[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f10cnjeky1pmrr":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":16,"seoTitleEn":30,"seoDescription":16,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda488251d6","flash-flash-revolution2019","Flash Flash Revolution (2019 breach)","flash-flash-revolution-2019-breach","flashflashrevolution.com","2019-07-16T00:00:00.000Z","2019-07-21T20:31:54.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:50.284Z","Third party breach","",[],1858124,"known",null,"unknown","Critical",[24,25,26,27,28],"Dates of birth","Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The Flash Flash Revolution 2019 data breach is the second major account leak experienced by the music-based rhythm game and forum community during July 2019. This incident affected 1,858,124 unique accounts and should be considered separately from the previous Flash Flash Revolution breach in 2016. The 2019 leak included email addresses, IP addresses, usernames, dates of birth, and salted MD5 password hashes. The date of birth field is one of the significant differences of this incident; for the 2016 leak, the same field was not verified.\u003C\u002Fp>\u003Cp>The Flash Flash Revolution community should not view the breach merely as an old game account issue, since it has a user base focused on games, rhythm, and forums. The presence of usernames, emails, IPs, birth dates, and password hashes together lays the groundwork for both account brute-force attacks and identity matching and targeted social engineering attempts. The fact that the same platform has experienced a breach before implies that both old and new passwords could have been exposed again in different incidents.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in the 2019 record are birth dates, email addresses, IP addresses, passwords, and usernames. Passwords were stored in a salted MD5 hash format. Email and username can be used for account attempts and profile matching on different services. The IP address can provide connection history or regional context. The birth date can be misused to create messages that better understand the user, guess certain account recovery questions, or strengthen authentication scenarios.\u003C\u002Fp>\u003Cp>Salted MD5 hashes are more secure than plain text passwords, but MD5 is a weak method according to current security expectations. The risk of cracking continues for weak, short, or reused passwords. The 2019 record is additional to and independent from the 2016 incident, so users should not rely solely on old password changes. People who set a new password after 2016 but used that password until 2019 may also be at risk.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The number of verified unique accounts is 1,858,124. The incident date is tracked as July 16, 2019. The record belongs to the Flash Flash Revolution platform and is a separate incident in addition to the same service breach in 2016. The data fields are limited to email addresses, IP addresses, usernames, dates of birth, and salted MD5 password hashes. This limitation is the main point that distinguishes the 2019 record from that of 2016.\u003C\u002Fp>\u003Cp>In this record, the phone number, physical address, payment card, bank account, official identification document, private message content, or purchase history are not among the verified data fields. The presence of a date of birth increases the risk, but no financial data claim should be added. Users should assess the incident based on account security, password reuse, social engineering supported by date of birth, and forum identity matching risks.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The users at the highest risk are those who use the password from their Flash Flash Revolution account on other game, forum, email, or social media accounts. People who changed their password after the 2016 incident but used the same new password for a long time may also have been affected due to the 2019 record. The fact that the old game account is no longer active does not eliminate the risk; the same password history can continue to exist on other accounts.\u003C\u002Fp>\u003Cp>The risk of targeted messages is higher for individuals whose date of birth and username are found together. Attackers may craft messages themed around old gaming communities, birthday campaigns, account recovery, rewards, tournaments, profile verification, or security checks. IP information and email addresses can also make these messages more convincing. People who use the same nickname on different platforms should consider the risk of their digital identity being matched across multiple services.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>If your email address appears in this record, change the password you used for your Flash Flash Revolution account in 2019 and any accounts where the same password was reused. Even if you changed your password after the 2016 breach, check whether the password used in 2019 remains on other accounts. Email accounts, game accounts, social media profiles, and shopping sites should be prioritized. Use a unique and long password for each service.\u003C\u002Fp>\u003Cp>Two-step verification should be enabled on the email account, security notifications should be kept on, and sessions you do not recognize should be closed. For messages coming under the name of an old forum or gaming community, check the domain by typing it yourself before clicking the link. If a message asks you for a password, one-time code, or account recovery information, verify this request through a separate channel. A message that knows your date of birth should not automatically be assumed to be trustworthy.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The Flash Flash Revolution 2019 incident shows that the same platform can experience separate breaches in different years. Users should not consider a one-time password change sufficient and should think about which password period could have been affected in each incident. Unique passwords for game and forum accounts, two-factor authentication, and regular session monitoring are long-term fundamental security steps. Old accounts should be closed or protected with updated email addresses and strong passwords.\u003C\u002Fp>\u003Cp>For community platforms, strong password storage, up-to-date forum software, access monitoring, and clear user notification in the case of repeated violations are of critical importance. Retaining additional personal fields such as date of birth increases the impact of an account security incident. Reducing unnecessary personal data, keeping password hash algorithms up to date, and regularly auditing account databases are permanent security requirements for such community services.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If your email address is found in the Flash Flash Revolution 2019 record, remember that this incident is separate from the 2016 record. Change the password you used during the 2019 period and any other accounts that use the same password. Protect your email account with two-factor authentication, enable security notifications on your game and social media accounts, and be cautious of messages personalized with your date of birth information.\u003C\u002Fp>\u003Cp>The verified data fields in this breach are email, IP address, username, date of birth, and salted MD5 password hashes. Phone, address, or payment data are not verified; however, the combination of password and date of birth is high risk. The most accurate action is to evaluate the records from 2016 and 2019 separately, clear your password history, use unique passwords for each account, and prevent old game\u002Fforum accounts from creating risk on other services.\u003C\u002Fp>","Flash Flash Revolution (2019 breach) (1.9 Million Reported Records)","Flash Flash Revolution (2019 breach). 1.9 Million reported records were reported. Reported data: Dates of birth, Email addresses, IP addresses. Review the…","\u002Fuploads\u002Flogo\u002Fflashflashrevolution_com.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"Flash Flash Revolution","Gaming","Unknown"]