[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc3xva5zoqnar":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":16,"seoTitleEn":30,"seoDescription":16,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882541b","wo-tlabs","WoTLabs Data Breach","wotlabs","wotlabs.net","2024-03-03T00:00:00.000Z","2024-03-07T03:32:45.000Z","2024-03-07T03:45:25.000Z","2026-07-19T00:01:39.936Z","Third party breach","",[],21994,"known",null,"unknown","Medium",[24,25,26,27,28],"Dates of birth","Email addresses","IP addresses","Time zones","Usernames","\u003Cp>The WoTLabs data breach is a security incident recorded in March 2024 that affected approximately 22,000 accounts. In the incident related to the World of Tanks statistics and forum community, identity, IP, and time zone fields of forum members were exposed. This statement has been prepared to clarify which user data may be at risk and which steps should be taken first.\u003C\u002Fp>\u003Cp>In the context of the gaming community, the date of birth, IP address, and time zone, when combined with the username, make the online identity easier to associate. The text only uses verifiable data categories; unverified password, payment, identity, or technical claims are not added as data fields. Events with similar names and different years belonging to the same brand are also not confused with each other.\u003C\u002Fp>\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are: birth dates, email addresses, IP addresses, time zones, and usernames. IP and time zone can signal a user's regional habits. The presence of these fields together can make it easier for attackers to prepare fake account reporting, fraud, identity linking, or targeted social engineering attempts.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; it results from the combination of the risk forum ID, IP, and date of birth. If there is no password, the risk is not completely eliminated; an address, phone number, date of birth, device information, work profile, loyalty program, web activity, or purchase information can also be sufficient to target the user. If there is a password, it should be urgently checked whether the same password is reused on other services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 22,000 forum members associated with the domain wotlabs.net. The event is in the confirmed record category. The scope has been determined by comparing the domain, company context, country, sector, number of accounts, and data classes. The fields shown to the user are limited to those listed in the record.\u003C\u002Fp>\u003Cp>The sector has been corrected as a gaming statistics and forum community, not technology. In some cases, company verification may be limited or the dataset may have been spread in third-party environments. In this case, the explanation focuses on areas showing the user's real risk, without exaggerating the points that are not certain.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>WoTLabs members, people who use the same username on game accounts, and users with IP\u002Fdate of birth fields are at risk. The main risk for these users is the matching of leaked fields with common information used on other platforms. If the same email, phone, username, address, social profile, or password is repeated on different accounts, the attack surface increases.\u003C\u002Fp>\u003Cp>Game statistics context can be used in fake tournaments, clan invitations, account verification, or profile messages. Game, retail, payment, social profile, travel, investment, airline, and health-wellness contexts produce different risks. The user should consider not only the list of fields but also which account or service those fields are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check for the use of the same email on forum and game accounts and review suspicious logins. If a password or password-like field is listed, users should change it on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication where possible. The email account should also be secured.\u003C\u002Fp>\u003Cp>If there are fields such as address, phone number, date of birth, device, work profile, purchase or loyalty program, users should check account recovery options, session history, forwarding rules, and suspicious messages. Verification and document requests received in the context of finance, payment, or airlines should be confirmed through a second channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unnecessary profile fields such as date of birth should not be shared on game forums, and a unique username and password should be chosen. In the long term, a password manager, unique password, multi-factor authentication, closing old accounts, and deleting unnecessary profile fields are basic defenses. Since permanent personal data cannot be recovered, user behavior and account settings should be strengthened.\u003C\u002Fp>\u003Cp>Data minimization for institutions, the retention period of old customer records, forum and community account permissions, loyalty program fields, and incident reporting processes should be regularly audited. On the user side, not using the same identity information everywhere permanently reduces risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check their WoTLabs account and game profiles using the same username. If a match is found, the user should read which data fields are listed and determine the order of actions accordingly. If there is a password, changing the password is a priority; if there is an address or phone number, a fraud warning is a priority; if there is finance or payment information, account monitoring is a priority; if there is a social profile, privacy control is a priority.\u003C\u002Fp>\u003Cp>Final assessment: This record has been marked as sensitive gaming community data because it contains IP, date of birth, and time zone. The user should compare this record with their account history; they should separately check the services where they have used the same email, phone number, username, address, or password. Any suspicious search, email, message, or account recovery notification should be considered higher risk after the incident.\u003C\u002Fp>","WoTLabs Data Breach (22 Thousand Reported Records)","WoTLabs Data Breach. 22 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, IP addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fwotlabs_net.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"WoTLabs","Gaming Statistics \u002F Forum","Global"]