CSIDB logo
Incident

DayZGame

Incident posture

Attack window
Jan 2016
Location
Czechia
Status
Historical
CIA posture
Available to members
Updated
2025-12-14 00:00

Linked entities

Victim
DayZGame
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The official forums of the DayZ survival game community suffered a security breach by the OurMine hacking group, compromising over 200,000 user accounts. Attackers accessed usernames, email addresses, and hashed passwords due to outdated forum software, prompting developers to warn users, initiate an investigation, and plan migration to a more secure authentication system while advising password changes for affected accounts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The DayZ online forums suffered a security breach on or around January 23, 2016, when hackers from the Saudi Arabian group OurMine infiltrated the platform. OurMine publicly claimed responsibility by posting a visible topic on the forum's main page and sharing a screenshot of their access on their Tumblr account. The attackers compromised a database containing details of over 200,000 registered users, specifically extracting usernames, email addresses, and hashed passwords. The forum software, identified as an outdated version of IPBoard, hosted the vulnerable authentication system. DayZ's development team at Bohemia Interactive first acknowledged the incident publicly through Twitter, warning forum users of the breach while investigations remained ongoing. The standalone survival game, though still in alpha development stages at the time, maintained an active community through these compromised forums.

Following initial detection via the hackers' forum post, Bohemia Interactive launched an investigation confirming unauthorized database access and data exfiltration. The company issued direct communications to all affected forum users, urging immediate password changes and advising against password reuse across other accounts. As a containment measure, developers announced plans to replace IPBoard's native login system with Bohemia's proprietary authentication infrastructure already securing other company services. No evidence suggested compromise beyond forum credentials, though the scale exposed approximately 200,000 accounts. The public response emphasized transparency through Twitter updates, detailing breach confirmation and planned security upgrades without disclosing technical vulnerabilities. User notifications reiterated the theft of hashed passwords while acknowledging operational disruptions to forum services during remediation.

Sources

Sources available to members: 1 source.

CSIDB