Data breach
Flash Flash Revolution
- Records
- 1,546,923
- Breach date
- 16 July 2019Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses1,546,923
- Passwords1,546,310
- UsernamesReported, not counted
- IP addressesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In July 2019, Flash Flash Revolution, a long-running browser-based rhythm game and its associated community forum, suffered a data breach. The incident involved an estimated 1,546,923 records, with email addresses appearing in every record and passwords in all but a small fraction of them. The team estimates the attack took place on July 16, 2019.
Independent breach-monitoring services corroborate the general outline of the incident. Mozilla Monitor lists a July 16, 2019 breach of the site and notes it was added to its own database on July 21, 2019. Coverage from major news outlets appears sparse, and a detailed company notice could not be located.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
February 2016: Flash Flash Revolution's vBulletin forum was hacked in an earlier incident, exposing roughly 1.8 million accounts, according to reporting by DeHashed and North IT.
July 16, 2019: The date Mozilla Monitor and North IT list for the 2019 breach of the site.
July 21, 2019: The breach was added to Mozilla Monitor's database after being discovered and verified.
Some third-party sources date the underlying data differently, with DeHashed placing the exposure around February 2019 and reporting a larger record count. The figures above follow the investigation team's indexed fields, and the discrepancy has not been resolved through an official company statement.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present in all 1,546,923 records reviewed.
Passwords, present in 1,546,310 records.
Breach-monitoring services that cataloged the incident, including Mozilla Monitor and North IT, additionally report that the exposed data included usernames, IP addresses, dates of birth, and passwords stored as salted MD5 hashes. These fields come from external listings rather than the index, and we could not independently verify them against the original data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk involves passwords. Salted MD5 is an older, fast hashing method, and security researchers widely consider it vulnerable to cracking attempts. If a password hash can be recovered, an attacker could try it against the victim's email account or any other service where the same password was reused.
Email addresses and usernames are also valuable for phishing. Criminals can use them to send convincing messages that appear tied to the game or its forum, tricking recipients into revealing credentials or clicking malicious links. Dates of birth and IP addresses, if present, add material for identity-based scams and account-security questions.
Because this incident followed a 2016 breach of the same community, long-time members may have older credentials exposed twice, which increases the chance that reused passwords will match leaked records.
What Should You Do If You Were Affected?
Change your Flash Flash Revolution password immediately, and change it anywhere else you reused it.
Use a long, unique password for each account, ideally with a password manager.
Turn on two-factor authentication wherever the service offers it, especially for your email account.
Watch for phishing emails that reference the game, its forum, or the breach itself, and avoid clicking links in unexpected messages.
