Data breach
Heroes of Newerth
- Records
- 6,973,784
- Breach date
- 17 December 2012Estimated
- Added
- 5 February 2025
What was exposed
2 types of data · 1 more reported
- Usernames6,923,811
- Email addresses6,895,498
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In December 2012, the multiplayer online battle arena game Heroes of Newerth suffered a data breach that exposed millions of player accounts. According to our investigation team, the listing contains roughly 6.97 million rows, including about 6.92 million nicknames and about 6.9 million email addresses. The estimated attack date is December 17, 2012. Outside records, including Mozilla Monitor, also list passwords among the compromised data, and the game's developer, S2 Games, confirmed at the time that passwords had been stolen.
The breach became public in an unusual way. According to CyberInsurance.com, the attacker claimed credit on Reddit on December 16, 2012, reportedly taunting the company and describing security weaknesses in S2's network. The hacker was described in reporting as a network security engineer from Belarus, and threatened further attacks. S2 Games later acknowledged the breach itself.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
December 16, 2012: The attacker claimed credit for the breach on Reddit, describing security flaws in S2's platform, according to CyberInsurance.com.
December 17, 2012: The breach date listed by Mozilla Monitor; S2 Games publicly acknowledged the incident around this time and posted security responses on its forums.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Nicknames for about 6,923,811 individuals
Email addresses for about 6,895,498 individuals
External breach records, including Mozilla Monitor, additionally list passwords as compromised. S2 Games' own security notice, quoted by CyberInsurance.com, stated that "only passwords were stolen" and that no credit card or billing information was compromised because the company did not store it.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk from an old gaming breach is password reuse. If you used the same password for Heroes of Newerth and for an email account, social media profile, or banking site, attackers who obtain the leaked credentials can try those logins elsewhere. This technique, called credential stuffing, remains one of the most common ways accounts are taken over.
Exposed email addresses also enable targeted phishing. Messages that reference the game or claim to come from its support team can appear more convincing when sent to players of that game. Because the breach is more than a decade old, much of the data has circulated widely, but the underlying risks have not disappeared.
What Is Heroes of Newerth Doing in Response?
S2 Games responded to the breach at the time. According to its security notice quoted by CyberInsurance.com, the company said a third-party software component that interacted with its account database had been hacked, not the game client itself. S2 said it removed the third party's access to sensitive information, upgraded its security systems while the game was offline, and expired all account passwords so that players were forced to create new ones on their next login. The company also warned players to change passwords on any other accounts that used the same credentials.
What Should You Do If You Were Affected?
Change your Heroes of Newerth password if you have not done so since 2012, and change it anywhere else you reused it.
Use a unique password for each important account, ideally with a password manager.
Turn on two-factor authentication wherever it is offered, especially for email and banking.
Be cautious with emails referencing the game, its developer, or account problems, and avoid clicking links in unexpected messages.
Check whether your email appears in this breach using the search tool.
