered completely fabricated, but since the level of full verification is limited, the text should use cautious security language rather than definitive judgment.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>People in the highest risk group are those who use the password from their Duowan.com or affiliated gaming community accounts on other services. If an email account, social media, game stores, forums, and messaging platforms are protected with the same password, this old leak can lead to new account takeover attempts. People who have not changed their password since around 2011 or who continue to use the same password root with minor changes are at higher risk.\u003C\u002Fp>\n\u003Cp>The second risk group consists of people who use the same username across different game and community accounts. A username alone may not seem sensitive, but combined with an email and password, it can create an account map. For users registered with a corporate email address, the risk is even more significant; because a password from an old game account can be used in automated login attempts or targeted phishing messages against a work account.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in the Duowan.com registration, the first action to take is to stop reusing passwords. If the password used for Duowan.com or a very similar password is used on another account, it should be changed immediately, and a different, strong password should be set for each service. The email account should be prioritized, because password reset links for many services are sent to email, and if the email account is compromised, other accounts are also at risk.\u003C\u002Fp>\n\u003Cp>Using a password manager is the most practical method to avoid repeating old passwords. For accounts that support two-step verification, this feature should be enabled. Users should be cautious of links that come under the pretext of old game accounts, account verification, rewards, penalties, or security alerts. Since old records containing plain text passwords can circulate in the hands of attackers for a long time, it is not enough to only consider the Duowan.com account; all accounts using the same password should be checked.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that old game and forum accounts should not be forgotten in the digital security inventory. Users should close accounts they no longer use, use unique passwords for accounts that cannot be closed, and update their email addresses if possible. Using a single email address across all forums for years makes it easy to link different profiles if a leak occurs. Email aliases dedicated to different purposes and unique passwords weaken this connection in the long term.\u003C\u002Fp>\n\u003Cp>For companies, this record reminds them of the risk that employees using work email on personal accounts may pose. Corporate security teams should consider even old leaks with limited verification levels as signals for password reuse. In employee awareness training, the long-lasting impact of plaintext password leaks should be explained, and measures such as multi-factor authentication and compromised password checks for corporate logins should be maintained regularly.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>An email address included in this record does not by itself prove that the person is a victim of an attack whose details are fully known; however, it is a serious warning that the combination of email, username, and password may have circulated on the internet. Therefore, user action should be clear: retire the old password, abandon similar passwords, review accounts registered with the same email, and enable two-factor authentication on important accounts.\u003C\u002Fp>\n\u003Cp>The correct approach to the Duowan.com data breach is not to generate exaggerated additional claims, but to act quickly on the verifiable risk. Areas such as payment card, phone, address, or private messages should not be added to the verified scope of this record. In contrast, the risk of plaintext passwords should not be underestimated. You can prevent this old record from affecting your current accounts by updating every account where you used the same credentials, strengthening email security, and monitoring suspicious logins.\u003C\u002Fp>","","Duowan.com Alleged Data Exposure (2.6 Million Email Identifiers)","Duowan.com Alleged Data Exposure. 2.6 Million email identifiers were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fduowan_com.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":21},"Duowan.com","Gaming","China"]