Mortal Online Data Breach (2018): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Mortal Online Data Breach (2018) (reported June 17, 2018) exposed Email addresses, Names, Passwords and Physical addresses belonging to roughly 607K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The breach occurred in June 2018 and affected the massively multiplayer online role-playing game Mortal Online. A file holding roughly 570,000 email addresses together with cracked passwords appeared online first. A more complete set of records covering 607,000 email addresses, along with original unsalted MD5 password hashes, names, usernames and physical addresses, was subsequently circulated. The data was provided to the Have I Been Pwned service by researcher Adam Davies, and the original listing was updated to reflect the fuller contents.
How a breach like this happens
Incidents involving online service accounts often begin with unauthorised access to a server or database that stores user credentials. Attackers may exploit vulnerabilities in software, weak authentication controls or compromised administrative accounts to extract stored information. Once obtained, password hashes can be processed offline in attempts to recover the original passwords, after which the resulting files are sometimes posted or traded on public or restricted channels.
About Mortal Online
Mortal Online operates as a persistent online role-playing environment in which players create accounts to participate in a shared virtual world. Services of this type routinely collect and retain registration details such as email addresses, chosen usernames and, in some cases, billing or delivery addresses. A breach at such a platform therefore involves records that users supply when creating and maintaining their accounts.
The information in question
The reported data set included email addresses, names, usernames, physical addresses and passwords stored as unsalted MD5 hashes. One version of the material contained cracked passwords derived from those hashes. Public reporting does not specify additional categories of information, and the precise scope of every record remains limited to what was contained in the files that were distributed.
What's at stake
Exposure of email addresses and physical addresses can increase the volume of unsolicited messages directed at affected individuals. Re-use of the same password across multiple services raises the possibility that recovered credentials could be tested on other sites. For the organisation, the incident underscores the long-term consequences of storing user data without modern protective measures such as salted and iterated hashes.
If your data was in this breach
Individuals can change the password associated with their Mortal Online account and avoid reusing that password elsewhere. Enabling any available two-factor authentication on linked services adds a further control. A free exposure scan of an email address against known breach data sets can indicate whether the address has appeared in this or other documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
IIMJobs Data Breach (2018)BannerBit Data Breach (2018)BlankMediaGames Data Breach (2018)Roll20 Data Breach (2018)Latest breaches
Read GalaxyWarden’s full analysis of the Mortal Online Data Breach (2018) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.