Data breach
Lord of the Rings Online
- Records
- 746,053
- Breach date
- 1 January 2013Estimated
- Added
- 29 January 2025
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses746,053
- Passwords740,287
About this breach
In 2013, the data of roughly 746,000 Lord of the Rings Online players surfaced in a breach linked to the massively multiplayer online game, according to the investigation team. The team estimates the attack occurred around January 1, 2013. The listing was added to the database on January 29, 2025. No hacking group has claimed responsibility for the breach.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Secondary reporting has described the breach differently in some places. CyberInsurance.com's breach database says the game was breached in August 2013 and that more than 1.1 million player accounts were stolen and traded on underground forums. A listing on Leaked.Domains cites a similar figure of over 1.1 million accounts and describes the exposed data as including email addresses, birth dates, and password hashes, with the passwords stored using the outdated MD5 hashing method. The discrepancy may reflect how the data was collected, deduplicated, or split across multiple leaks, but neither explanation can be confirmed from the available record.
It is worth noting that Lord of the Rings Online's developer, Turbine, had a documented security incident before this breach. In 2011, Tweakers reported that the game's account database and official forum were left accessible over the internet without login credentials and were also vulnerable to SQL injection. Turbine took the database and forum offline after players reported the problem. Whether that earlier incident and the 2013 leak are connected has not been established.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (746,053 records) and passwords (740,287 records).
Not every individual is affected by every type of data listed here.
Nearly every record in the data set includes an email address. A small number of records, about 5,700, appear without a corresponding password. Secondary reporting cited above suggests passwords in related copies of this leak were hashed with MD5, a method that modern hardware can crack quickly, rather than stored in plain text or protected with a stronger modern algorithm.
What Are the Potential Risks for Affected Individuals?
The main risk from this breach is credential abuse. If you used the same password on Lord of the Rings Online as you did on your email, banking, shopping, or social media accounts, attackers can try those combinations elsewhere. This technique, known as credential stuffing, works because people reuse passwords across sites.
Leaked email addresses also fuel phishing. Attackers who know a person played Lord of the Rings Online can send convincing fake messages about account suspensions, game updates, or subscription problems to trick them into handing over login details or payment information.
If the passwords were indeed protected only by MD5 hashing, as secondary reporting indicates, attackers can recover the original passwords for a large share of accounts with modest effort.
What Should You Do If You Were Affected?
Change your Lord of the Rings Online password immediately, and choose a password you have never used anywhere else.
If you reused that password on other sites, change it on every one of them, starting with your primary email and financial accounts.
Turn on two-factor authentication for the game account and for your email account if the services offer it.
Be wary of emails referencing Lord of the Rings Online, especially anything asking you to log in through a link. Type the site's address into your browser instead.
Check whether your other accounts show unexpected logins or password reset requests.
