Facepunch Data Breach (2016): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Facepunch Data Breach (2016) (reported June 3, 2016) exposed Dates of birth, Email addresses, IP addresses and Passwords belonging to roughly 343K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach was reported on 3 June 2016. Records indicate that usernames, email addresses, IP addresses, dates of birth and salted MD5 password hashes were taken from Facepunch systems. No further technical details about the method of access or the duration of the intrusion have been made public. Facepunch confirmed awareness of the incident and said notifications were issued to users at the time.
How a breach like this happens
Incidents involving the exposure of user account data often begin with an attacker obtaining unauthorised access to an organisation’s servers or databases. Once inside, the attacker may copy files containing account records before the activity is detected. In many cases the precise entry point, such as a compromised credential, unpatched software or misconfigured service, remains undisclosed after the event.
Who is Facepunch?
Facepunch is a game development studio that operates online platforms for its titles. These platforms require users to create accounts, which typically store identifiers such as usernames and email addresses together with technical details like IP addresses. A breach at such a company can therefore affect a large number of individuals who registered for access to its games or community features.
The information in question
The data set associated with the incident contains usernames, email addresses, IP addresses, dates of birth and salted MD5 password hashes. The exact scope of any additional fields that may have been present in the original database has not been confirmed publicly. Organisations of this type commonly hold only the minimal account information needed for registration and login.
The real-world impact
Exposed email addresses and usernames can be used for targeted phishing or to test whether the same credentials appear on other services. Password hashes, even when salted, may be subject to offline cracking attempts, potentially allowing account access if users reused those passwords elsewhere. Dates of birth and IP addresses add further context that could assist in account recovery fraud or more precise targeting. For the organisation, the event requires notification, investigation and remediation work that consumes resources and can affect user trust.
If your data was in this breach
Individuals who believe their information may have been included should change the password on their Facepunch account and on any other service where the same password was used. Enabling two-factor authentication where available adds a further layer of protection. Monitoring email accounts for unexpected login attempts or password-reset messages is also advisable. Readers can run a free exposure scan of their email address against known breach data sets to check for appearances in this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Anti Public Combo List Data Breach (2016)Ethereum Data Breach (2016)PayAsUGym Data Breach (2016)MrExcel Data Breach (2016)Latest breaches
Read GalaxyWarden’s full analysis of the Facepunch Data Breach (2016) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.