[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f39cwruej2zvyt":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488251f2","gamevn","GameVN Data Breach","gamevn.com","2016-05-01T00:00:00.000Z","2024-09-23T01:39:12.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:51:20.772Z","Third party breach","https:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fbillions-passwords-credentials-leaked-mother-of-all-breaches\u002F",[15],1369485,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The GameVN data breach is a confirmed incident from May 2016 affecting members using accounts on the Vietnam-based gaming forum. The confirmed scope is 1,369,485 unique email records. The affected data groups are email addresses, IP addresses, usernames, and salted MD5 password hashes. It has been confirmed that the forum is XenForo-based and that the incident data later resurfaced within a larger data archive. The risk for this record is not limited to an old forum account; if the same email, username, or password is reused on other platforms, attackers may use this information to attempt access to current accounts. Phone number, physical address, payment card, official ID, date of birth, private messages, or in-game purchase history are not among the verified data classes for this incident.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The most critical data set verified in this breach consists of salted MD5 password hashes. A hashed password does not mean the plaintext password; however, MD5 is considered weak for current security expectations. The use of salt makes some bulk comparisons more difficult, but short, predictable, or reused passwords can still be cracked. If the same password was also used in email, gaming, forum, social media, or shopping accounts, an old GameVN record could pose a risk to active accounts today.\u003C\u002Fp>\n\u003Cp>When email addresses, usernames, and IP addresses are found together, the risk of targeted phishing increases. A username can be matched with a person's profiles on different gaming and forum platforms. An IP address alone does not necessarily indicate a definite identity or physical address; however, together with an email and username, it provides additional contextual linkage. Therefore, a user with a positive match should check not only their GameVN account but also other accounts associated with the same identity information.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified number for this record should be kept as 1,369,485. This value represents a unique email coverage; it should not be assumed with certainty that each record corresponds to a single, unique real person. The same person may have multiple accounts, old email addresses may appear separately, or technical duplicates may be present in the data. Nevertheless, the verified coverage indicates that the incident was a large-scale breach of a gaming forum.\u003C\u002Fp>\n\u003Cp>Verified data classes are email addresses, IP addresses, passwords, and usernames. The password field should be specified as a salted MD5 hash. Phone numbers, physical addresses, payment information, official IDs, birth dates, private messages, device information, in-game inventory, or purchase history should not be added to the record because they are not among the verified fields. Additionally, being reshared in larger archives is not considered sufficient evidence to add different data fields to the GameVN record.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use on their GameVN account on other services. The same email and username can be maintained for years across different platforms in gaming forums. This repetition makes it easier to transfer data obtained from a past breach to current accounts. Even if the account is no longer active, if the same password is valid on another platform today, the risk of account takeover continues.\u003C\u002Fp>\n\u003Cp>People who use the same username in Vietnamese gaming communities or regional forums should also be careful. When a username and email address are found together, attackers can prepare messages themed around fake forum notifications, game account verification, free content, gift codes, or community invitations. An IP address can also provide additional traces about the session context. Therefore, the user should review other accounts created with the same nickname.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user with an email address in this record should make sure that the old password used on their GameVN account is not valid on any other account. If the same or a similar password has been used for email, game store, forum, social media, or shopping accounts, a separate, long, and hard-to-guess password should be set for each account. Using a password manager makes this process more secure. Simply adding a small modification to the old password does not provide sufficient protection.\u003C\u002Fp>\n\u003Cp>Email accounts, game accounts, and social networks should have multi-factor authentication enabled. If there is an unknown device in the account history, unexpected login, password reset request, or security notification, sessions should be closed and recovery information should be updated. Forum-themed fake login pages, gift code messages, and security alerts should be carefully examined. Before clicking on a link, the address and sender information should be independently verified.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The GameVN incident shows that old accounts used in regional gaming forums can carry security implications for a long time. Users should not repeat the same password across game, forum, email, and social media accounts. Unused forum accounts should be closed or isolated with a unique password. Since maintaining the same username on multiple platforms increases the risk of profile matching, users should consider this choice consciously.\u003C\u002Fp>\n\u003Cp>The basic lesson for forum administrators is to abandon MD5-based password hashes and carry out password storage processes using up-to-date, cost-adjusted methods. Security updates in forum software like XenForo and similar should not be delayed, plugins should be regularly checked, and database access should be restricted with the least privileges. During incident reporting, it should be clearly specified which fields were affected and which fields were not verified.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>During record checking for a GameVN violation, the result shows whether the entered email address is found in this verified dataset. If the result is positive, the email address, IP address, username, and salted MD5 password hash should be considered at risk. If the result is negative, it means that no match was found in this particular dataset; this does not prove that the person has not been involved in other violations. The result should be interpreted only in the context of the GameVN incident.\u003C\u002Fp>\n\u003Cp>The correct user action is to completely abandon the old password, change reused passwords across all platforms, use multi-factor protection on email and gaming accounts, and review other profiles created with the same username. An old forum breach presents a current risk if the same password or username is still in use today. The user should not regard this record as a purely past event.\u003C\u002Fp>","","GameVN Data Breach (1.4 Million Reported Records)","GameVN Data Breach. 1.4 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fgamevn_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":19},"GameVN","Online Gaming Forum","Vietnam"]