HomeIntelligenceBrief
BREACH BRIEF🟡 Medium Breach

Defunct RuneScape Boards Forum Leak Exposes 223k Emails, IPs, and Password Hashes

In December 2011 the RuneScape Boards forum was breached, leaking 222,762 email addresses, usernames, IP addresses and salted MD5 password hashes. The data resurfaced in 2026 via Have I Been Pwned, highlighting lingering credential‑reuse risks for third‑party services.

LiveThreat™ Intelligence · 📅 March 24, 2026· 📰 haveibeenpwned.com
🟡
Severity
Medium
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
haveibeenpwned.com

RuneScape Boards Forum Leak Exposes 223k User Emails, IPs, and Password Hashes

What Happened – In December 2011 the now‑defunct RuneScape Boards (RSBoards) forum suffered a data breach that exposed 222,762 unique email addresses, usernames, IP addresses and salted MD5 password hashes. The compromised data resurfaced in 2026 via the Have I Been Pwned (HIBP) breach feed.

Why It Matters for TPRM

  • Legacy forum platforms can still hold credential data that attackers reuse against current services.
  • Third‑party community sites may be linked to corporate gaming brands, creating a supply‑chain credential risk.
  • Exposure of IP addresses can aid targeted phishing or credential‑stuffing campaigns against partner organizations.

Who Is Affected – Gaming community platforms, SaaS forum providers, and any organization that allowed employees or customers to reuse RSBoards credentials.

Recommended Actions

  • Verify that no current corporate accounts reuse passwords from the RSBoards breach.
  • Enforce password‑reset and MFA for any accounts that share email addresses with the leaked list.
  • Review credential‑reuse policies across all third‑party services.

Technical Notes – The breach stemmed from a vulnerability/exposure in the vBulletin forum software, resulting in the dump of salted MD5 hashes (weak against modern cracking). Data types leaked: email, username, IP address, password hash. Source: Have I Been Pwned – RSBoards breach

📰 Original Source
https://haveibeenpwned.com/Breach/RSBoards

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →