[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1j9cuwrhqcny8":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":16,"seoTitleEn":29,"seoDescription":16,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882533b","r2-2017","R2 (2017 forum breach)","r2-2017-forum-breach","r2games.com","2017-01-01T00:00:00.000Z","2017-04-25T11:04:29.000Z","2026-07-03T23:38:27.452Z","2026-07-18T23:56:49.903Z","Third party breach","",[],1023466,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","Passwords","Usernames","Website activity","\u003Cp>The R2 Games 2017 forum breach data incident is associated with the exposure of user accounts in a separate 2017 event involving the R2 Games forum. The scope is approximately 1,023,466 accounts. This record was treated as a separate forum breach from the previous incident on the same domain; the company, country, industry, website, and data class fields were realigned with the verified scope. The separation of title and text was maintained to avoid confusion with the 2015 R2Games incident.\u003C\u002Fp>\u003Cp>The text was rewritten to explain risk, scope, and action directly to the user. The website domain was kept as r2games.com; since the protocol was not added, a format that would cause https to appear twice on the link side was not used. The country was set to Global; game forum users are not tied to a single country.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, passwords, usernames, and site activity. It was assessed that passwords were stored as MD5 hashes without salt; this is a weak form of protection. Unverified payment cards, bank accounts, private messages, health records, or additional profile fields were not added to the data class list; only supported fields were kept.\u003C\u002Fp>\u003Cp>Site activity and username can match the player's community behavior with their email address. The email address alone poses a risk of spam; when combined with phone, address, IP, date of birth, password, official ID, support record, vehicle information, or physical address, it becomes easier for an attacker to generate messages specific to the user. The risk assessment was conducted based on this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope is limited to the R2 Games forum incident at the beginning of 2017. Confirmed areas were preserved, while unconfirmed areas were excluded. The incident was not combined with similarly named datasets, incidents from different periods of the same company, or incorrect sector references.\u003C\u002Fp>\u003Cp>The larger R2Games record from 2015 belonging to the same domain name was not merged with this record. Domain name, company name, and industry information were kept in the narrowest accurate context possible. In areas of uncertainty, verified flags or website fields were set accordingly; thus, uncertain brand responsibility was not shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk in the 2017 period may be players who had an R2 Games forum account and individuals who used the same username in different games. Matching users should also evaluate other accounts where they used the same email, phone, username, or password pattern outside of the relevant service.\u003C\u002Fp>\u003Cp>If old forum passwords are reused on a game store or email account, the risk is transferred to current accounts. If there is a corporate email, game forum, motorcycle customer registration, shopping mall application, support request, rental account, marketing list, or malware context, the social engineering risk may increase. Details that appear correct alone are not a sign of trust.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their R2 Games forum password and any other accounts using the same password. For records that have a password field, all accounts using the same password should be updated; for records without a password field, the focus should be on email, phone, fake notification, privacy, and identity matching risks.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Invoice, account warning, game reward, support, shipping, customer service, maintenance appointment, public notice, or subscription renewal messages should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A unique password, a separate username, and a habit of two-step verification should be created for gaming forums. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and old phone and address information. A unique password for each service and two-step verification wherever possible should be the basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and ready user notification processes are required. Different incidents on the same domain should be explained to the user with separate scopes. Correct scope explanation is also part of the security work; exaggerated or incomplete information may mislead the user into taking incorrect action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first verify with their email address in this record. If a match is found, it should be assumed that site activity, username, and weak password hashes may be at risk. The absence of a match does not completely rule out different email usage or old password reuse; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; it was not duplicated with the 2015 R2Games record. In this arrangement, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","R2 (2017 forum breach) (1 Million Reported Records)","R2 (2017 forum breach). 1 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fr2games_com.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"R2 Games Forum","Gaming Forum","Global"]