Data breach
Evony
- Records
- 28,770,969
- Breach date
- 1 June 2016Estimated
- Added
- 17 March 2025
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses28,770,969
- Passwords28,273,271
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Hackers stole the account data of tens of millions of players of the online strategy game Evony in mid-2016. Independent reporting at the time put the total even higher: SecurityAffairs and SiliconAngle reported in October 2016 that the leak service LeakedSource had obtained 33,407,472 records from Evony's main game database, plus 938,000 records from its forums in a separate incident. The investigation team estimates the attack occurred around June 1, 2016, and no individual or group has been identified as claiming the breach in our records.
Breach Timeline
June 2016: Attackers gained access to Evony's main game database, according to reporting on LeakedSource's findings.
August 2016: A second compromise exposed records for about 938,000 registered users of the Evony forums, per the same reporting.
October 14, 2016: Details of the stolen database, including the scale of the leak and weak password patterns, were publicly reported.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
The passwords in the indexed records account for more than 28 million of the nearly 28.8 million rows, meaning nearly every affected account had its password exposed.
Not every individual is affected by every type of data listed here.
Contemporary reporting described additional fields. LeakedSource said each record contained a username, email address, password, and IP address, along with other internal data fields, as quoted by SecurityAffairs and SiliconAngle. That reporting also stated the passwords were stored with weak, unsalted MD5 and SHA-1 hashing, which made most of them straightforward to crack. LeakedSource's analysis found the password "123456" appeared more than 714,000 times in the database.
What Are the Potential Risks for Affected Individuals?
The main risk is account takeover. If a password from this breach matches a password you still use anywhere, someone with the leaked data can try those credentials on other websites, a practice known as credential stuffing. Gaming accounts are frequently targeted this way, but email, social media, and financial accounts are at risk too if passwords were reused.
The exposed email addresses also enable targeted phishing. Attackers who know an address is tied to a gaming account can send convincing messages about account problems, refunds, or game updates designed to steal more information.
If the IP addresses reported in outside coverage are confirmed in copies of the data, that detail can reveal approximate location at the time of signup and could be used to make phishing attempts more believable.
What Should You Do If You Were Affected?
Change your Evony password immediately, and change it on any other site where you used the same one.
Choose a long, unique password for each important account. A passphrase of several unrelated words works well.
Turn on two-factor authentication wherever the service offers it, especially for your email account, which can be used to reset other logins.
Watch for phishing emails that reference Evony or gaming accounts and avoid clicking links or entering credentials on sites reached through them.
