Data breach
NextGenUpdate
- Records
- 1,194,323
- Breach date
- 22 April 2014Estimated
- Added
- 24 July 2026
What was exposed
1 type of data · 3 more reported
- Email addresses1
- PasswordsReported, not counted
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In April 2014, NextGenUpdate, a long-running video game news site and discussion forum, lost account data for roughly 1.2 million registered users. According to our investigation team, the listing contains 1,194,323 rows, and the estimated attack date is April 22, 2014. The data later surfaced on hacking forums, where it was offered for sale. No individual or group has claimed responsibility in connection with this listing.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
April 22, 2014: The breach of NextGenUpdate occurred, according to Mozilla Monitor.
June 5, 2015: After the leak was discovered and confirmed, it was added to Mozilla Monitor's breach database on this date.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses. The number of email addresses present in the indexed records has not been counted, so the exact figure is unknown.
Independent breach listings, including Mozilla Monitor and Cyberinsurance.com, describe the stolen records as also containing usernames, IP addresses, and passwords. One breach reference describes the passwords as salted and hashed, which is a weaker but not worthless form of protection compared with plaintext passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is account compromise. If you reused your NextGenUpdate password on other sites, attackers who obtained this database can try those same credentials against email providers, gaming platforms, and other services. This technique, called credential stuffing, works because many people reuse passwords across accounts.
The email addresses in the leak can also feed targeted phishing. Someone who knows your email address, username, and gaming interests can craft messages that look convincing, such as fake account recovery notices or password reset requests.
IP addresses are a lower-severity exposure, but they can reveal approximate location at the time of registration and help attackers link accounts across different services.
What Should You Do If You Were Affected?
If you had a NextGenUpdate account around 2014, take these steps:
Change your NextGenUpdate password if you still use the site, and pick something unique.
Change passwords on any other account where you used the same or a similar password. Email accounts come first, since they can be used to reset nearly everything else.
Turn on two-factor authentication wherever it is offered, especially for email and any account tied to payments.
Watch for phishing. Be cautious with unexpected emails about account security, and never enter your password through a link in an email.
Consider a password manager so that every account has a distinct, random password you do not need to memorize.
A decade-old forum breach may feel like old news, but leaked databases circulate for years and remain useful to attackers precisely because people have long since forgotten the original incident.
