Clash of Kings Data Breach (2016): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Clash of Kings Data Breach (2016) (reported July 14, 2016) exposed Email addresses, IP addresses, Passwords and Usernames belonging to roughly 1.6M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Breaking down the breach
The available records show that the breach occurred in July 2016 and involved the forum for Clash of Kings. It impacted 1.6 million user accounts. The exposed fields consisted of usernames, email addresses, IP addresses, and passwords stored as MD5 hashes. No further details on the method of access or the precise timing within the month have been disclosed in public reporting. The dataset was supplied to breach-tracking services by a third party, dehashed.com.
How a breach like this happens
Incidents affecting online forums commonly begin with unauthorized access to web servers or databases that store user account information. Attackers may exploit unpatched software, weak authentication controls, or stolen administrative credentials to reach these systems. Once inside, they can copy tables containing login details and associated metadata. The resulting files are sometimes later shared or sold on data-trading platforms, after which they surface in public breach repositories.
Clash of Kings and its sector
Clash of Kings is a mobile strategy game that maintains an associated online forum for player discussion and account management. Organizations in the online gaming sector routinely collect usernames, email addresses, and IP addresses to support account creation, moderation, and anti-abuse measures. Passwords are stored to enable login verification. A breach at such a service therefore touches the core account infrastructure used by players to access both the forum and, in many cases, linked game profiles.
The information in question
The breach record lists usernames, email addresses, IP addresses, and passwords stored as MD5 hashes. MD5 is a legacy hashing algorithm that does not incorporate modern safeguards such as salting or iteration, which can make reversal more feasible when computational resources are applied. No additional categories of data, such as payment details or full names, are named in the reported facts. The exact scope of any individual record beyond these fields remains unconfirmed.
Why it matters
For individuals whose information appeared in the dataset, the combination of email addresses and hashed passwords can facilitate attempts to access other online accounts that reuse the same credentials. IP addresses can contribute to location profiling or targeted follow-on activity. For the organization, the incident highlights the long-term exposure of user account data once it enters circulation in breach collections. The use of MD5 hashing increases the practical likelihood that some passwords can be recovered from the leaked material.
If your data was in this breach
Begin by changing the password for any Clash of Kings forum account and for any other service where the same password or a close variation was used. Enable multi-factor authentication wherever available. Monitor email accounts for unexpected login attempts or password-reset messages. Individuals can run a free exposure scan of their email address against known breach datasets to determine whether their information appears in this or other publicly tracked incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ethereum Data Breach (2016)Anti Public Combo List Data Breach (2016)PayAsUGym Data Breach (2016)MrExcel Data Breach (2016)Latest breaches
Read GalaxyWarden’s full analysis of the Clash of Kings Data Breach (2016) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.