← The Breach Files

2023 · Data breach

PlayCyberGames

Breached 9 August 2023 · Published 31 August 2023 · playcybergames.com

3,681,753Accounts exposed
65/100Severe severity
3Types of data
VerifiedBy HIBP

On 9 August 2023, PlayCyberGames was breached. 3,681,753 accounts were exposed, including email addresses, passwords, usernames. MyRecon rates it 65/100, severe. That is about 14% of the population of Australia.

Checked against this breach and every other on record, against public breach data only. Your address is not sent to us as a form and is not stored, it is handed straight to the lookup tool in your own browser. See the privacy policy.

The detail that matters is six words long: MD5 hashes with a constant value in the salt field. A salt that never changes is not a salt. Its entire function is to be different for every record, so that two people who chose the same password do not produce the same hash and one precomputed table cannot be run against the whole file. Fix the value and you have plain MD5 with extra steps.

What makes this instructive rather than merely bad is that it passes inspection. The column exists. The field is populated. The word "salt" appears in the schema, in the code, and presumably in whatever security questionnaire the company answered. Everything is present except the property that made any of it worth doing, which is a far more common shape of failure than having no protection at all.

The last line of the record is the one with consequences for readers: multiple attempts to disclose the breach went unanswered. No reset emails were sent, no notice was published, and 3.7 million people were never told by the company that lost their credentials. If a password from a gaming account of yours is still in use somewhere else, this is the only notification you are going to get.

What happened

In August 2023, PlayCyberGames which "allows users to play any games with LAN function or games using IP address" suffered a data breach which exposed 3.7M customer records. The data included email addresses, usernames and MD5 password hashes with a constant value in the "salt" field. PlayCyberGames did not respond to multiple attempts to disclose the breach.

Breach description from Have I Been Pwned, used under a CC BY 4.0 licence.

Who was behind it

No party has been publicly confirmed as responsible, and this page will not name one. Most breaches are never formally attributed: data surfaces on a forum or inside a combined dump long after the intrusion, and the trail back to a specific actor is rarely made public. Where a group has claimed responsibility it is usually named in the account above, that claim is theirs, not a finding of ours.

What was exposed, and why it matters

What to do if you were in it

  1. Change this password anywhere you reused it, starting with your email account, that is the one that can reset all the others.
  2. Expect better-aimed phishing. A message that already knows your name and where you have an account is the whole point of a breach like this.

Questions people ask about this breach

Was my email address in the PlayCyberGames breach?

Enter it in the box at the top of this page. MyRecon checks it against this breach and every other one on record, and the address is never stored.

What data was leaked in the PlayCyberGames breach?

email addresses, passwords, usernames. Each one is explained above, along with what it means for the person it belongs to.

When did it happen, and when did it become public?

The breach is dated 9 August 2023. It was published to Have I Been Pwned on 31 August 2023, a gap of 22 days during which the data was already out.

Is the PlayCyberGames breach real?

Yes. Have I Been Pwned lists it as verified, meaning the data was checked against the source rather than taken on trust.

How many people were affected?

3,681,753 accounts. That is about 14% of the population of Australia. That is accounts rather than people, one person often has several.

Read next

Also in the archive

Case Files: how the landmark breaches actually happened →

Three kinds of content appear on this page and they are kept apart deliberately. The breach description is quoted from Have I Been Pwned under its licence. The severity score, the field-by-field explanation and the advice are computed from the record itself, every sentence derives from a number or a flag in it, which is what stops the analysis drifting from the evidence. Anything under the "MyRecon's take" byline is editorial: our reading of this breach, presented as opinion rather than as a finding.

← All breaches