---
title: "Reborn Gaming Store unauthorized-access data incident"
description: "Evidence-backed account of Reborn Gaming Store unauthorized-access data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/reborn-gaming-store-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/reborn-gaming-store-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/reborn-gaming-store-data-incident-2026/stix.json"
---

# Reborn Gaming Store unauthorized-access data incident

Unauthorized remote access to the Reborn Gaming Store backend through a vulnerability that Reborn Gaming described as affecting cPanel and WHM. Store-login data that Reborn Gaming said may have been accessed, with a separately measured HIBP corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Reborn Gaming Store
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized remote access to the [Reborn Gaming](https://reborngaming.net/) Store backend through a vulnerability that Reborn Gaming described as affecting cPanel and WHM. [2](#source-2)

## Impact

Store-login data that Reborn Gaming said may have been accessed, with a separately measured HIBP corpus. [2](#source-2)

Documented data types include:

- Contact information — Email addresses that Reborn Gaming said may have been accessed. [1](#source-1) [2](#source-2)
- Usernames and account identifiers — Steam names and Steam IDs that Reborn Gaming said may have been accessed; this does not imply Steam credentials were exposed. [1](#source-1) [2](#source-2)
- IP addresses — IP addresses that Reborn Gaming said may have been accessed. [1](#source-1) [2](#source-2)

A cited record reports 126 records (Unique email addresses represented in HIBP's verified, organization-submitted corpus; not a Reborn Gaming-confirmed count of affected people, accounts, total rows, or all store users; as of 2026-05-04). [2](#source-2)

HIBP described the associated dataset as self-submitted by Reborn Gaming and marked the incident record verified and not fabricated. [1](#source-1) [2](#source-2)

## Timeline

### April 30, 2026 — Public disclosure

Date shown on Reborn Gaming's first-party statement; the page was last edited May 3, 2026. [2](#source-2)

### April 30, 2026 — Documented event

Reborn Gaming reported unauthorized access from 2:20 AM through 2:45 AM EST on April 30, 2026; the canonical date does not normalize that stated EST time to another timezone. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The incident involved Reborn Gaming Store. [2](#source-2)

Reborn Gaming said attackers obtained unauthorized remote access to its store backend through an authentication-bypass vulnerability affecting cPanel and WebHost Manager. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Reborn Gaming said it patched and secured the vulnerability, removed unauthorized access, reviewed affected systems, and increased monitoring and security controls. Reborn Gaming said it identified and contained the issue and restored full control of the affected systems. Reborn Gaming said no passwords or payment methods were compromised and that its store neither processes nor stores payment details or passwords. Reborn Gaming said Stripe and Steam, the third-party services on which its store relies, did not experience this security incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/reborn-gaming-store-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Reborn Gaming breach record

advisory · Have I Been Pwned · May 4, 2026

<https://haveibeenpwned.com/api/v3/breach/RebornGaming>

<a id="source-2"></a>

### Reborn Gaming's Statement on the 4/30/2026 Data Breach

official · Reborn Gaming · Apr 30, 2026

<https://reborngaming.net/threads/6120/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   Reborn Gaming Store member-data exposure: 126 record
2. **Exposed Data Category · 100% confidence · current**  
   Reborn Gaming Store member-data exposure: Contact information
3. **Used Product · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming Store
4. **Disclosed At · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: 2026-04-30
5. **Exposed Data Category · 100% confidence · current**  
   Reborn Gaming Store member-data exposure: Usernames and account identifiers
6. **Resulted In · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming said it patched and secured the vulnerability, removed unauthorized access, reviewed affected systems, and increased monitoring and security controls.
7. **Resulted In · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming said it identified and contained the issue and restored full control of the affected systems.
8. **Resulted In · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming said attackers obtained unauthorized remote access to its store backend through an authentication-bypass vulnerability affecting cPanel and WebHost Manager.
9. **Occurred At · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: 2026-04-30
10. **Resulted In · 100% confidence · current**  
   Reborn Gaming Store member-data exposure: Reborn Gaming said no passwords or payment methods were compromised and that its store neither processes nor stores payment details or passwords.
11. **Affected Organization · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming
12. **Resulted In · 100% confidence · current**  
   Reborn Gaming Store member-data exposure: HIBP described the associated dataset as self-submitted by Reborn Gaming and marked the breach record verified and not fabricated.
13. **Resulted In · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming Store member-data exposure
14. **Exposed Data Category · 100% confidence · current**  
   Reborn Gaming Store member-data exposure: IP addresses
15. **Resulted In · 100% confidence · current**  
   April 2026 Reborn Gaming Store unauthorized access: Reborn Gaming said Stripe and Steam, the third-party services on which its store relies, did not experience this security incident.

</details>
