← Blog

NationStates: RCE Exposes Emails, MD5 Hashes, Login Data

Share on X

NationStates, the long-running browser-based government simulation game, confirmed a January 2026 breach after a vulnerability report escalated into unauthorized remote code execution on its production server. Reporting by BleepingComputer and the operator's breach notice described a bug chain involving insufficient input sanitization in a newer Dispatch Search feature plus double parsing, allowing the reporter to copy application code and user data.

The exposed categories included email addresses, historical emails, MD5 password hashes, login IP addresses, browser User-Agent strings, and likely some internal telegram/private-message content. NationStates said it does not collect real names, physical addresses, phone numbers, or credit cards.

Canonical record: NationStates 2026 breach on BreachHistory.

Sources: BleepingComputer, NationStates breach notice archive