So this week FC put out a security update:
https://www.eveonline.com/news/view/eve-online-security-update-8-september-2026
I had already heard rumblings of this on the Oz discord but it was good to et some clarity from FC as to what was happening.
Essentially, someone modified their client and used 4 characters to spam over 1 million characters with 0 ISK donations. Something about the response to that deposit call returned the wallet balance of the wallet being donated to. This didn't return other wallet balances other than corp master wallet and personal wallets. So no PLEX balances or anything.
I don't know if donating to a character would also get their corp wallet balance, I would hope not.
I've seen some speculation that the list of users was scraped from zKillboard, but I'm not convinced as my market characters have been affected. I've not done a thorough inventory but all the characters I checked were affected. My industry corp wallet however does not show a donation so might be unaffected.
There is a limit to what someone can do with this information, unless they can map characters to accounts somehow and therefor have targets to hack, or alternatively use the knowledge of who has large wallets to target them for social engineering or phishing. So as the article says you should enable 2FA on your accounts.
Fortunately, none of my characters have more than a few billion in their wallets, so I don't look much like a target which is nice. If they could see PLEX balances that would be a different matter.
Here's hoping this is as far as it goes, but be very careful if you receive suspicious EVEMails or emails from "FC" over the next couple of months!









