Data breach
EpicNPC
- Records
- 54,456
- Breach date
- 2 January 2016Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses54,456
- Passwords54,428
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
EpicNPC, an online marketplace where players buy, sell, and trade game accounts, suffered a data breach in early January 2016 that exposed account credentials for members of the site. According to our investigation team, the indexed records tied to this breach total 54,456 rows, with email addresses and passwords appearing in nearly every record. The breach went largely unreported at the time and only surfaced in public breach databases years later.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
January 2, 2016: The breach of EpicNPC occurred, according to Mozilla Monitor.
July 27, 2019: Mozilla Monitor added the verified breach to its public database, more than three years after the attack.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords. Email addresses appear in all 54,456 indexed records, while passwords appear in 54,428 of them, according to our investigation team.
Mozilla Monitor also lists usernames and IP addresses among the compromised data types for this breach.
Not every individual is affected by every type of data listed here.
No public statement from EpicNPC describing the exact cause or scope of the breach was found in the sources reviewed as of September 25, 2026, so details about how attackers obtained the data remain unclear.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and passwords are the core ingredients for account takeovers. If you reused the same password on other sites, attackers who obtain this data can try those credentials on email providers, social media, gaming platforms, and payment services. This technique, known as credential stuffing, works because many people reuse passwords across accounts.
The email addresses themselves can also be used for phishing. Attackers may send messages that appear to come from EpicNPC, game publishers, or account services, hoping recipients click malicious links or hand over additional credentials. IP addresses exposed in a breach reveal general location and internet provider information, which can support targeted scams.
Because EpicNPC is a marketplace for valuable game accounts, affected users may face particular risk to any accounts they traded or managed through the site.
What Should You Do If You Were Affected?
If you had an EpicNPC account around January 2016, take these steps:
Change your EpicNPC password if you still use the site, and choose a password you do not use anywhere else.
Change passwords on any other accounts where you used the same or a similar password. Start with email, banking, and gaming accounts.
Watch for phishing emails that reference EpicNPC, game account sales, or login problems, and avoid clicking links in unexpected messages.
Use a password manager to create and store unique passwords for every account.
Turn on two-factor authentication wherever it is offered, especially for your email account, which often controls password resets for everything else.
Because this breach occurred years ago, stolen credentials have likely circulated for some time. Acting now still reduces the chance that an old password leads to a new compromise.
