Data breach
DragonNest
- Records
- 3,135,018
- Breach date
- 23 August 2013Estimated
- Added
- 5 February 2025
What was exposed
6 types of data · 1 more reported
- Usernames3,135,014
- Interests3,133,683
- IP addresses2,798,805
- Email addresses504,501
- Names497,731
- Biographies59,554
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In August 2013, DragonNest, the fantasy massively multiplayer online role-playing game operated at dragonnest.com, suffered a data breach that exposed records belonging to roughly 3.1 million users. The estimated attack date is August 23, 2013, and the indexed dataset contains 3,135,018 rows. No individual or group has claimed responsibility for the breach. The incident received little mainstream press coverage in 2013, but the dataset has since been cataloged by multiple breach-tracking services, including Mozilla Monitor and DeHashed, both of which list the same August 23, 2013 date.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 23, 2013: the investigation team estimates the attack occurred on this date. Mozilla Monitor and DeHashed both list August 23, 2013 as the date of the DragonNest breach.
July 25, 2022: HEROIC analysts report a DragonNest-related dataset surfacing with a leak date of July 25, 2022, indicating the data circulated long after the original intrusion.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Usernames or nicknames: 3,135,014 records
Interests listed on user profiles: 3,133,683 records
IP addresses: 2,798,805 records
Email addresses: 504,501 records
Full names: 497,731 records
Biographies: 59,554 records
Not every individual is affected by every type of data listed here.
The profile-style fields, such as usernames, interests, and biographies, suggest the data came from a user account or forum database rather than payment or government identity records. DeHashed's summary of the incident also describes geographic location and gender fields in the exposed dataset.
What Are the Potential Risks for Affected Individuals?
The combination of email addresses, full names, usernames, and personal profile details is useful to criminals even without passwords. Attackers can use this data to send convincing phishing emails that reference a person's interests or game activity, making scams harder to spot. Email addresses paired with names also enable credential-stuffing attempts against other websites if a person reused a password from 2013 elsewhere. IP addresses linked to usernames can reveal rough location information and help tie online identities together. Because the dataset has resurfaced years after the breach, the risk is not limited to the original incident window.
What Should You Do If You Were Affected?
If you played DragonNest or registered an account on dragonnest.com around 2013, take the following steps:
Change your password on any account that still uses a password you used in 2013, starting with your email account.
Use a unique password for every service, and consider a password manager to keep track of them.
Turn on two-factor authentication where it is offered, especially for email and gaming accounts.
Be cautious with emails that mention the game, your old username, or your interests, since attackers can use the leaked profile data to make messages look legitimate.
