[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3kjtn8pv9xbmb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda488251e8","funny-games","Funny Games Data Breach","funny-games.biz","2018-04-28T00:00:00.000Z","2018-07-24T03:01:35.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:51:10.043Z","Third party breach","",[],764357,"known",null,"unknown","High",[23,24,25,26],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The Funny Games data breach is an incident from April 2018 that affected the authentication data of members using online gaming and entertainment accounts. The verified scope is limited to 764,357 records. The affected data groups have been identified as usernames, email addresses, IP addresses, and salted MD5 password hashes. Therefore, the risk is not limited to just accessing the game account; if the same email, username, or password was reused on other accounts, attackers could try this information on different services as well. It has been confirmed that the incident was reported to the company in July 2018, that the company acknowledged the breach, and determined that the cause was related to an old piece of code that was no longer in use.The number of records shows a size approximately equivalent to half of the user base. Fields such as phone number, physical address, payment information, date of birth, or private message content are not among the verified data groups for this record.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The most critical area confirmed in this breach is that the passwords are in the form of salted MD5 hashes. The use of salt reduces the chance that accounts with the same password will appear with identical hash values; however, MD5 is considered weak for current security expectations. If the password is short, predictable, or has appeared in a previous leak, the likelihood of the hash being cracked increases. This situation increases the risk of account takeover not only for the Funny Games account but also for email, gaming, social media, forum, or shopping accounts where the same password is reused.\u003C\u002Fp>\n\u003Cp>When email addresses and usernames are obtained together, attackers can see which pseudonym the account owner registered with and through which email. This pair of information can be used in targeted phishing messages, fake login pages, and password reset attempts. Finding IP addresses can provide additional context about a user's connection traces. Although not definitive proof of identity on its own, when combined with time, location, and session information, it increases the risk of user profiling.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified records should be kept at 764,357. This number refers to the number of records in the leaked data file; each record may not represent a unique real person. It is possible for the same person to have opened multiple accounts, for old and current email addresses to appear separately, or for records to be duplicated due to technical reasons. Therefore, the magnitude of the number should be maintained in the coverage assessment, but unverified certainty about the number of individuals should not be given.\u003C\u002Fp>\n\u003Cp>The verified data fields for this record are email addresses, IP addresses, usernames, and passwords. The password field should be specified as a salted MD5 hash; plain text password, payment card, ID number, open address, phone number, date of birth, in-game payment history, or private message data should not be added to this record unless verified. Since country information is also not explicitly verified, the company's location should not be matched with a specific country. In this way, the user is not presented with an overly broad or unsubstantiated account of the breach.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they used on their Funny Games account on other platforms. When the email and username remain the same, attackers can target different accounts with automated login attempts. Especially since it is common for passwords on old game accounts to remain unchanged for years, even if the incident is old, the risk is not completely gone. If an old password is still used on another active account today, this record still has practical security implications.\u003C\u002Fp>\n\u003Cp>Accounts opened on behalf of children and young players should also be carefully evaluated. Usernames used on gaming and entertainment sites are sometimes repeated on social media, messaging, streaming platforms, or forum accounts. This repetition can lead to the person's online identity in different environments being linked. Finding the IP address also leaves an additional trace about which connection environments the account has been used from. Therefore, the account owner should check not only the game account but also all accounts associated with the same email and nickname.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>In this record, the user with an email address should first ensure that the old password used on the Funny Games account is not used anywhere else. If the same or a similar password has been used on another account, this password should be immediately changed to a strong and unique password. Using a password manager to generate a separate, long, and hard-to-guess password for each account reduces the risk of reuse. When changing a password, it is not sufficient to only change the last character or add small additions to the same pattern.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on email accounts, game accounts, social media accounts, and all services involving financial transactions. If there is foreign access, unrecognized devices, unexpected password reset requests, or security emails in the account activity history, sessions should be closed and recovery options updated. Even if phone or payment data has not been verified in this incident, attackers can use email, username, and old password information in messages that appear trustworthy. Therefore, incoming links and attachments should be examined carefully.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Although this breach is an old incident, the long-term lesson is not to leave the password as the only layer of defense. Users should use unique passwords for each account, enforce multi-factor protection on critical accounts, and regularly review old game or forum accounts. Accounts that are no longer used should be closed if possible; if they cannot be closed, the password should be made unique and profile information minimized.\u003C\u002Fp>\n\u003Cp>On the institution side, outdated hashing methods like MD5 should be abandoned, and current and cost-adjusted algorithms should be preferred in password storing processes. Leaving old code fragments in the system creates invisible security debt over time. Therefore, in applications that process account data, code inventory, access logs, dependency checks, and regular security tests should be continuously operated. In user-facing notifications, which data fields are affected, which fields are not affected, and what the user needs to do should be clearly distinguished.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>During record checking for a Funny Games breach, the result indicates whether the person's email address is found in this data set. If the result is positive, the username, email address, IP address, and password hash should be considered at risk. If the result is negative, it means no match is found in this specific data set; this does not mean that the person has not been involved in other breaches. Therefore, the security assessment should not be limited to a single record.\u003C\u002Fp>\n\u003Cp>According to this record, the correct user actions are to clear old passwords, switch to a unique password, enable multi-factor authentication, and check the security history on other accounts using the same email address. In a past incident where the password hash was exposed, it is possible for attackers to reuse the data even years later. Users should completely abandon old password patterns, especially those used for gaming and entertainment accounts, and should not consider security warnings trivial by looking only at the date of the incident.\u003C\u002Fp>","Funny Games Data Breach (764.4 Thousand Reported Records)","Funny Games Data Breach. 764.4 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffunny_games_biz.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Funny Games","Online Gaming","Unknown"]