Data breach
Gamigo
- Records
- 8,234,526
- Breach date
- 1 March 2012Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses8,234,526
- Passwords8,232,924
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early 2012, the German online games publisher Gamigo was hacked, and months later the stolen data surfaced publicly. Our investigation team estimates the breach exposed more than 8.2 million accounts, including roughly 8.23 million email addresses and about 8.23 million passwords. The company, then part of Axel Springer, disclosed the attack to its users in March 2012, but the full cache of credentials did not appear online until July of that year, when it was posted to a password-cracking forum and analyzed by the breach monitoring service PwnedList.
March 1, 2012: Gamigo emailed users to confirm an attack on its database, saying usernames and encrypted passwords had been stolen and that all passwords had been reset. The company's websites and game servers had been offline for "maintenance" in the days around the attack.
July 2012: A file containing roughly 11 million credential entries was uploaded to the cracking forum InsidePro and a file-sharing service. PwnedList identified 8,243,809 unique email addresses in the dump.
July 23, 2012: Forbes reported on the leak, citing PwnedList's analysis of the 478 MB data file.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Contemporary reporting, including coverage by ZDNet and Forbes, described the passwords as encrypted hashes rather than plain text. German technology site heise Security reported that the hashes appeared to be unsalted MD5, a weak method, and that one forum user claimed to have cracked 94 percent of them within a short time. The company's own March 2012 notice to users mentioned stolen usernames as well as encrypted passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger is password reuse. Gamigo forced a reset of all its account passwords in March 2012, so the leaked credentials were unlikely to work on Gamigo's own services by the time the dump went public. But many people reuse the same password, or slight variations of it, across email, banking, shopping, and social media accounts. Anyone whose email and password appeared in the dump could face account takeover at other services.
The weak, unsalted hashing made matters worse. Once attackers crack the hashes, they hold readable passwords linked to real email addresses. PwnedList's analysis found addresses belonging to users in the United States, Germany, and France, including corporate email domains. Even years later, such credentials circulate in lists used for credential stuffing, where attackers automatically try leaked email and password pairs against many websites. The exposed addresses can also be used for targeted phishing, since a message that references a gaming account the recipient actually had is more convincing.
What Is Gamigo Doing in Response?
According to the notice Gamigo sent users on March 1, 2012, the company detected the attack, reset all passwords for its account system and games, and urged users to change passwords on game forums as well. The company said character data and in-game items were safely stored on a backup, and that it could not rule out that the intruder held additional personal data, though it had received no reports of fraudulent use at that time.
In a later statement reported by Forbes and heise Security, Gamigo said it had taken the affected database offline, launched a comprehensive review of its IT security, notified civil authorities, and addressed legal inquiries. The company told heise Security that the leaked data was genuine but came from an older version of its database.
What Should You Do If You Were Affected?
Change your password everywhere you may have used the same one, starting with email and financial accounts.
Use a unique password for each service, ideally generated and stored in a password manager.
Turn on two-factor authentication wherever the service offers it.
Watch for phishing emails that reference gaming accounts or old registrations, and never enter credentials from a link in an email.
In the news
- ZDNet: 8.24 million Gamigo passwords leaked after hackzdnet.com (opens in a new tab)
- Forbes: Eight Million Passwords Spilled From Gaming Site Gamigoforbes.com (opens in a new tab)
- heise Security: 11 Millionen Passwort-Hashes von Gamigo im Netzheise.de (opens in a new tab)
- SC World: Hackers loot German gaming site Gamigo of 8m passwordsscworld.com (opens in a new tab)
