[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f36msp588x4es3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825269","league-of-legends","League of Legends Data Breach","leagueoflegends.com","2012-06-11T00:00:00.000Z","2018-07-28T21:52:12.000Z","2026-07-18T23:53:22.456Z","Website breach","https:\u002F\u002Fwww.cio.com\u002Farticle\u002F286998\u002Fsecurity0-european-league-of-legends-game-players-have-their-account-data-compromised.html",[14,16,17],"https:\u002F\u002Fwww.leagueoflegends.com\u002F","https:\u002F\u002Fwww.riotgames.com\u002Fen",339487,"known",null,"unknown","High",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>The League of Legends data breach is a verified security incident from 2012 that affected player account data of the online MOBA game developed by Riot Games. The recorded date of the breach is June 11, 2012, and the number of unique accounts affected, as listed, is confirmed to be 339,487. The incident was initially announced in the context of European player account data, and in 2018 a more limited subset of this data, including email addresses, usernames, and plain text passwords, became visible. Therefore, the record represents accounts within the verified subset, not the entire League of Legends player base.\u003C\u002Fp>\n\u003Cp>Competitive game accounts like League of Legends do not only carry login information; elements such as the player name, game history, circle of friends, ranked account value, store purchasing habits, and associated email are also important from a social engineering perspective. The verified data classes in this record are email addresses, usernames, and passwords. Payment card, billing information, phone number, physical address, official ID, health data, or full date of birth are not among the verified data classes in this index. Risk should be assessed particularly around password reuse and account takeover attempts.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>When the three verified data classes are evaluated together, the most significant risk is account takeover and phishing. The email address enables communication with the player; the username can be matched with in-game identities and nicknames on other platforms; the password, if used the same or similarly on other services, turns into a broader account security issue. Although it was reported that the passwords were cryptographically protected in the 2012 incident, the presence of plaintext passwords in the subset that appeared in 2018 suggests that this protection may have been later compromised.\u003C\u002Fp>\n\u003Cul>\u003Cli>\u003Cstrong>Email addresses:\u003C\u002Fstrong> They can be used for fake account security warnings, fake tournament invitations, fake prizes, and fake support messages.\u003C\u002Fli>\u003Cli>\u003Cstrong>Usernames:\u003C\u002Fstrong> They can be matched with player identity, social circles, and profiles in other gaming communities.\u003C\u002Fli>\u003Cli>\u003Cstrong>Passwords:\u003C\u002Fstrong> If the same password has been used on other accounts, email, gaming, social media, and store accounts may be at risk.\u003C\u002Fli>\u003Cli>\u003Cstrong>Game account value:\u003C\u002Fstrong> Accounts with rare costumes, ranked levels, in-game currency, or collectible value may become targets.\u003C\u002Fli>\u003Cli>\u003Cstrong>Social engineering:\u003C\u002Fstrong> Username and email information provide a basis for messages that imitate the player's circle of friends, making them more convincing.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified index record is limited to 339,487 unique accounts. The fact that the League of Legends service had a much larger registered player base at the time the incident was first announced does not mean that everyone in this record or all players were affected. This record should be maintained through the subset that circulated in 2018, which includes email addresses, usernames, and passwords. This distinction prevents both misrepresentation of volume and the addition of unverified data fields.\u003C\u002Fp>\n\u003Cp>In period reports, European region player data, the initial protected state of passwords, and some additional personal fields appearing in the original event are explained. However, in this system record, data categories are limited to three fields: email addresses, usernames, and passwords. Therefore, the description should not be expanded as if payment information, billing data, address, phone, or identification data were included. Additionally, it should not be concluded that a currently active League of Legends account has been definitively compromised; this record is related to data that was exposed in the past.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for players who had a League of Legends account during the 2012 period and later reused the same password on email, social media, game stores, streaming platforms, or other game accounts. Even if an old password appears inactive today, attackers can use it in password guess lists, variation attempts, and old account recovery processes. If the username is also the same as the player's nickname in other communities, the targeting power increases.\u003C\u002Fp>\n\u003Cp>Players with high-level accounts, rare cosmetic items, collections, event rewards, or paid content also become economic targets. Acquired game accounts can be sold, used in fraudulent events, or abused to send fake links to people on the friends list. For high-visibility users such as those in e-sports, streaming, or community moderation, the risk is not only account access; reputation loss and targeting of the follower base should also be considered.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address matches in this record, first set a unique password for your League of Legends and associated Riot account. Change all accounts where you used the same old password individually. The email account is a priority because game account recovery links usually go through email. Account recovery addresses, active sessions, security notifications, and connected devices should also be checked.\u003C\u002Fp>\n\u003Col>\u003Cli>\u003Cstrong>Separate your passwords:\u003C\u002Fstrong> Do not use the same password for your game account, email, and store accounts.\u003C\u002Fli>\u003Cli>\u003Cstrong>Enable multi-factor authentication:\u003C\u002Fstrong> Prefer app-based authentication or security key on supported accounts.\u003C\u002Fli>\u003Cli>\u003Cstrong>Review the sessions:\u003C\u002Fstrong> If there is an unknown login, region change, username change, or account recovery attempt, initiate security steps.\u003C\u002Fli>\u003Cli>\u003Cstrong>Beware of fake reward messages:\u003C\u002Fstrong> Do not open links for free costumes, tournament invitations, account verification, or penalty appeals outside of the official site.\u003C\u002Fli>\u003Cli>\u003Cstrong>Strengthen your email account:\u003C\u002Fstrong> Keep recovery addresses, phone verification, and security alerts up to date.\u003C\u002Fli>\u003C\u002Fol>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Long-term security in game accounts is not limited to choosing strong passwords. When players use the same nickname across different communities, it becomes easier to link accounts. Therefore, the main email account, game accounts, and publisher\u002Fcommunity profiles should be managed with separate security levels. Using a password manager, generating unique and long values for each account, and not reusing old passwords are fundamental defenses.\u003C\u002Fp>\n\u003Cp>An additional strategy for gaming platforms is to limit the attack surface without reducing account value. It is necessary to close unused old accounts, keep recovery channels up to date, be cautious even of connections from the friends list, and not trust files or plugins outside the official client. On the corporate side, the duration of storing player data, old regional systems, password protection methods, and post-breach notification processes should be regularly reviewed.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Seeing a match in this record indicates that the relevant email address or account ID is linked to verified fields in the League of Legends dataset. This result does not mean that your account was compromised today; however, it shows that the email, username, and password combination that was previously exposed could have been tried on other services. Therefore, a match should be considered a warning not only for the game account but for all accounts where the same password is used.\u003C\u002Fp>\n\u003Cp>The most appropriate action after checking is to use separate passwords for your game account and the linked email, enable multi-factor authentication, update account recovery options, and terminate sessions you do not recognize. If you are present in other gaming communities with the same username, review those profiles as well. Be cautious of fake tournament, reward, support, account penalty, or security verification messages; when an action is required, go to the official site by typing the address yourself.\u003C\u002Fp>","","League of Legends Data Breach (339.5 Thousand Reported Records)","League of Legends Data Breach. 339.5 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fleagueoflegends_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":20},"Riot Games \u002F League of Legends","Online Gaming","United States"]