[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6kpqkelbvns2":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda488251c1","Evony","Evony 2016 Data Breach","evony","evony.com","2016-06-01T00:00:00.000Z","2017-03-25T23:43:45.000Z","2026-07-21T16:56:41.709Z","Verified breach record","https:\u002F\u002Fsecurityaffairs.com\u002F52260\u002Fdata-breach\u002Fevony-data-breach.html",[15,17],"https:\u002F\u002Fsiliconangle.com\u002F2016\u002F10\u002F14\u002Fdetails-of-33-million-accounts-stolen-in-evony-gaming-hack\u002F",29396116,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The 2016 Evony data breach involved unauthorized access to the online multiplayer game's main user database and exposed 29,396,116 unique accounts. The canonical breach date is June 1, 2016. Contemporary reports described 33,407,472 raw records in the main database, while the number on this page represents the verified, deduplicated account count.\u003C\u002Fp>\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\u003Cp>Verified data classes are email addresses, IP addresses, passwords, and usernames. Passwords were stored as unsalted MD5 hashes rather than plain text. MD5 is a fast algorithm now considered weak, and the lack of a salt means identical passwords produce identical hashes that are easier to test with dictionaries or precomputed tables.\u003C\u002Fp>\u003Cp>The combination of an email address, username, and password hash increases account-takeover and credential-stuffing risk. IP addresses can also provide clues about the approximate region of a past connection. Payment cards, bank accounts, government identifiers, physical addresses, and dates of birth are not verified data classes for this record.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>Contemporary technical reporting said more than 33 million raw user records were taken from Evony's main game database in June 2016. After duplicate records were removed, the verified dataset contained 29,396,116 unique accounts. The raw row count and the number of affected unique accounts should therefore not be used interchangeably.\u003C\u002Fp>\u003Cp>A separate incident affecting approximately 938,000 Evony forum records was also reported later that year. This page covers the main game database and must not combine the forum incident with it. Public reporting from the period did not establish the initial technical access method, so a specific vulnerability or attack vector should not be presented as confirmed fact.\u003C\u002Fp>\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\u003Cp>People who created an Evony account before 2016 and reused the same or a similar password elsewhere face the greatest risk. Even if the game account is no longer active, exposure remains relevant when the old password is still used for email, social media, game stores, or other online accounts.\u003C\u002Fp>\u003Cp>People who reuse the same username across games and communities may face targeted phishing and profile correlation. Clan leaders, community moderators, and visible game profiles may receive fake support, in-game reward, account-recovery, or security-notice messages.\u003C\u002Fp>\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\u003Cp>If the password used for Evony in 2016 is still used anywhere, replace it with a unique password on every affected account. Small variations such as adding a number to the old password are not sufficient. Prioritize your primary email account and any account used as a password-recovery channel.\u003C\u002Fp>\u003Cp>Enable multi-factor authentication wherever available, and review active sessions and account-recovery details. Do not sign in through links in messages about Evony, in-game rewards, or account security; navigate to the known domain yourself and never share verification codes.\u003C\u002Fp>\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\u003Cp>Use a trusted password manager to create a unique, random password for every service. Close old gaming accounts that are no longer needed or protect them with current security controls. A strong password and multi-factor authentication on the primary email account reduce the chance that an old breach can spread to other accounts.\u003C\u002Fp>\u003Cp>Email addresses and usernames from accounts created years ago can still support targeted fraud. Verify unexpected login alerts, password-reset notices, and gaming-community messages through an independent channel, and periodically assess the profile-correlation risk created by using the same username and contact address across platforms.\u003C\u002Fp>\u003Ch2>Record Check and User Action\u003C\u002Fh2>\u003Cp>Search for your email address with the breach-checking tool to see whether it matches the Evony record. A match shows that the email address appeared in the verified dataset taken from the main game database; it does not mean the account is compromised today or that it also appeared in the separate forum incident. The priority after a match is to replace the old password anywhere it was reused.\u003C\u002Fp>","","Evony 2016 Data Breach (29.4 Million Reported Records)","Evony 2016 Data Breach. 29.4 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fevony_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Gaming","United States"]