Data breach
lotro.com
- Records
- 746,053
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses746,053
- Passwords740,287
About this breach
Our investigation team indexed the entry, tied to the game's website, lotro.com, on December 1, 2024, with an estimated attack date of January 1, 2020. The listing covers 746,053 records, including 746,053 email addresses and 740,287 passwords. No hacker group has claimed the breach.
The dating deserves a caveat. Independent breach trackers list Lord of the Rings Online data with breach dates in mid-2013, including LeakCheck, which shows roughly 960,000 entries dated July 2013, and the 9Ghz breach list, which lists about 1.36 million records dated August 1, 2013. The 2020 estimate in our catalog may reflect when the data was compiled or recirculated rather than when the original attack occurred. The game was developed by Turbine at the time of the older incident and is now operated by Standing Stone Games. There is no confirmed link between this listing and a 2011 forum security issue that Turbine disclosed publicly, which MCV reported on October 19, 2011, when the developer took the game's forums offline and advised players to change their passwords.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: passwords and email addresses.
Not every individual is affected by every type of data listed here.
The catalog does not state whether the passwords were stored in plain text or in hashed form, so the real exposure could vary.
What Are the Potential Risks for Affected Individuals?
Email and password pairs are the raw material for credential stuffing. Attackers take combinations stolen from one site and test them against other services, because many people reuse the same password across accounts. If a leaked password also protects an email inbox, a bank account, or a work login, the damage can reach well beyond the game itself.
Stolen email addresses also fuel phishing. Someone who knows your address and that you play a particular game can craft convincing messages that appear to come from the game's support team, asking for login details or payment information. Even users whose passwords were not included in the listing can be targeted this way.
What Should You Do If You Were Affected?
Change your Lord of the Rings Online password first, and pick something you do not use anywhere else. If you reused that password on other sites, change it there too, starting with your email account. Turn on any multi-factor authentication option the service or your email provider offers. Be skeptical of unexpected emails about your game account, especially those linking to login pages, and reach the company through its official support site rather than through links in a message. Watch your other accounts for sign-in attempts you did not make.
