101,753 Plaintext Passwords Dumped in Fortnite Combo
HEROIC identified a stealer log file labeled "Combo Fortnite New" being distributed on Telegram since March 2023. This massive dataset contains 101,753 compromised credential records compiled into a combo list specifically targeting Fortnite and Epic Games account users. Gaming accounts are highly prized in underground markets because they often contain rare cosmetic items, V-Bucks balances, and linked payment methods that can be exploited for profit.
Over 100,000 Passwords Exposed in Plain Sight
Every one of the 101,753 passwords in this dataset is stored in plaintext. No hashing, no encryption, no obfuscation of any kind. Attackers who download this combo list can immediately begin logging into Fortnite accounts and any other service where victims used the same credentials. The scale of this dump, exceeding 100,000 records, means it represents a significant portion of the Fortnite player base and constitutes a serious threat to the gaming community.
What Was Exposed
- Email Addresses — accounts linked to Epic Games, Fortnite, and potentially other gaming platforms
- Plaintext Passwords — fully readable login credentials ready for account takeover
- URLs — the gaming-related login pages and services where credentials were intercepted
Gaming Credentials Fuel a Thriving Black Market
Credential stuffing with Fortnite combo lists feeds a lucrative underground economy. Stolen accounts with rare skins, high-level battle passes, and substantial V-Bucks balances sell for significant sums on black market forums. Attackers also drain linked payment methods by purchasing in-game currency or gifting items to accounts they control. With 101,753 credential pairs to exploit, even accounts with minimal cosmetics have value when aggregated. Beyond Fortnite, these credentials are tested against every other Epic Games title and third-party service where victims may have reused their password.
How Gaming Credentials Get Stolen by Malware
The Fortnite player base is particularly vulnerable to infostealer malware because of the prevalence of fake tools marketed to gamers. Malware is commonly distributed through supposed Fortnite cheat engines, V-Bucks generators, account unlockers, and cracked game launchers. When players download these tools, the embedded infostealer malware activates, harvesting saved passwords from browsers, capturing Epic Games launcher credentials, and stealing session cookies. The collected data is compiled into gaming-specific combo lists and distributed through Telegram channels where account resellers and credential stuffing operators purchase them.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database indexes over 400 billion records from data breaches, stealer logs, and dark web marketplaces. Fortnite players and Epic Games users should use the HEROIC breach scanner to check whether their email or password appears in this combo list. If your credentials are found, change your Epic Games password immediately, enable two-factor authentication, review your account for unauthorized purchases, and remove any stored payment methods until your account is secured.
Breach Breakdown
101,753 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds