[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2752dosmiwris":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488251ed","games-box","Games Box Data Breach","gamesbox.com","2020-09-21T00:00:00.000Z","2024-09-15T02:41:52.000Z","2026-07-27T16:11:13.101Z","Third party breach","https:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fbillions-passwords-credentials-leaked-mother-of-all-breaches\u002F",[14],1439354,"known",null,"unknown","Critical",[22,23,24,25,26],"Ages","Email addresses","Genders","Passwords","Usernames","\u003Cp>The Games Box data breach is a verified incident that occurred in September 2020 on an online game-focused site that is now reported to be inactive. The verified scope is limited to 1,439,354 records. The affected data groups include age information, email addresses, gender information, usernames, and passwords. The password field is particularly important; it has been verified that some passwords in the records were stored as hashes and some in plain text. This situation poses a high risk not only for the old site account but also for other accounts using the same email and password. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The most significant risk in the Games Box record is that passwords are not only stored as hashes but also, in some records, in plain text. A plain text password allows an attacker to try it directly without needing to crack it. If the same password is used in another email, game, social media, forum, or shopping account, the risk of account takeover arises immediately. Passwords in hash form should also not be considered secure; weak or reused passwords can be cracked over time.\u003C\u002Fp>\n\u003Cp>When email addresses, usernames, age, and gender information are found together, the risk of targeted fraud and profiling increases. While age and gender fields alone are not considered high-impact identity information, when combined with email and username, more convincing fake notifications, game account scams, and phishing messages can be created. Therefore, the user should review not only their password but also other platforms where they use the same profile information.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified number for this record should be maintained as 1,439,354. This value represents the unique email coverage in the dataset; each record does not necessarily correspond to a single real person. Multiple accounts opened by the same person, old email addresses appearing separately, or data duplicates may affect the interpretation of this number. Additionally, redistributing the event within a larger data archive is not sufficient on its own to expand the coverage of this record.\u003C\u002Fp>\n\u003Cp>Verified data categories are age information, email addresses, gender information, passwords, and usernames. The password field may be in hashed or plain text format; this distinction should be preserved in the text. Since IP address, phone number, physical address, payment card, official ID data, private message, in-game purchase history, or device information are not among the verified fields, they should not be added to the record. The risk presented to the user should be explained only through the proven data categories.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use on their Games Box account on other accounts as well. Having a plaintext password makes it easier for attackers to try the same password on different services. Even if an old gaming site account is no longer in use, the risk continues if the same password is still valid on an active email, game store, social media, or forum account. Old gaming accounts opened in the name of younger users can especially be forgotten, but the same email and password can remain elsewhere for years.\u003C\u002Fp>\n\u003Cp>The risk of targeted messaging should also be assessed for users with age and gender information. Attackers can use these fields to create messages that appear personalized, such as campaigns, rewards, account verifications, or in-game gifts. If the username is also used on other games and social platforms, the risk of profile matching increases. Therefore, a user in a positive match should check not only their Games Box account but also all accounts associated with the same email and username.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>In this breach, users with an email address should first ensure that the password they used on their Games Box account is not used on any other account. If the same or a similar password has been used on another service, they should immediately switch to a unique, long, and hard-to-guess password. Using a password manager makes it easier to generate a separate password for each account. Due to the risk of plaintext passwords, steps such as only changing a few characters or adding numbers at the end should not be considered sufficient.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled on email accounts, game stores, social media, forums, and platforms involving payments. If there is an unrecognized device, unexpected login, password reset request, or suspicious security notification in the account history, all sessions should be closed and recovery information should be updated. For in-game rewards, free balance, gift codes, or account verification-themed messages, the address and sender information should be independently verified before clicking on links.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Games Box incident shows that passwords used on old gaming sites can become a security issue even years later. Users should not reuse the same password across gaming, forum, email, social media, and shopping accounts. Accounts that are no longer in use should be closed; for accounts that cannot be closed, the password should be made unique and profile information minimized. Repeating the same username across multiple platforms should also be a conscious choice, as it makes profile matching easier.\u003C\u002Fp>\n\u003Cp>The most critical lesson for service providers is that passwords should never be stored in plain text under any circumstances. The password storage process should be carried out using up-to-date, cost-adjusted hash algorithms, and access controls should be regularly audited. Profile fields such as age and gender should not be kept longer than necessary, and only truly necessary information should be stored in accordance with the data minimization principle. During incident reporting, it should be clearly specified which fields are hashed and which fields are in plain text.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>During record checks for Games Box violations, the result indicates whether the entered email address exists in this verified dataset. If the result is positive, the email address, username, age, gender, and password information should be considered at risk. Since the password field may be in plain text in some records, a positive result should be taken seriously. If the result is negative, it is understood that there is no match in this specific dataset; this does not prove that the person has not been involved in other breaches.\u003C\u002Fp>\n\u003Cp>The correct user action is to completely abandon the old password, change any reused passwords across all platforms, add multi-factor protection to critical accounts, and review other game or social accounts created with the same username. The user should not consider the risk insignificant due to the event being old or the site no longer being active. The possibility of a plaintext password can provide sufficient data for account takeover attempts even years later.\u003C\u002Fp>","","Games Box Data Breach (1.4 Million Reported Records)","Games Box Data Breach. 1.4 Million reported records were reported. Reported data: Ages, Email addresses, Genders. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fgamesbox_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":18},"Games Box","Online Gaming","Unknown"]