Data breach
Bot of Legends
- Records
- 148,438
- Breach date
- 13 November 2014Estimated
- Added
- 12 February 2025
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses148,438
- Passwords148,363
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In November 2014, Bot of Legends, a community forum built around scripting and botting tools for League of Legends, suffered a data breach that exposed user account records from its website, botoflegends.com. According to our investigation team, the incident affected roughly 148,438 records, including about 148,363 passwords and email addresses for all listed accounts. The site ran on the IP.Board forum platform, and multiple breach trackers report that attackers exploited weaknesses in that software to pull user data from its database. No individual or group has publicly claimed the attack.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
November 13, 2014: The Bot of Legends forum was breached, according to Mozilla Monitor, which dates the incident to this day.
December 27, 2016: Mozilla Monitor added the breach to its public database of known incidents.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Not every individual is affected by every type of data listed here.
Independent breach trackers describe the incident more broadly. Mozilla Monitor and LeakCheck also list usernames, IP addresses, and website activity data among the exposed fields, and both report that passwords were stored as salted MD5 hashes, a weaker protection method than modern password hashing. Record counts differ across trackers; LeakCheck indexes 192,402 records while our investigation team's dataset holds 148,438 rows.
What Are the Potential Risks for Affected Individuals?
The main risk is account takeover. If your Bot of Legends password was reused on other websites, email inboxes, or gaming accounts, attackers who obtain the leaked data can try those same credentials elsewhere, a technique known as credential stuffing. Weak password hashing makes it easier for criminals to recover the original passwords from the leak.
The exposed email addresses can also be used for targeted phishing. Someone who knows you had an account on a gaming forum can craft convincing emails that reference games, downloads, or account warnings to trick you into handing over more credentials or installing malware.
IP addresses and usernames add to the exposure. They help attackers link your online identities across sites and make phishing messages feel more personal.
What Should You Do If You Were Affected?
If you had a Bot of Legends account, take these steps:
Change that password everywhere you reused it. Start with your email account, then banking, gaming, and social media logins. Reused passwords are the single biggest risk from this breach.
Create unique passwords for each account. A password manager can generate and store strong, distinct passwords for you.
Turn on two-factor authentication wherever it is offered. This blocks most account takeovers even if a password leaks.
Watch for phishing. Be skeptical of emails about gaming accounts, script downloads, or login warnings, and never enter credentials through links in unsolicited messages.
Check whether your email appears in this breach.
