[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1rwqjltjd7esa":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda488251a9","epic-games","Epic Games Data Breach","epicgames.com","2016-08-11T00:00:00.000Z","2016-11-07T10:19:34.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:11.096Z","Forum database leak","https:\u002F\u002Fwww.infosecurity-magazine.com\u002Fnews\u002Fepic-games-forums-hacked-user\u002F",[15,17,18,19],"https:\u002F\u002Fwww.tripwire.com\u002Fstate-of-security\u002Fepic-games-forums-hacked-for-the-second-time-in-a-year","https:\u002F\u002Fsecurityaffairs.com\u002F50537\u002Fdata-breach\u002Fepic-games-hacked-2.html","https:\u002F\u002Fwww.securityweek.com\u002Fepic-games-resets-passwords-following-forum-breach\u002F",251661,"known",null,"unknown","High",[26,27,28],"Email addresses","Passwords","Usernames","\u003Cp>The Epic Games data breach is an old forum data leak affecting the company's forum infrastructure and covering 251,661 accounts. In terms of record-keeping, the incident is recorded as a breach dated August 11, 2016. This record should not be described as a new incident affecting all Epic Games Store or Fortnite accounts; the confirmed scope is the Epic Games forum account data. The breach has been reported to be associated with an old SQL injection vulnerability used in vBulletin forum software.\u003C\u002Fp>\n\u003Cp>The verified data classes are email addresses, usernames, and passwords. It is stated that passwords are stored in salted MD5 hash form. While the use of salt provides additional protection compared to plain MD5, MD5 is considered weak for modern password storage standards. Therefore, the risk of account takeover continues for weak or reused passwords. If the same email and username combination is used in other game, forum, or social media accounts, the risk of profile matching and phishing also increases.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In the Epic Games forum registration, the email address and username can help the attacker associate the person with online games and developer communities. Forum usernames are often reused across different gaming platforms, developer forums, and social accounts. Therefore, even the compromise of a single forum account can be a starting point for attempts targeting the person's other accounts.\u003C\u002Fp>\n\u003Cp>The risk is not completely eliminated because the password field was found as a salted MD5 hash. A hash may not mean that the password was published in plain text; however, due to the fast nature of MD5, weak and common passwords can be attempted to be cracked. If the user used the same password on their email, game store, developer platform, or social media account, this forum record could be used in automated login attempts. The discovery of password reuse causes the incident to remain effective even years later.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main scope for this record is 251,661 accounts. The incident date is recorded as August 11, 2016; being added to breach lists later does not mean the incident occurred at a more recent date. Different forum incidents associated with Epic Games and Unreal Engine forum records may have emerged around the same period; however, the scope to be shown to the user for this slug is the Epic Games forum record and 251,661 accounts.\u003C\u002Fp>\n\u003Cp>The verified data classes are email address, username, and password. IP address, date of birth, private messages, posting history, phone number, payment card, or in-game purchase history are not included among the verified fields of this record. This limitation is particularly important because there may be broader field claims regarding different forum subsystems during the same period. Only the risk of verified forum account credentials should be described in this record.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users who are in the highest risk group are those who reuse the password they use on their Epic Games forum account on other accounts. Game developers, players, and community members who opened a forum account in 2016 may have used the same email address for their Epic Games account, game store, developer tools, or other forums. In this case, an attacker could attempt account takeover or targeted phishing attempts by trying the email and username on different services.\u003C\u002Fp>\n\u003Cp>There is also a risk of profile matching for people who use the same username across different gaming communities. Even if forum history is not public, the username can provide context about a person's gaming preferences, developer interest, or community membership. For developers and studio employees who register with a corporate email address, the risk is that their old forum identity could be used in phishing messages targeting their work account. Therefore, one should look not only at the forum account but also at other associated accounts.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, check whether the password used on your Epic Games forum account is being reused on another account. If the same or a similar password has been used for email, game stores, developer platforms, social media, or other forums, change it immediately. New passwords should be unique, long, and random; they should be stored using a password manager. Making small additions to an old password is not sufficient.\u003C\u002Fp>\n\u003Cp>Be cautious of security alerts, reward messages, account verification links, and support requests related to Epic Games or game accounts. Instead of clicking on the link, log in by typing the account's address yourself. Enable this protection on accounts that support two-factor authentication. Check your email account for unknown sessions, recovery addresses, or forwarding rules. Closing or isolating old unused forum accounts also reduces risk.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Epic Games forum incident shows that old forum software and user forums need to be protected with the same care as main product accounts. Organizations should keep forum infrastructures like vBulletin up to date, regularly test for SQL injection risks, and bring password storage methods up to modern standards. Although salted MD5 was commonly used in the past, it is not considered sufficient in current systems. Slow and strong hash algorithms should be preferred.\u003C\u002Fp>\n\u003Cp>The long-term solution on the user side is to use unique passwords for game forums, store accounts, and email accounts. Using the same username everywhere makes profile matching easier; using separate usernames and email aliases for different purposes reduces the risk. Developers and studio staff should avoid using work email on personal forum accounts and should review old community accounts regularly.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, know that it does not mean that your Epic Games account or payment information has been directly leaked. This record is limited to forum account credentials. Nevertheless, the combination of email, username, and salted MD5 password hash poses a serious account security risk. Change any accounts where you use the same password, enable two-factor authentication, and do not take action on suspicious game or forum-themed messages without verifying them.\u003C\u002Fp>\n\u003Cp>The correct course of action is to treat your old forum account as part of your current digital identity security. Close unused forum accounts, use unique passwords, protect your email account, and do not allow the same username to easily match you on other platforms. The Epic Games forum data breach shows that even community forums that are separate from main product accounts can have lasting effects on user security.\u003C\u002Fp>","","Epic Games Data Breach (251.7 Thousand Reported Records)","Epic Games Data Breach. 251.7 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fepicgames_com.webp",false,{"name":36,"sector":37,"country":38,"website":9,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":22},"Epic Games","Gaming","United States"]