[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2i44ggnml1yay":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":36,"seoTitle":37,"seoTitleEn":38,"seoDescription":37,"seoDescriptionEn":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"68e3266eda11adda48825400","VNG","VNG Data Breach","vng","zing.vn","2015-05-19T00:00:00.000Z","2018-04-28T07:49:02.000Z","2026-07-19T15:22:44.863Z","Account data breach","https:\u002F\u002Fvng.com.vn\u002F",[15,17,18],"https:\u002F\u002Fcongnghe.tuoitre.vn\u002Flo-thong-tin-hang-tram-trieu-tai-khoan-khach-hang-vng-xin-loi-20180427225719109.htm","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180428013143id_\u002Fhttps:\u002F\u002Fcongnghe.tuoitre.vn\u002Flo-thong-tin-hang-tram-trieu-tai-khoan-khach-hang-vng-xin-loi-20180427225719109.htm",24853850,"known",null,"unknown","Critical",[25,26,27,28,29,30,31,32,33,34,35],"Dates of birth","Email addresses","Genders","IP addresses","Marital statuses","Names","Occupations","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>A May 2015 breach affecting VNG's Zing ID gaming accounts exposed \u003Cstrong>24,853,850 unique email addresses\u003C\u002Fstrong>. The incident became public when the data was offered for sale on a criminal forum in April 2018, and VNG acknowledged that some user information had leaked and apologized to customers.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The canonical data classes are dates of birth, email addresses, genders, IP addresses, marital statuses, names, occupations, passwords, phone numbers, physical addresses, and usernames. Passwords were \u003Cstrong>hashed with unsalted MD5\u003C\u002Fstrong>, which does not adequately protect weak passwords from offline guessing.\u003C\u002Fp>\u003Cp>This broad profile can support targeted phishing, SMS scams, abuse of account recovery, and account-takeover attempts based on password reuse. Payment cards, bank accounts, identity documents, and private messages are not verified data classes for this record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The canonical breach date is May 19, 2015. A forum listing in April 2018 claimed that a 7.55 GB archive held 163,666,400 Zing ID rows; that raw-row volume is not the same measure as the canonical 24,853,850 unique email addresses. VNG said it had recorded that 160 million Zing IDs might be at risk in 2015, used technical controls to limit the impact, and found that actual exposure was concentrated among gaming customers without affecting other products. The company also said approximately 99% of the accounts had been inactive for more than a year. The precise technical entry point was not publicly disclosed.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People with Zing ID or VNG gaming accounts face the greatest risk, especially those who reused the same username and password elsewhere. Combining names, dates of birth, occupations, marital status, phone numbers, and addresses can help attackers craft personalized messages, while email and IP information can support account linking and login attempts.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Change the old Zing ID or VNG password and every account that used the same or a similar password. Use a \u003Cstrong>unique password\u003C\u002Fstrong> for each service, secure the email account first, close active sessions, and enable two-step verification where supported. Verify unexpected messages containing phone, address, or occupation details through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a different password for every account, and close gaming or portal accounts you no longer use. Keep only necessary information in profile fields, and continue monitoring phishing and account-recovery notices involving hard-to-change data such as physical addresses, phone numbers, and dates of birth.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Check this record with the email address you used for Zing ID or VNG. A match means the address appears in the canonical VNG dataset; it does not mean all 163 million rows claimed in the forum listing represented unique or active users. If the result is positive, replace the old gaming-account password everywhere it was reused.\u003C\u002Fp>","","VNG Data Breach (24.9 Million Reported Records)","VNG Data Breach. 24.9 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fzing_vn.webp",false,{"name":7,"sector":43,"country":44,"website":45,"websiteArchiveUrl":37,"websiteStatus":37,"websiteCheckedAt":21},"Technology \u002F Gaming & Internet","Vietnam","vng.com.vn"]