Data breach
Onverse
- Records
- 500,585
- Breach date
- 1 January 2016Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses500,585
- Passwords500,524
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In January 2016, Onverse, an online virtual world game where players build avatars and explore 3D environments, was hacked, exposing user account information. The investigation team has indexed the incident as containing roughly 500,585 rows, nearly all of which include an email address and a password. No individual or group has publicly claimed responsibility for the attack, and details about how the breach occurred remain scarce.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
January 1, 2016: The breach of Onverse is estimated to have occurred on this date, according to both the investigation team and a Mozilla Monitor listing for the incident.
September 6, 2016: Mozilla Monitor states the breach was discovered, verified, and added to its database on this date, several months after the estimated attack.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
The Mozilla Monitor listing for this incident also describes usernames and IP addresses among the compromised data, in addition to the email addresses and passwords found in our own analysis.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from a breach like this is credential reuse. Many people use the same email and password combination across multiple websites, including email providers, banking sites, and social media. If an Onverse password matches a password used elsewhere, attackers can gain access to far more important accounts than a gaming profile.
This kind of stolen credential data is commonly used in credential stuffing attacks, where automated tools try exposed email and password pairs against hundreds of other services until something works. Exposed email addresses also make recipients targets for phishing messages that appear more convincing because they can reference a service the victim actually used.
Because Onverse accounts in 2016 were tied to a virtual world rather than financial services, the direct harm from the original hack may be limited. The knock-on risk to other accounts is what makes this listing worth taking seriously years later.
What Should You Do If You Were Affected?
If you had an Onverse account, take these steps:
Change your Onverse password if the account still exists, and make the new one unique to that service.
Check other accounts that share the same or a similar password and update any that match. Prioritize your email account first, since it often controls password resets for everything else.
Turn on two-factor authentication wherever it is offered, especially for email, banking, and social media.
Be alert to phishing. Emails referencing Onverse or claiming your account was compromised can be a lure. Avoid clicking links in unexpected messages and go directly to a website by typing its address instead.
Consider a password manager to generate and store a distinct password for every account, which prevents one breach from unlocking many doors.
