Data breach
Dungeons & Dragons Online
- Records
- 1,030,098
- Breach date
- 2 April 2013Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 1 puts you at serious risk
- Email addresses1,030,098
- Usernames1,030,095
- IP addresses994,866
- Passwords942,565
About this breach
In April 2013, Dungeons & Dragons Online, the massively multiplayer role-playing game operated by Turbine, suffered a data breach that exposed more than one million player accounts. According to our investigation team, the estimated attack date is April 2, 2013, and the breach data covers 1,030,098 records. The exposed information was later circulated and traded on underground forums.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present in all 1,030,098 records
Usernames or nicknames, present in 1,030,095 records
Passwords, present in 942,565 records
IP addresses, present in 994,866 records
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of email addresses and passwords in a single leak is the most immediate concern. Many people reuse the same password across multiple services, so a password taken from a game account in 2013 can still unlock email, shopping, or banking accounts today if it was never changed.
Attackers can feed leaked email and password pairs into automated credential stuffing tools that try the same combinations on other websites. They can also use the exposed emails for targeted phishing, sending messages that look like legitimate game or account security notices to trick people into handing over more information.
The exposure of IP addresses and usernames adds a smaller but real privacy risk, because it links a person's online identity to a network address and can help attackers build a more convincing picture of a target.
Because this breach is more than a decade old, anyone who has since changed the password they used on ddo.com and has not reused it elsewhere faces a much lower risk today.
What Should You Do If You Were Affected?
If you played Dungeons & Dragons Online and had an account around April 2013, take these steps:
Change your DDO account password immediately, and change it anywhere else you may have used the same password.
Use a unique, strong password for every account. A password manager makes this practical.
Turn on two-factor authentication wherever it is offered, including on your email account.
Be alert to phishing emails that reference the game, your account, or password resets, and avoid clicking links in unexpected messages.
