Data breach
Armor Games
- Records
- 11,015,960
- Breach date
- 1 January 2019Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 2 more reported
- Usernames11,013,615
- Email addresses10,780,970
- IP addresses9,619,533
- Biographies2,014,327
- PasswordsReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Armor Games, an online portal for browser-based games, suffered a data breach around January 1, 2019, that exposed roughly 11 million user account records. The company confirmed the incident in a public notice after a security group contacted it privately, and the stolen database later surfaced for sale on a dark web marketplace alongside data from 15 other hacked companies. According to our investigation team, the indexed dataset contains 11,015,960 rows spanning usernames, email addresses, IP addresses, and profile biographies.
Around January 1, 2019: Armor Games says the breach occurred at approximately this date, based on its own investigation.
January 29, 2019: Tuik Security Group privately contacted the company to report a potential breach of user data.
February 11, 2019: The Register reported that databases from 16 hacked websites, including Armor Games, were being offered for sale on the Dream Market dark web marketplace, with Armor Games listed at about 11 million accounts.
March 1, 2019: Armor Games published a public breach notification confirming the incident and requiring password resets.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames (11,013,615 records), email addresses (10,780,970), IP addresses (9,619,533), and profile biographies (2,014,327).
The company's own breach notice listed additional details beyond what appears in our indexed data. According to that notice, the affected database held public profile information, login data including hashed passwords, and the password salt used in the hashing process. The company acknowledged that including the salt could allow the hashed passwords to be reversed. The notice also stated that birthdays of administrator accounts were involved, and that the company does not hold, and believes this incident does not involve, first or last names, credit card data, addresses, or phone numbers.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of email addresses, usernames, IP addresses, and reversible password hashes creates several concrete risks.
Because the password salt was exposed alongside the SHA-1 hashed passwords, attackers with computing time could attempt to crack the original passwords. Anyone who reused an Armor Games password on other accounts, such as email, banking, or social media, faces a credential stuffing risk, where stolen login pairs are tested automatically on other websites. Even users whose passwords are never cracked can be targeted with phishing emails that reference their Armor Games username or account activity to appear credible.
The exposure of IP addresses and biographies is less dangerous on its own but can help attackers personalize scams or link a person's gaming identity to their other online accounts. Armor Games stated it had no evidence of actual misuse of user data at the time of its notice.
What Is Armor Games Doing in Response?
In its public notice, the company said it began an investigation immediately after being contacted on January 29, 2019, including an audit of its hosting provider, web servers, and database systems. It required affected users to update their passwords as a precaution. The company also said it began notifying authorities, would cooperate with law enforcement if requested, and might work with the other companies affected in the wider incident. The company directed questions to its support email address.
What Should You Do If You Were Affected?
If you had an Armor Games account around early 2019, take the following steps:
Change your Armor Games password if you have not done so since the breach. The company required this of affected users, so log in and check your account status.
If you reused that password anywhere else, change it on every other site where it was used. This is the single most important step, because cracked passwords from one site are routinely tested against others.
Use a unique, strong password for each account, ideally with a password manager, and turn on two-factor authentication wherever a service offers it.
Watch for phishing emails that mention your Armor Games username or gaming activity. Do not click links in unexpected emails; navigate to sites directly instead.
Review your email account security especially carefully, since email resets can unlock many other services.
The company's notice also recommended standard identity protection resources, such as the credit bureaus' fraud reporting channels, for users concerned about misuse.
