[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ibmc03mg1f07":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488251ab","epic-bot","EpicBot Data Breach","epicbot","epicbot.com","2019-09-01T00:00:00.000Z","2019-11-19T23:29:42.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:16.094Z","Bot service breach","https:\u002F\u002Farstechnica.com\u002Finformation-technology\u002F2019\u002F11\u002Fpassword-data-dumped-online-for-2-2-million-users-of-currency-and-gaming-sites\u002F",[16,18,19,20],"https:\u002F\u002Fwww.scworld.com\u002Fnews\u002Fstolen-gatehub-and-epicbot-credentials-spotted-on-hacking-forum","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fepic-bot-2019","https:\u002F\u002Fheroic.com\u002Fdarkhive-breaches\u002Fepicbot-2019-data-breach\u002F",816662,"known",null,"unknown","High",[27,28,29,30],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The EpicBot data breach is an account data leak affecting RuneScape bot service users and associated with 816,662 accounts. In terms of record-keeping, the incident is recorded as a breach dated September 1, 2019. The dataset was later reported to have been shared on a popular hacking forum. This record should be considered in the context of a game bot and community account; it should not be described as a general retail account or payment system leak.\u003C\u002Fp>\n\u003Cp>The verified data classes are email addresses, IP addresses, usernames, and passwords. It is stated that passwords are in salted MD5 or bcrypt hash formats. This distinction is important: bcrypt is considered a relatively stronger method of storing passwords, whereas MD5 is weak by modern standards. It should not be concluded that the password has been published in plaintext; however, weak or reused passwords may be attempted to be cracked by attackers.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The combination of the email address, username, and IP address registered with EpicBot can be used to match profiles in gaming communities. RuneScape bot users may have reused the same username on game forums, bot panels, chat servers, or social accounts. This situation helps the attacker identify the person on different platforms and prepare targeted messages.\u003C\u002Fp>\n\u003Cp>Password hashes are one of the most critical areas. Salted MD5 and bcrypt are not at the same security level; while bcrypt is considered slower and more resistant, salted MD5 can be targeted more easily. In the dataset, which hashing method was used for each record may not be visible to the user individually. Therefore, a secure approach is to ensure that the password used for the EpicBot account is not used on any other account. If the same password is used, gaming, email, social media, and payment-linked accounts could be at risk.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main scope for this record is 816,662 accounts. The incident date is recorded as September 1, 2019; the later circulation of the data or its addition to breach lists does not mean that the violation occurred on a more recent date. The date shown to the user is the breach date associated with the incident. This distinction prevents misinterpretation when different addition dates are seen on the account security screen.\u003C\u002Fp>\n\u003Cp>Verified data classes are email, IP address, password, and username. Phone number, physical address, payment card, real name-surname, game account inventory, in-game currency balance, or private message content are not among the verified fields of this record. EpicBot being a RuneScape bot provider should not imply that the user's game account content or main game account has been directly leaked. The correct statement should focus on the risk to the bot service account and credentials.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users in the highest risk group are those who reuse the password they used for their EpicBot account on other accounts. Technically active users in gaming bot communities may have used the same email address on game forums, developer tools, crypto wallets, or remote access services. In this case, an old bot account leak can pave the way for credential attempts on other accounts.\u003C\u002Fp>\n\u003Cp>There is a risk of profile matching for people who use the same username across different gaming communities. The IP address field may also allow limited inference about regional connection or service provider. Since the user uses a bot service, they can be targeted with themes such as fake ban warnings, account security notifications, in-game asset recovery messages, or bot license renewal links. These messages can appear more convincing when they use real event context.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in the EpicBot record, immediately check whether the password you used for this account is being reused on other accounts. If the same or a similar password has been used for email, game, forum, social media, wallet, or payment accounts, change it immediately. New passwords should be unique, long, and random; they should be stored with a password manager. Adding a number to the end of the old password is not sufficient.\u003C\u002Fp>\n\u003Cp>Be cautious of game and bot-themed security messages. Messages about account bans, bot licenses, in-game assets, free memberships, or urgent password verification may be fake. Instead of clicking on the link, access the relevant service directly from its official address. Enable this protection on accounts that support two-factor authentication. Check your email account for unknown sessions, forwarding rules, or recovery addresses.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The EpicBot incident shows that game bots and niche community accounts should be managed as carefully as main email and game accounts. Users should use separate passwords for bot, forum, and game community accounts, and, if possible, prefer separate email aliases. Using the same username everywhere increases the risk of profile matching; using different usernames for different purposes weakens this connection.\u003C\u002Fp>\n\u003Cp>On the platform side, the long-term lesson is to keep password storage methods up to date with current standards. Bcrypt can be a strong option if configured correctly; salted MD5 should no longer be considered sufficient. Old account data should not be kept unnecessarily, database accesses should be monitored, and forum or panel software should be updated regularly. On the user side, stopping password reuse prevents such old records from spreading to other accounts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, do not conclude that your password has definitely been published in plain text; however, using the same password elsewhere is not safe due to the risk of salted MD5 or bcrypt hashes. The combination of email, username, and IP address can be used to match your gaming community profiles and send targeted messages. Therefore, avoid reusing passwords, enable two-factor authentication on important accounts, and do not click on suspicious links.\u003C\u002Fp>\n\u003Cp>The correct action is not to treat a bot service account as an old and insignificant record. Check your game accounts, your email account, and forum accounts opened with the same username. Close unused accounts, use unique passwords, and do not respond to bot- or game-themed threat messages without verifying them through an official channel. The EpicBot data breach shows that even accounts on niche gaming tools can pose long-term risks to credential and profile privacy.\u003C\u002Fp>","","EpicBot Data Breach (816.7 Thousand Reported Records)","EpicBot Data Breach. 816.7 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fepicbot_com.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":23},"EpicBot","Gaming","International"]