[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3j9ep3fszqn00":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488251ad","epal","E-Pal Data Breach","e-pal","epal.gg","2022-04-15T00:00:00.000Z","2022-10-24T04:54:30.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:12.388Z","Platform breach","https:\u002F\u002Fwww.redpacketsecurity.com\u002Fe-pal-108-887-breached-accounts\u002F",[16,18,19,20],"https:\u002F\u002Fwww.epal.gg\u002F","https:\u002F\u002Fpolicies.epal.gg\u002Fprivacy","https:\u002F\u002Fwww.trustpilot.com\u002Freview\u002Fepal.gg",108887,"known",null,"unknown","High",[27,28,29],"Email addresses","Purchases","Usernames","\u003Cp>The E-Pal data breach is an account and purchase record leak affecting users of a platform focused on gaming and social connections. In terms of the registration system, the incident is recorded as a breach dated April 15, 2022; it has been reported that the platform announced the incident in the October 2022 period. This date distinction is important: the date of announcement or addition to the list should not be confused with the date of the incident to which the dataset is linked.\u003C\u002Fp>\n\u003Cp>The number of verified primary impacts is 108,887 unique email addresses. The dataset has been associated with approximately 1 million order or purchase records. The verified data classes are email addresses, usernames, and purchase records. Passwords, phone numbers, physical addresses, payment cards, or identification documents are not among the verified data classes of this record. Therefore, the incident should be described not as a financial card leak, but as an account identifiers and transaction context leak.\u003C\u002Fp>\n\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\n\u003Cp>When the email address and username are present together in the E-Pal registration, an attacker may try to match the user with different profiles on gaming and social platforms. Purchase records, on the other hand, can be used in social engineering to understand a person's use of services on the platform, the context of their order history, or the types of services they have paid for. These fields alone do not mean payment card information; however, they can make fake refunds, order verifications, or support messages more convincing.\u003C\u002Fp>\n\u003Cp>Since a password leak has not been verified for this record, the risk of direct credential cracking is limited. Nevertheless, the email and username pair can be used as a starting point in account takeover attempts. If the username is repeated across different gaming communities or social accounts, the risk of profile matching increases. The purchase context also gives the attacker the opportunity to prepare fake invoices, support requests, or account verification messages that appear personalized to the user.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main scope for this record is 108,887 unique email addresses. Approximately 1 million purchase or order records indicate the row count; this number should not be read as the number of unique individuals. The same user may have made multiple transactions. Therefore, the correct explanation to the user should keep the number of unique emails and the number of transaction records separate.\u003C\u002Fp>\n\u003Cp>Verified data classes are email addresses, usernames, and purchase records. Passwords, IP addresses, phone numbers, physical addresses, payment cards, bank accounts, real names, private messages, or account balances should not be added to the verified scope of this record. Purchase data does not imply that payment card or bank information has been leaked. The correct boundary is user account identifiers and in-platform transaction context.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of people who have purchased services on E-Pal or created a visible profile with a username. These users can be targeted with fake order confirmations, return notifications, support requests, membership alerts, or account verification links. When the email address and username are used together, it is possible for the message to appear as if it is based on the real platform history.\u003C\u002Fp>\n\u003Cp>The risk of profile matching is higher for individuals who reuse the same username in games and social communities. If the same username exists on different platforms, attackers may try to infer the person's gaming preferences, social connections, or service usage. For users registered with a corporate email address, the risk may appear in the form of targeted phishing messages carried over from their personal social\u002Fgaming account to their work email.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in an E-Pal registration, carefully review the order, return, support, account verification, or campaign messages in your inbox. Instead of clicking on the link in the message, log into the relevant account directly from its official address. Even though this registration does not confirm a password leak, enabling two-factor authentication on other accounts that use the same email and username and reviewing password reuse is a proper precaution.\u003C\u002Fp>\n\u003Cp>Due to the context of the purchase history, fake return or payment verification messages may appear more convincing. Since the card information is not verified in this record, instead of panicking, payment requests should be verified through official channels. Check the privacy settings on the game, social media, and community accounts where you use the same username. Reducing the visibility of your username on unused accounts or closing the account decreases the risk.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The E-Pal incident shows that purchase records can make a user susceptible to targeted social engineering even if they do not include a payment card. Platforms should not store transaction data longer than necessary, should minimize user identifiers, and should strictly monitor access to purchase histories. Using separate email aliases for different social and gaming services on the user side makes profile matching more difficult.\u003C\u002Fp>\n\u003Cp>In the long term, users should manage game, social connection, marketplace, and payment accounts with separate passwords. Even if the password is not a verified data class in this record, the leakage of the email address can increase targeted login attempts. Two-factor authentication, unique passwords, reducing username repetition, and the habit of verifying suspicious transaction messages through official channels limit the impact of such records.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, do not conclude that your payment card or password has been leaked; these fields are not included in the verified scope. However, your email address, username, and purchase context may be present in a dataset. This combination may be used in fake support, refund, order verification, or promotional messages.\u003C\u002Fp>\n\u003Cp>The correct action is to avoid suspicious links, directly check E-Pal and related social\u002Fgaming accounts, review privacy settings on accounts where you use the same username, and enable two-factor authentication on important accounts. The E-Pal data breach shows that even records without passwords can create social engineering and profile privacy risks when combined with purchase history context.\u003C\u002Fp>","","E-Pal Data Breach (108.9 Thousand Reported Records)","E-Pal Data Breach. 108.9 Thousand reported records were reported. Reported data: Email addresses, Purchases, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fepal_gg.webp",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":23},"E-Pal","Gaming social platform","United States"]