From their post:
- Hackers gained access to certain personal player data contained in certain EU West and EU Nordic & East databases ; as a security precaution, we’re emailing all players on these platforms
- The most critical data accessed included email address, encrypted account password, summoner name, date of birth, and – for a small number of players – first and last name and encrypted security question and answer
As HackerNews user jemfinch points out, LoL’s stating how many accounts shared password hashes implies the passwords were not salted before hashing.
We compared encrypted password hashes and discovered that 11 passwords were shared by over 10,000 players each
Other discussions: