NationStates confirmed a data breach after an unauthorized user achieved remote code execution (RCE) on the game’s production server while testing a newly reported vulnerability. The intruder was described as a long-time community member and prior vulnerability reporter who “crossed a line” by moving beyond authorized testing, enabling access sufficient to copy application code and exfiltrate user data; the site was taken offline for investigation and remediation, and the operator stated it is treating the system and data as compromised because deletion claims cannot be verified.
Reporting attributes the root cause to a flaw in the relatively new “Dispatch Search” feature (introduced 2025-09-02), where insufficient input sanitization combined with a double-parsing bug enabled the exploitation chain leading to RCE. Exposed data reportedly includes email addresses, MD5 password hashes, IP addresses, browser User-Agent strings, and potentially some internal messaging content; the disclosures state no financial or real-world identity data was involved. NationStates indicated it is rebuilding or hardening infrastructure and security controls and has reported the incident to authorities, while technical analysis details the attack path and mitigations based on primary-source evidence.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
As part of remediation, NationStates said it would accelerate migration away from MD5 to a modern password hashing algorithm and urged users to change any reused passwords. It also planned additional security improvements and user data review options once the site returned.
After confirming the compromise, NationStates reported the incident to government authorities and began rebuilding systems on new hardware while auditing and hardening code. The company said it was treating the server and data as fully compromised because it could not verify the attacker's claim that the copied data was deleted.
NationStates publicly confirmed the breach and shut down the game site to investigate and remediate the incident. The company said exposed data included email addresses, MD5-hashed passwords, IP addresses, browser User-Agent strings, and possibly some private telegram content.
A player and prior bug reporter reported a critical vulnerability on NationStates but exceeded authorized testing boundaries on January 27, 2026, achieving remote code execution on the production server and copying application code and user data.
NationStates introduced the "Dispatch Search" feature, which later proved to contain insufficient input sanitization and a double-parsing bug that could be chained into remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.