Last updated 1 month ago
In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach that exposed 126,293 records. The incident was confirmed by the service operator, who advised that the issue has since been fixed. The breach exposed email addresses, usernames, dates of birth, and bcrypt password hashes.
The attack vector remains unspecified, but the exposed data suggests unauthorized access to the server's database. The use of bcrypt hashing for passwords indicates a reasonable security measure, though the exposure of plaintext email addresses and dates of birth increases the risk of targeted phishing and identity theft. No threat actor has been attributed.
The service operator confirmed the breach and stated that it has been fixed. No further details on remediation or regulatory involvement have been disclosed.
Data breach exposing email addresses, usernames, dates of birth, and bcrypt password hashes
The Dragonica Lunaris breach underscores the importance of securing private game servers against unauthorized access. The exposure of bcrypt-hashed passwords, while better than plaintext, still requires robust password policies and monitoring for credential stuffing. The inclusion of dates of birth alongside email addresses heightens the risk of targeted social engineering, suggesting that data minimization and access controls should be reviewed.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector