[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fred33ra0wmv9":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":16,"seoTitleEn":29,"seoDescription":16,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488252ef","on-rpg","OnRPG Data Breach","onrpg","onrpg.com","2016-07-01T00:00:00.000Z","2025-05-08T06:29:49.000Z","2026-07-03T23:18:32.738Z","2026-07-18T23:55:20.318Z","Third party breach","",[],1047640,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The OnRPG data breach is related to the exposure of user accounts belonging to the free online game list and community site in July 2016. The scope is approximately 1,047,640 accounts. This record was treated as a game community account breach; the company, country, industry, website, and data class fields were realigned with the verified scope. The industry was corrected from retail to gaming and online games directory.\u003C\u002Fp>\u003Cp>The text has been rewritten to directly explain the risk, scope, and action to the user. The website domain was kept as onrpg.com; since the protocol was not added, a format that would cause https to appear twice in the link was not used. The country was set to Global; the platform targets users of the gaming community.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, IP addresses, passwords, and usernames. Passwords were evaluated to be stored as salted MD5 hashes; old and weak passwords are risky. Unverified payment card, bank account, private message, health record, or additional profile fields were not added to the data class list; only supported fields were kept.\u003C\u002Fp>\u003Cp>Username and email matching can create identity links between game accounts. An email address alone poses a risk of unwanted messages; when combined with phone number, address, IP, date of birth, password, ID number, photo, or private preference data, it becomes easier for an attacker to generate user-specific messages. The risk assessment was made according to this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was verified with 1.04 million accounts as of July 2016. Confirmed areas were retained while unconfirmed areas were excluded. The incident was not combined with data sets with similar names, incidents from different periods of the same company, or incorrect attributions.\u003C\u002Fp>\u003Cp>The registration is limited to the domain onrpg.com and has not been combined with other game datasets. The domain name, company name, and industry information were kept in the narrowest accurate context possible. In places where there was uncertainty, verified flags or website fields were set accordingly; thus, no uncertain brand responsibility was shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may include former players with an OnRPG account and people who use the same username in different games. Matching users should also evaluate other accounts where they use the same email, phone, username, or password pattern outside the relevant service.\u003C\u002Fp>\u003Cp>If the same password is used on a game store, email, or social media account, the risk is transferred to current accounts. If there is a context of corporate email, child account, gaming community, adult content AI service, retail shopping, public record, or malware, the risk of social engineering and privacy can increase. Details that appear correct are not a sign of trust on their own.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their OnRPG password and all game, email, and social accounts where the same password is used. All accounts using the same password in records with a password field should be updated; in records without a password field, focus should be on the risk of email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages regarding cargo, account alerts, game rewards, support, public records, security notifications, job offers, or subscription renewals should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unique passwords, limited profile information, and different usernames should be used on game and forum accounts. Users should regularly clean up old accounts, unnecessary profile fields, repeated usernames, and old phone and address information. A unique password for each service and two-step verification where possible should be a basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are required. Old gaming communities can still be used in password retries years later. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can lead the user to take the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record using their email address. If a match is found, it should be assumed that the username, IP, and password fields may be at risk, and old game passwords should be cleared. The absence of a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; the problematic word and sector error in the old text were corrected. In this revision, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not included, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","OnRPG Data Breach (1 Million Reported Records)","OnRPG Data Breach. 1 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fonrpg_com.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"OnRPG","Gaming \u002F Online Games Directory","Global"]