In our last devlog we counted what Reclaim City players did: the passwords changed, the two-factor turned on, the credit frozen. This time we want to look at what they found.
One person checking one inbox for breaches learns something about themselves. Nine thousand people checking their inboxes, each one answering a single question in the debrief, draws a map nobody could draw alone. Here’s the map from the first month.
The checks all ask about an email address, not a mail company. When it says “breached,” that doesn’t mean Gmail got hacked. It means some shop, forum or app where you signed up with that address got hacked, and your address was in the stolen data.
Gmail addresses are often old, and they’re the ones people type into every sign-up form for a decade. Each of those sites is another place your address can leak from. ProtonMail addresses tend to be newer, and the people who make them tend to be careful about where they hand them out. We can’t untangle those two reasons from here. What it shows is that the address you give out everywhere ends up in breaches everywhere, and an address you’re careful with mostly stays clean.
That’s a cheap habit anyone can start today: one address for the people you know, another for everything that asks for one at checkout.
Players found 5,424 accounts sitting in at least one breach. Here’s how many of those they went on to fix in the same play.
That’s just under one in five. It’s an honest number, and it’s the one we most want to move. Finding the breach is the scary part. The fix is a few minutes in a settings menu. Some players surely fixed things the next day on a different device, which we wouldn’t see. Either way, between a red screen and a new password is where most of the work is left.
From September 25 to October 5:
Newer players are getting further. Among players who finished at least one mission, a quarter made it from scouting their accounts to locking them down, and 15% reached Reclaim, where you take back your privacy settings and your old posts (up from 10%). Part of that is new content. Since mid-September the city has had a year-by-year review of your old Facebook and Instagram history, and an OSINT Sieve that shows what a stranger could piece together about you from public posts. Players have worked through nearly a hundred stretches of their own posting history so far, one era at a time.
Data brokers already have the big picture. They know which addresses leaked, from where, and how often, and they sell it. Until now the people inside that picture have mostly seen only their own little corner of it, one red screen at a time.
Reclaim City flips that around a little. Every player who answers “how many breaches?” in a debrief helps everyone else see the shape of it: which addresses are exposed, how often, and how much is still left unfixed. We think that kind of knowledge should belong to the people it’s about.
— Multiverse Studios
Numbers cover September 7 – October 5, 2026, from Reclaim City’s anonymous gameplay events on our own self-hosted analytics. No ad networks, no third parties, no accounts. “Players” means anonymous browser sessions, so someone who plays on a phone and a laptop counts twice. Breach results are the answer players picked in the debrief (“none,” “1–2” or “3 or more”), and percentages leave out the people who chose to skip the question. We never see your address, your passwords or your accounts. “Fixed in the same play” means the same anonymous session went on to finish that account’s password or two-factor mission. You can switch sharing off any time on the Your City screen.
Reclaim City is free, runs in your phone’s browser, and needs no account.
Play Now → More devlogs