LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Divine Skins Data Breach (2026)

MEDIUM severityConfirmedHow we verify

Divine Skins Data Breach (2026): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 13, 2026

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Divine Skins Data Breach (2026)

Reported March 13, 2026. Approximately 106K people affected.

MEDIUM
Severity
106K
People affected
3
Data types exposed
March 13, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Divine Skins disclosed a data breach on 13 March 2026 affecting 106 000 individuals. The exposed records include email addresses, usernames, and purchase details; anyone who created an account with the company should verify their status and consider changing passwords or enabling additional account protections.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Divine Skins Data Breach (2026) breach?
106K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On March 13, 2026, Divine Skins disclosed a data breach that affected 106,000 users of its League of Legends custom skins service. An unauthorised third party accessed part of the company’s systems, deleted all skins from the database, and exposed email addresses, usernames, and records of user purchases. The company announced the incident through its Discord server. The event adds to the steady stream of incidents involving online platforms that store customer account and transaction details. Public records of the breach remain limited to the company’s statement, with no further technical details released at the time of reporting.

Inside the incident

Divine Skins stated that the intrusion occurred in March 2026. The unauthorised party gained access to part of the service’s systems, removed the entire collection of custom skins from the database, and made email addresses, usernames, and purchase histories available. The disclosure was posted on the company’s Discord server on March 13, 2026. No information has been published about the method of entry, the duration of access, or whether additional data was taken.

How a breach like this happens

Incidents involving unauthorised access to online service databases often begin with the exploitation of remote access points, weak authentication controls, or unpatched software components. Once inside, an attacker may locate customer records stored for account management and transaction processing. In some cases the intruder also alters or deletes files as part of the activity. Public reporting on any single event rarely includes the precise sequence until forensic findings are shared by the affected organisation.

About Divine Skins

Divine Skins operates a service that supplies custom skins for the game League of Legends. Users register accounts, select items, and complete purchases through the platform. Companies of this type routinely maintain records that link an individual’s contact information to their transaction history and chosen username. A breach at such a service therefore touches both personal identifiers and evidence of commercial activity.

The information in question

The company’s statement lists three categories of data as exposed: email addresses, usernames, and purchase histories. It is not known whether additional fields, such as passwords, payment card details, or full names, were present in the accessed portion of the database. Organisations in this sector commonly store the data types named in the disclosure, yet the precise contents of the exposed records remain unconfirmed beyond the published summary.

What's at stake

Exposed email addresses and usernames can be used to craft targeted messages that appear to come from the service or related platforms. Purchase records may reveal patterns of spending that could be referenced in follow-on attempts to gain further information. For the organisation, the deletion of its skin database represents an immediate operational loss, while the exposure of customer records creates longer-term obligations around notification and account security. The scale of 106,000 affected users means these issues apply across a sizable group rather than isolated individuals.

If your data was in this breach

Individuals who used Divine Skins should review the email account associated with the service for any unexpected messages and consider changing the password on that account as well as any other service where the same credentials may have been reused. Enabling multi-factor authentication where available adds a further control. Readers can also run a free exposure scan of their email address against known breach data sets to check whether their information appears in this or other publicly documented incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyDivine Skins security record
74/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Divine Skins’s full breach history →

More recent breaches

Moody Bible Institute Data Breach (2026)June 15, 2026Sysco Data Breach (2026)June 15, 2026JCPenney Data Breach (2026)June 12, 2026American Tower Data Breach (2026)June 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Divine Skins Data Breach (2026) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram