[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f27fspmkzurkte":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488252b7","Mortal Online","Mortal Online Data Breach","mortal-online","mortalonline.com","2018-06-17T00:00:00.000Z","2018-08-31T05:38:46.000Z","2018-09-24T21:05:18.000Z","2026-07-18T23:54:40.015Z","MMORPG account data breach","https:\u002F\u002Faccount.mortalonline.com\u002Fbreach.html",[16,18,19],"https:\u002F\u002Fwww.mortalonline.com\u002F","https:\u002F\u002Fwww.starvault.se\u002F",606637,"known",null,"unknown","High",[26,27,28,29,30],"Email addresses","Names","Passwords","Physical addresses","Usernames","\u003Cp>The Mortal Online data breach is a verified security incident associated with account data for the online role-playing game developed by Star Vault AB. The record is linked to June 17, 2018, and covers 606,637 unique accounts. Verified data classes include email addresses, full names, passwords, physical addresses, and usernames. Information that passwords appear in unsalted MD5 hash form in the more complete data set makes this record significant in terms of password reuse risk.\u003C\u002Fp>\u003Cp>Game accounts should not be seen only as entertainment accounts. When email, username, real name, physical address, and password hash information are included together, the risks of account takeover, password attempts on other platforms, fake support messages, game account trading, and phishing increase. Since payment card, private messages, in-game asset breakdown, or official ID numbers are not included as verified data classes in this record, the risk explanation is limited to the five existing fields.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in Mortal Online records are email addresses, full names, passwords, physical addresses, and usernames. The email address and username can help match the player with their accounts on other forums, games, streaming, or social platforms. The full name and physical address can make fake customer support or account ownership verification messages more convincing. Therefore, the risk is not limited to just the compromise of the game account.\u003C\u002Fp>\u003Cp>The password field is associated with an unsalted MD5 hash format, so weak and repeated passwords carry a higher risk. Even if a strong password is used, the fact that the same password remains valid on other services gives attackers an opportunity to test it. Players often use the same username on forums, game stores, streaming accounts, and social media; this behavior increases the risk of profile matching. The physical address being known can also serve as an additional persuasion element in fake delivery or security confirmation messages.\u003C\u002Fp>\u003Cul>\u003Cli>Email and username can be matched with other game accounts.\u003C\u002Fli>\u003Cli>Password hash information increases the risk of being cracked for weak passwords.\u003C\u002Fli>\u003Cli>Name, surname, and address information can strengthen fake support messages.\u003C\u002Fli>\u003Cli>If the same password has been repeated, non-game accounts may also be affected.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record was limited to the name Mortal Online, the domain mortalonline.com, the date June 17, 2018, 606,637 affected accounts, and five verified data classes. In the initial data circulation, a smaller file was mentioned; later, in a more complete file, salted MD5 password hashes, names, usernames, and physical addresses along with email addresses were verified. Therefore, the number of records and data fields are maintained based on the more complete file.\u003C\u002Fp>\u003Cp>Payment card, bank information, date of birth, phone number, private message, in-game item, character list, or identity document were not added as verified data classes in the record. Other games, forums, or server registrations with a name similar to Mortal Online were not included in this document. Duplication control was carried out based on brand name, domain name, date, registration number, and data classes. This approach shows the real risk to the user while preventing unverified fields from appearing as definite information.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The primary risk group consists of players who had a Mortal Online account before 2018 and used the same username or password for other gaming services as well. The combination of email and username may cause a match with the player's forum, game store, streaming account, or social media profiles. If physical address and real name information are also available, fake account recovery or fake support messages become more personal.\u003C\u002Fp>\u003Cp>People who have been using the same email address for a long time, do not change old game passwords, use the same username in game forums, and have not enabled multi-factor authentication on game accounts should be more careful. On the corporate side, game communities, publisher teams, and users involved in in-game trading can also be targeted. Attackers may use old game data as supporting information when attempting to access current store accounts or email accounts.\u003C\u002Fp>\u003Cul>\u003Cli>Players using old passwords on Mortal Online account\u003C\u002Fli>\u003Cli>People who use the same username on other game and forum accounts\u003C\u002Fli>\u003Cli>Users with repeated email addresses in the game store and social accounts\u003C\u002Fli>\u003Cli>People whose physical address and real name information match the old game profile\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>A user who encounters the result with Mortal Online should first completely abandon the old password used on this account and choose a unique new password for all accounts where the same password was used. Email accounts, game stores, streaming platforms, social media, payment services, and cloud accounts should be checked first. A slight variation of the password is not considered secure; a long and separate password should be preferred for each service.\u003C\u002Fp>\u003Cp>Links coming on behalf of the game account or support team should be verified through an independent channel. Suspicious login alerts, password reset messages, game account trade offers, and fake refund messages should be carefully examined. Multi-factor authentication should be enabled on possible game and email accounts, and login history and connected devices should be checked. Since a physical address exists, fake delivery or verification messages should not be ignored either.\u003C\u002Fp>\u003Cul>\u003Cli>Renew your Mortal Online password and all accounts that use the same password.\u003C\u002Fli>\u003Cli>Use multi-factor authentication on email and game store accounts.\u003C\u002Fli>\u003Cli>Verify support, exchange, refund, and account recovery messages through an independent channel.\u003C\u002Fli>\u003Cli>Check unknown sessions, connected devices, and password reset notifications.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Even if game accounts are forgotten for many years, old data sets can be valuable in new attack attempts. Users should choose a separate email address, a unique password, and a password manager for their game accounts. Repeating the same username across different platforms makes profile matching easier; therefore, different usernames or additional privacy settings should be considered for critical accounts. Old game accounts should be reviewed at regular intervals, and unnecessary accounts should be closed.\u003C\u002Fp>\u003Cp>Community managers, publishers, and users involved in in-game trading should exercise extra caution against fake sponsorship, exchange, and support messages. From an institutional perspective, this record reminds employees not to reuse personal game passwords in work systems. Controls that prevent password reuse, multi-factor authentication, secure email gateways, and awareness training reduce the secondary impact of game-related data breaches.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>A user who sees the Mortal Online result on LeakData.io should compare the matching email address, username, and old password habit with their own account history. The result does not mean that the person is an active Mortal Online player today; it shows that account data from the 2018 period has been exposed. Since the password field is present, the most correct action is to verify that the old password is no longer valid on any account today.\u003C\u002Fp>\u003Cp>This record is kept in a verified status and its scope is limited to five data classes. Instead of acting as if payment card, private message, or in-game asset data has leaked, attention should be focused on the real risk created by email, username, real name, address, and password hash information. With a habit of unique passwords, multi-factor authentication, and verifying suspicious communications through an independent channel, users can reduce the impact of the Mortal Online breach on current accounts.\u003C\u002Fp>","","Mortal Online Data Breach (606.6 Thousand Reported Records)","Mortal Online Data Breach. 606.6 Thousand reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmortalonline_com.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":22},"Mortal Online \u002F Star Vault AB","MMORPG \u002F online gaming","Sweden"]