Data breach
TheWarInc
- Records
- 761,851
- Breach date
- 1 January 2012Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses761,851
- Passwords761,649
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A forum database belonging to War Inc., an online game operated at thewarinc.com, surfaced with the account records of hundreds of thousands of players attached to it. According to our investigation team, the listing covers 761,851 rows containing email addresses, and 761,649 of those records also include passwords. Our team estimates the attack occurred around January 2012, while Mozilla Monitor records the War Inc. breach as occurring on July 4, 2012. The data later circulated on underground forums, and our team added the listing to its index on December 1, 2024.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
July 4, 2012: Mozilla Monitor records this as the date the War Inc. breach occurred.
November 7, 2016: Mozilla Monitor added the breach to its database after it was discovered and verified, noting that credentials can take months or years to surface publicly.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, 761,851 records
Passwords, 761,649 records
Not every individual is affected by every type of data listed here.
The HEROIC security company, which examined samples of the leaked data, reported that the passwords were stored in the hashed format used by the vBulletin forum software and that usernames were present alongside the email addresses. Hashed passwords are not stored in plain text, but older hashing methods can be cracked, so the original passwords may be recoverable by attackers.
What Are the Potential Risks for Affected Individuals?
The main risk here is password reuse. Many people use the same email and password combination across multiple sites, and email-password pairs from old gaming breaches have been recycled for years in credential stuffing attacks, where automated tools try leaked logins against banking, shopping, and social media accounts.
Because the passwords were hashed with a dated method, attackers may be able to convert a meaningful share of them back into plain text. Once they do, the email addresses in the same records give them ready-made login targets. Affected users could also receive phishing emails, since the leak confirms which addresses were active on a gaming platform in 2012.
There is no indication that payment details, names, or home addresses were part of this particular forum database.
What Should You Do If You Were Affected?
Change your password anywhere you reused the password you used on the War Inc. forums, starting with your email account. Your email is the key to resetting almost everything else.
If you still use that email address, consider that it has been public for over a decade and be skeptical of any email referencing War Inc., War Z, or old gaming accounts.
Turn on two-factor authentication wherever it is offered, especially for email, banking, and shopping accounts.
Use a password manager so that every account gets a unique password going forward.
Because this breach is old, some affected people may have long since abandoned the email addresses involved. Those addresses can still be valuable to attackers, however, because mail services recycle them and password reuse persists.
