[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f14xawdqj43ik":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda4882533d","R2Games","R2Games Data Breach","r2games","r2games.com","2015-11-01T00:00:00.000Z","2016-02-09T12:20:35.000Z","2026-07-19T17:48:17.484Z","Verified third-party breach","https:\u002F\u002Fwww.csoonline.com\u002Farticle\u002F561335\u002Fr2games-compromised-again-over-one-million-accounts-exposed.html",[15,17,18,19],"https:\u002F\u002Fwww.r2games.com\u002F","https:\u002F\u002Fcorporate.r2games.com\u002F","https:\u002F\u002Fwww.forbes.com\u002Fsites\u002Frussellflannery\u002F2014\u002F03\u002F17\u002F2014-forbes-china-30-under-30-bringing-chinese-online-games-to-players-globally\u002F",22281337,"known",null,"unknown","Critical",[26,27,28,29],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>\u003Cstrong>The R2Games data breach\u003C\u002Fstrong> exposed email addresses, usernames, IP addresses and password hashes associated with 22,281,337 accounts in late 2015.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The incident record contains email addresses, usernames, IP addresses and password hashes. Combining an email address with a username can help an attacker distinguish genuine R2Games accounts and prepare convincing password-reset, in-game reward or support messages. An IP address does not prove a precise home or personal location, but it can provide approximate region and internet-provider context that makes targeted phishing more credible. The passwords were not listed as clear text, yet the salted hashing implementation was reported to be weak enough for many passwords to be cracked rapidly. The risk is not confined to an old R2Games account: if the same password was reused for another game, an email account or a social network, credential-stuffing attempts can spread the impact to those services.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The recorded date is a month-level marker for November 2015; public evidence does not establish one exact day for every part of the intrusion. The first analysis identified about 2.1 million forum records. Approximately 11 million additional accounts were incorporated into the same incident in March 2016 and a further 9 million in July 2016, producing the verified total of 22,281,337 accounts. This staged growth does not represent three separate corporate breaches; it reflects related R2Games datasets obtained and validated at different times. The affected forum infrastructure used vBulletin, where IP addresses and passwords were present, and the salted password hashes were reported to be rapidly crackable because of a weak implementation. The company denied the claims; verification rests on independent dataset checks. A second forum incident reported in 2017 is separate, and its 1,023,466 accounts are not added to this total.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The greatest risk applies to players who created an account on the R2Games portal or forums during 2015–2016 and reused their password on another service. A dormant gaming account may appear unimportant, but an old username, email address and crackable password can give an attacker a starting point for reaching current accounts. People who registered for several gaming services with the same email, made in-game purchases, maintained public forum profiles or left multi-factor authentication disabled on email should be especially cautious. Old accounts may also contain reused passwords and outdated recovery addresses. People who do not remember R2Games may still appear because of an old forum membership or an alternate email address used years ago.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>If you reused your old R2Games password anywhere else, change the passwords on those accounts immediately.\u003C\u002Fstrong> Generate a long, unique password for every service and store it in a reputable password manager where possible. Secure the email account first because email access can reset many other accounts. If the R2Games account remains active, replace its password and review sessions and recovery details; if it is no longer needed, consider requesting deletion through official support. Enable multi-factor authentication on email, gaming-store and social accounts, preferring an authenticator app or security key over SMS when available. Do not follow urgent links promising free game currency, warning that an account will be suspended or offering a refund. Type the service address yourself and rely only on the r2games.com domain and official support channels.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>This incident shows why an old forum account can remain a weak link in a person's security chain years later. Keep an inventory of accounts created on gaming, forum and community sites; close those no longer needed and avoid leaving a current primary email address attached to abandoned profiles. A password manager makes it practical to assign a different secret to every account, preventing one cracked hash from unlocking unrelated services. Keep multi-factor authentication, current recovery options and session alerts enabled on the email account that controls password resets. Reviews should include old forum memberships and former usernames, not only services used every day. Examine the actual domain, link destination and whether a request is normal instead of trusting the sender's display name. Unique passwords, multi-factor authentication and session monitoring reduce the chance that exposed identifiers lead to account takeover.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>\u003Cstrong>Check your email address with LeakData\u003C\u002Fstrong> to see whether it matches the R2Games record or another known breach. A match does not mean the account is currently controlled by someone else or that an old IP address reveals your present location; it means the address appears in a validated breach dataset. Interpret the result together with the incident date, listed data types and the password habits you had at that time. If there is a match, identify every service where the old password may have been used, secure email and payment-connected accounts first, and then review forum and gaming profiles. No match is an absolute security guarantee because not every dataset becomes public or can be validated. Unique passwords and multi-factor authentication should remain continuous safeguards rather than measures used only after an alert.\u003C\u002Fp>","","R2Games Data Breach (22.3 Million Reported Records)","R2Games Data Breach. 22.3 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fr2games-official.webp",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":22},"Reality Squared Games (R2Games)","Gaming","China"]