Reborn Gaming Store unauthorized-access data incident

Unauthorized remote access to the Reborn Gaming Store backend through a vulnerability that Reborn Gaming described as affecting cPanel and WHM. Store-login data that Reborn Gaming said may have been accessed, with a separately measured HIBP corpus.

Last modified

Summary

  • Environment: Reborn Gaming Store
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized remote access to the Reborn Gaming Store backend through a vulnerability that Reborn Gaming described as affecting cPanel and WHM. [2]

Impact

Store-login data that Reborn Gaming said may have been accessed, with a separately measured HIBP corpus. [2]

Documented data types include:

  • Contact information — Email addresses that Reborn Gaming said may have been accessed. [1][2]
  • Usernames and account identifiers — Steam names and Steam IDs that Reborn Gaming said may have been accessed; this does not imply Steam credentials were exposed. [1][2]
  • IP addresses — IP addresses that Reborn Gaming said may have been accessed. [1][2]

A cited record reports 126 records (Unique email addresses represented in HIBP’s verified, organization-submitted corpus; not a Reborn Gaming-confirmed count of affected people, accounts, total rows, or all store users; as of 2026-05-04). [2]

HIBP described the associated dataset as self-submitted by Reborn Gaming and marked the incident record verified and not fabricated. [1][2]

Timeline

  1. Public disclosure

    Date shown on Reborn Gaming’s first-party statement; the page was last edited May 3, 2026.

    [2]
  2. Documented event

    Reborn Gaming reported unauthorized access from 2:20 AM through 2:45 AM EST on April 30, 2026; the canonical date does not normalize that stated EST time to another timezone.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The incident involved Reborn Gaming Store. [2]

Reborn Gaming said attackers obtained unauthorized remote access to its store backend through an authentication-bypass vulnerability affecting cPanel and WebHost Manager. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Reborn Gaming said it patched and secured the vulnerability, removed unauthorized access, reviewed affected systems, and increased monitoring and security controls. Reborn Gaming said it identified and contained the issue and restored full control of the affected systems. Reborn Gaming said no passwords or payment methods were compromised and that its store neither processes nor stores payment details or passwords. Reborn Gaming said Stripe and Steam, the third-party services on which its store relies, did not experience this security incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]