Data Breaches

NationStates shuts down after data breach

0

NationStates, a multiplayer browser-based government simulation game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident.

The game, created by author Max Barry and inspired by his novel Jennifer Government, disclosed that an unauthorized individual gained access to its production server and copied user data.

Vulnerability report turned breach

According to NationStates, the incident occurred on January 27, 2026, at around 10:00 p.m. UTC, when a player reported a critical vulnerability in the game’s application code. While testing the issue, the player exceeded authorized limits and obtained remote code execution (RCE) access to the main production server, enabling him to copy application code and user data.

In a breach notice updated on January 30, Barry explained that the individual was not a staff member and had never been granted permission for server access or elevated privileges. The player had previously submitted around a dozen bug and vulnerability reports since 2021 and had been recognized with a “Bug Hunter” badge for responsible disclosures.

Although the individual later apologized and claimed the data was deleted, NationStates said it has no way to verify this and is therefore treating the system and the data as fully compromised.

The breach was traced to a flaw in a relatively new feature called Dispatch Search, introduced on September 2, 2025. The attacker reportedly chained insufficient input sanitization with a double-parsing bug, ultimately achieving RCE.

Barry noted that this was the first critical vulnerability of its kind reported in the site’s history. While he thanked the player for identifying the bug, he stressed that exploiting it to access the server crossed a clear line. Due to the unauthorized entry, NationStates decided to completely wipe and rebuild the affected server to ensure security.

At the time of testing, the NationStates website was intermittently accessible, showing the breach notice before going offline again.

Data exposed

NationStates confirmed that the exposed data includes:

  • Email addresses (including historical addresses linked to accounts)
  • Passwords stored as MD5 hashes, an outdated and insecure hashing method
  • IP addresses used during logins
  • Browser User-Agent strings
  • Telegrams data (internal private messages), with the company warning that some content was likely exposed

The company emphasized that it does not collect real names, physical addresses, phone numbers, or credit card information.

NationStates expects the site to return within two to five days. Once restored, users will be able to review the data stored for their accounts via the game’s private information page.

The incident has been reported to government authorities. In parallel, NationStates is rebuilding its production environment on new hardware, conducting security audits, strengthening defenses, and upgrading its password security mechanisms.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Notepad++ update traffic hijacked in supply chain attack

Previous article

Citrix NetScaler scans hit via residential proxies

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *