The Aternos Leak Contains Exactly 1,055,969 Minecraft User Records
HEROIC analysts identified a database breach connected to Aternos, a free Minecraft server hosting platform, dated October 31, 2015. The breach exposed 1,055,969 records, including usernames, email addresses, IP addresses, and passwords hashed with MD5.
Why the Aternos Breach Is Dangerous
MD5 hashing is fast to crack with modern hardware, so passwords in this dataset should be treated as effectively exposed. For a platform built around Minecraft server hosting, a compromised account can also mean an attacker gains control of a user's hosted server, its configuration, and any linked in-game community.
What Was Exposed in the Aternos Leak
- Usernames
- Email addresses
- IP addresses
- Passwords, hashed with MD5
Why This Matters
At over a million exposed accounts, this breach is large enough to fuel credential stuffing campaigns across gaming platforms, email providers, and beyond. Many Aternos users are younger players who may reuse the same simple password across multiple accounts, increasing the odds that a cracked password here unlocks something more valuable elsewhere.
How Database Breaches Like This Happen
A database breach means an attacker gained direct access to Aternos's backend storage and extracted the user table in bulk. The use of MD5, an algorithm considered weak even by 2015 standards, meant that once this data was exposed, cracking a large share of the passwords required little effort.
Check If You Are Affected
If you or your child ever created an Aternos account, check your exposure now. HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including this one, in seconds.
Breach Breakdown
1,055,969 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds