NationStates
Disclosed Jan 30, 20267 months agoUnverified
NationStates takes game offline after player exploits RCE and copies user data
Browser game NationStates confirmed a player chained bugs in its Dispatch Search feature to run code on production servers and copy email addresses, MD5 password hashes, IP addresses and some private telegram data. The site was taken offline to be rebuilt.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jan 30, 2026 |
| Discovered | Jan 27, 2026 |
| Attack | Hacking |
| Data exposed | Emails, Passwords, IP addresses, Messages |
| Sector | Gaming |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| NationStates confirms data breach, shuts down game sitebleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jan 30 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.