Forum Data Breach

If you used Google to log in, you SHOULD BE SAFE!! This only applies to users who use email verification to log in!

Dear SwordBattle.io Community,

We are writing to inform you about a recent security incident that has occurred on our forum platform. We regret to inform you that our forum database has been compromised, and as a result, there is a possibility that user IPs and other forum info may have been leaked. We take this matter very seriously and want to provide you with all the information we have regarding the incident.

Upon discovering the breach, our team immediately launched a thorough investigation to assess the extent of the incident and identify the potential impact on our users. While we have no evidence at this time to suggest that any personal information beyond IP addresses was accessed or misused, we believe in transparency and want to ensure you have all the facts.

What Happened? Our initial findings indicate that an unauthorized party gained access to our forum’s database through a vulnerability in our security measures. This allowed them to potentially obtain user IPs. We have since patched the vulnerability and implemented additional security measures to prevent similar incidents in the future.

We recommend to change your password immediately or enable 2FA on your forum account just as a security precaution


What Information Was Compromised? The primary data that may have been accessed during this breach is user IP addresses and other user information like emails, personal chats with other users, and maybe encrypted password hashes (not the password itself). Rest assured that we do not store any sensitive information on our forum platform, so everything should be safe for you unless you shared or posted any sensitive information here.

Your Privacy and Security Matter At SwordBattle.io, we understand that your privacy and security are of paramount importance. We deeply apologize for any inconvenience or concern this incident may have caused. We remain committed to upholding the highest standards of data protection and will continue to enhance our security measures to safeguard your information.

If you have any questions or require further assistance, please don’t hesitate to reach out to our support team at [email protected]. We are here to help you.

We sincerely appreciate your understanding and ongoing support. We will continue to keep you updated on any significant developments regarding this incident. Thank you for being part of the SwordBattle.io community.

Stay safe and battle on!

UPDATE

After more investigation done by the team, we have found IPs, and encrypted passwords (NOT THE ACTUAL PASSWORD) have been leaked. From what we have seen emails have not been leaked though.

Just for safety, reset your password ASAP to a secure password. If you need assistance contact [email protected] .

If you used Google to log in, you SHOULD BE SAFE!! This only applies to users who use email verification to log in!

18 Likes

Note, this does not affect anything in-game!! Only the forum. And we haven’t confirmed that any of this data has been stolen, it just could have been stolen. So

We just recommend you to reset your password immediately just incase as a precautionary message.

8 Likes

For those who don’t know, You can reset your password by going into your preferences, then your security. It will send a password change email. Heres a link.

9 Likes

Will you be taking any measures to make sure that this does not happen again?

5 Likes

We have conducted a comprehensive security audit to identify any other potential vulnerabilities. We are working diligently to fortify our platform’s security to prevent similar incidents in the future. Also we will be advising moderators and staff on how to prevent further social engineering attacks like this.

8 Likes

Thank you for notifying everyone

6 Likes

ruh roh

1 Like

how did he hack forum i thought discourse was completely safe and secure an if it was a bug did you report it

1 Like

No software is perfect. And it was not a bug

6 Likes

Was a backup obtained?

1 Like

Thats something he would need to check. Either way only posts, messages, chats, and uploads are included so no emails, Ips etc

6 Likes

I thought backups included the entire database.

4 Likes

No they do not

5 Likes

Do any one know who the hacker was?

4 Likes

Yes we do

6 Likes

We do and they are now removed

8 Likes

can I know :o

1 Like

Ask coder if the info is allowed

No sorry

3 Likes

UPDATE

After more investigation done by the team, we have found IPs and encrypted passwords (NOT THE PASSWORD ITSELF) have been leaked. From what we have seen emails have not been leaked though.

Reset your password imminently to a secure password just to be safe. If you are using Google Login, you should be safe

11 Likes