Data breach
Ubisoft Forum
- Records
- 90,892,045
- Breach date
- 1 January 2014Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses90,892,045
- Passwords90,872,918
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Hackers broke into Ubisoft's systems and stole a database containing usernames, email addresses, and encrypted passwords, the game publisher disclosed in July 2013. The listing tied to the Ubisoft Forum contains 90,892,045 records, of which 90,872,918 include a password, with email addresses present throughout the data. The team estimates the attack occurred around January 1, 2014, though Ubisoft's own public disclosure of a breach came in July 2013. No hacking group has claimed responsibility, and the exact date of the intrusion remains unclear. Most of the records predate modern account-security practices, and the full set of records indexed does not match any single confirmed disclosure by Ubisoft, so the provenance of the full dataset is not settled.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
July 2, 2013: Ubisoft asked customers to reset their account passwords after discovering that an unknown attacker breached its systems, according to reporting by ZDNet.
July 3, 2013: Security researcher Sorin Mustaca, writing after Ubisoft's announcement, noted that the company's notice confirmed usernames, email addresses, and hashed passwords were compromised, and reported the advisory via the Avira TechBlog in a post on his site.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Ubisoft's own security notice from the disclosure period, as quoted in contemporaneous reporting, said the compromised database contained usernames, email addresses, and encrypted passwords. The company said passwords were stored not in plain text but as obfuscated values that could not be reversed, though it acknowledged weak passwords could still be cracked. Ubisoft also stated that no personal payment information was stored on the affected servers and that, to its knowledge, no phone numbers or physical addresses were accessed.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses paired with passwords are the raw material for several common attacks. If passwords were hashed with an older or unsalted method, attackers can run automated cracking tools against weak or common passwords. Even where cracking fails, stolen email and password pairs are frequently tested against other websites, a technique known as credential stuffing, because many people reuse the same password across accounts. Affected users may also see more phishing emails, since a valid email address linked to a gaming account makes a scam message more convincing.
The practical stakes go beyond the Ubisoft account itself. A password reused on email, banking, or shopping sites can give criminals access to far more sensitive services than a game forum ever held.
What Is Ubisoft Forum Doing in Response?
Ubisoft's verified response came at the time of its 2013 disclosure. The company posted a notice titled "Security update regarding your Ubisoft account, please create a new password," emailed customers, and forced password resets across its accounts. It also said it was investigating with the help of authorities and external security experts, and confirmed that its Uplay services and servers were not hacked. Ubisoft has not issued a separate public notice addressing the full 90.9 million record dataset indexed by the investigation team, as of September 25, 2026.
What Should You Do If You Were Affected?
If you had a Ubisoft forum or Uplay account in the early 2010s, change your Ubisoft password now, even if you believe you already did so years ago. Choose a unique password you do not use anywhere else, and turn on two-step verification if you have not already. If you reused that password on other sites, change it there too. Watch for phishing emails that reference Ubisoft, and never click password-reset links in unexpected messages.
