Data breach
Duowan.com
- Records
- 2,639,772
- Breach date
- 1 January 2011Estimated
- Added
- 24 July 2026
What was exposed
The kinds of data in this breach are not known yet.
About this breach
In late December 2011, user account data allegedly taken from Duowan.com, a Chinese gaming and gaming media website, surfaced online as part of a wave of leaks that hit several major Chinese internet companies. Our investigation team indexes this listing at roughly 2.64 million accounts, with an estimated breach date of January 1, 2011. Reporting at the time suggested the volume of exposed Duowan records may have been larger; a Chinese newspaper cited by DataBreaches.net put the figure at 8 million. Duowan did not appear to publish a detailed public notice confirming the leak, so key details remain unconfirmed.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
The Duowan data appeared during one of the largest password leak episodes in Chinese internet history. It began when a file containing about 6 million CSDN usernames and plaintext passwords circulated online on December 21, 2011, according to The Hacker News. Within days, data attributed to other sites, including Duowan, 7K7K, Dodonew.com, 178.com, Tianya, and Renren, was also being shared publicly.
December 21, 2011: A file with roughly 6 million CSDN usernames and plaintext passwords began circulating online, starting a wave of leak claims against Chinese websites.
December 22, 2011: Chinese media reports said user data from Duowan.com, with some accounts putting the figure at 8 million records, had been leaked alongside data from other sites.
December 26, 2011: DataBreaches.net reported that profiles from Duowan.com and 7k7k.com, both gaming sites, had been found online amid the widening leak wave.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, usernames, and passwords. Contemporary Chinese reporting indicated that many of the passwords in these leaked files were stored in plain text, meaning they were not encrypted or hashed. The investigation team has not confirmed the exact number of email addresses present in the indexed data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk from a decade-old leak of email addresses and plain text passwords is password reuse. Many people use the same password across multiple sites, and attackers routinely test leaked credentials against email providers, banking sites, gaming platforms, and social networks, a technique known as credential stuffing.
Exposed usernames and email addresses can also support phishing. An attacker who knows your email address and a password you once used can craft convincing messages that reference your gaming accounts to trick you into revealing current credentials. If the leaked email address is still active, it may continue to receive spam or targeted scam attempts.
What Should You Do If You Were Affected?
If you had an account on Duowan.com or used the same credentials elsewhere, take these steps:
Change your password on Duowan.com if the account still exists, and change it anywhere else the same password was used.
Choose a long, unique password for each important account, and consider a password manager to keep track of them.
Turn on two-factor authentication where it is offered, especially for your primary email account.
Watch for phishing emails that reference gaming accounts or old passwords, and avoid clicking links in unexpected messages.
In the news
- The Hacker News: Tianya, China's biggest online forum 40 million users data leakedthehackernews.com (opens in a new tab)
- DataBreaches.net: Attacks on Chinese sites continuedatabreaches.net (opens in a new tab)
- Mozilla Monitor: Duowan.com Data Breachmonitor.mozilla.org (opens in a new tab)
- Sina Finance: CSDN leak coverage (Chinese)m.cj.sina.cn (opens in a new tab)
