Bitgamer
We've been tracking the resurgence of older forum databases appearing on Telegram channels dedicated to credential stuffing, and one recent dump stood out due to its age and the relatively low level of encryption used. What really struck us wasn't the size of the breach, but the clear text passwords included for a significant portion of the user base. This represents a potential goldmine for attackers targeting older accounts that may have reused credentials across multiple services. The data had been circulating quietly for a few weeks, but we noticed increased chatter among threat actors discussing successful account takeovers.
Bitgamer: A blast from the past spills 1.5M records with plaintext passwords
The compromised data originates from Bitgamer, a now-defunct online community centered around video game piracy, active primarily in the late 2000s and early 2010s. The breach involves a database dump containing approximately 1.5 million user records. We first observed mentions of the database on a Telegram channel known for aggregating and distributing leaked credentials on October 26th, 2024. What caught our attention was the presence of a significant number of accounts with passwords stored in plaintext, a practice considered highly insecure even by the standards of the time. This significantly lowers the barrier to entry for attackers attempting to compromise user accounts across other platforms.
The breach matters to enterprises now because it illustrates the long tail of security risk. Users who were active on Bitgamer over a decade ago may still be using the same or similar passwords on current accounts, including those associated with corporate email, SaaS applications, and other sensitive services. This type of breach highlights the importance of proactive credential monitoring and employee education around password reuse.
- Total records exposed: 1,472,883
- Types of data included: Usernames, email addresses, IP addresses, password hashes (MD5 and plaintext), forum posts, private messages.
- Sensitive content types: Potentially personal messages and forum posts, IP addresses that could be used for geolocation.
- Source structure: SQL database dump.
- Leak location(s): Telegram channels, various dark web forums.
Independent security researcher Troy Hunt has added the Bitgamer breach to Have I Been Pwned, allowing users to check if their email address was part of the leak. This public awareness can drive password resets and improve overall security posture. On a related note, the re-emergence of older breaches aligns with a broader trend of threat actors focusing on historical data for credential stuffing attacks. As older websites and services shut down, their databases become vulnerable to compromise and subsequent leakage, posing a persistent threat to individuals and organizations alike. One Telegram post claimed the files were "collected after a forum admin left the server exposed." This underscores the continued importance of secure data disposal practices, even for defunct online communities.
Breach Breakdown
41,224 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds