Earth 2 Data Breach (2024): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Earth 2 disclosed a data breach on October 16, 2024, affecting 421,000 users whose email addresses and usernames were exposed. Anyone who has an account with the service should check whether their data was included and take appropriate protective steps.
In October 2024, roughly 421,000 unique email addresses linked to accounts on the virtual-world platform Earth 2 became available after they were derived from embedded Gravatar images that also carried player usernames. For anyone who has used the service, the practical question is straightforward: whether those addresses and names now sit in places where they can be collected, sold, or used for phishing and account-takeover attempts. Public reporting makes clear that passwords and financial details were not part of the exposure, yet the combination of email and username still creates a usable starting point for social-engineering campaigns.
The incident was reported on 16 October 2024. Earth 2 has stated that the underlying Gravatar feature has since been disabled on its platform. What follows is a factual account of what is known, how such exposures typically arise, and the concrete steps people can take if they believe their data is involved.
Inside the incident
According to the reported summary, 421,000 unique email addresses belonging to Earth 2 users were obtained by reverse-engineering MD5 hashes that Gravatar embeds in avatar image links. Those hashes appeared alongside the corresponding player usernames inside services that consumed the images. The root cause was therefore tied to the way Gravatar publicly presents avatar URLs rather than to a conventional database dump or credential-stuffing attack against Earth 2 itself.
Earth 2 advised that the feature responsible for embedding the hashes has now been disabled on its platform. The same reporting states that the incident did not expose any further personal information, passwords or financial data. No additional technical details—such as the precise window during which the hashes were harvestable, the identity of any party that collected them, or the subsequent distribution of the list—have been disclosed in the available record.
How a breach like this happens
Incidents of this type usually begin with a design choice that treats a cryptographic hash of an email address as a convenient public identifier. Gravatar and similar avatar services generate an MD5 hash of a user’s email so that any website can request a profile picture without storing the address itself. When that hash is left visible in image URLs or page source, anyone who can collect the hashes can attempt to reverse them—either by looking them up in pre-computed rainbow tables or by testing against large lists of known email addresses.
Once a match is found, the recovered email can be paired with any username or display name that appears next to the avatar. The resulting list is then typically offered for sale, posted on leak sites, or used directly for credential-stuffing and phishing campaigns. Because the original service never intended the hash to be secret, the exposure often occurs without a classic “hack” of the platform’s servers; the data simply becomes harvestable through ordinary web traffic. Organisations that later disable the feature can stop new collection, but any hashes already gathered remain outside their control.
Earth 2 and its sector
Earth 2 is a browser-based virtual-earth platform on which users claim, buy and develop digital parcels of land that map onto the real planet. Like other metaverse and virtual-property services, it maintains user accounts that link email addresses to in-game identities, land holdings and transaction histories. The sector as a whole routinely holds contact details, usernames, wallet addresses and sometimes payment-method tokens—information that, if exposed, can be used to target players with fraudulent land offers, phishing messages that impersonate the platform, or attempts to take over accounts that hold valuable virtual assets.
A breach affecting hundreds of thousands of accounts therefore carries consequences beyond simple spam: it can undermine trust in the platform’s ability to protect the digital identities that players use to manage real-money investments. Even when only emails and usernames are confirmed as exposed, the association of those identifiers with a specific virtual-world community gives attackers a ready-made list of people who are known to be active in that ecosystem.
The information in question
The facts name two data types as exposed: email addresses and usernames. The reported figure is 421,000 unique email addresses, each appearing alongside the corresponding player username. The same summary states explicitly that no further personal information, passwords or financial data were exposed in this incident.
Organisations of this kind typically also store additional profile fields, land-ownership records and payment references, but those categories are not listed among the exposed data. Because the public record does not confirm their involvement, any claim that they were compromised would be unfounded. The only verified contents remain the email–username pairs derived from the Gravatar hashes.
What's at stake
For affected individuals the immediate risks are phishing and account-takeover attempts that reference their Earth 2 username to appear legitimate. An attacker who knows both the email and the in-game name can craft messages that look as if they come from the platform itself—password-reset notices, land-sale alerts or security warnings—raising the chance that a recipient will click a malicious link or enter credentials on a fake site. Because the emails are unique and already linked to an active gaming account, they also become more valuable on secondary markets that specialise in targeted lists.
For Earth 2 the stakes include reputational damage and the cost of supporting users who later report unauthorised activity. Even though the company has disabled the Gravatar feature, the already-collected list cannot be recalled. Continued monitoring for secondary use of the data, clear communication with users, and reinforcement of account-security features are the practical measures available once the initial exposure has occurred.
What to do if you're exposed
If you have ever registered an account on Earth 2, treat the possibility that your email and username appear in the 421,000-record set as real until you can check otherwise. Practical first steps include:
- Change the password on your Earth 2 account and enable any available multi-factor authentication.
- Review recent login activity and land-transfer history for signs of unauthorised access.
- Be sceptical of any unsolicited email that mentions your Earth 2 username or offers urgent account actions; verify through the official site instead of clicking links.
- Use a unique password for Earth 2 that is not reused on email, banking or other gaming services.
- Monitor the email address associated with the account for an increase in phishing or spam.
Readers can also run a free exposure scan of their email address to check whether that address has already surfaced in known breach data sets. Doing so provides an independent signal of whether further monitoring or password changes are warranted. Stay alert, but avoid panic: the confirmed exposure is limited to emails and usernames, and timely defensive steps sharply reduce the chance of follow-on harm.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Speedio Data Breach (2024)Young Living Essential Oils Data Breach (2024)Senior Dating Data Breach (2024)FlipaClip Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the Earth 2 Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.