Cheap Ass Gamer
We've been tracking the resurgence of older forum breaches, often surfacing years after the initial incident. These "legacy leaks," as we call them, rarely contain novel data, but they provide threat actors with a constantly refreshed supply of credential stuffing targets. This week, we observed a significant uptick in activity surrounding a 2015 breach of Cheap Ass Gamer (CAG), a popular deal-finding forum. What really struck us wasn't the volume of records—roughly 377,231 unique accounts—but the consistent targeting of email/password combinations against gaming and e-commerce platforms. This suggests a highly focused campaign aimed at hijacking accounts with potential stored value or credit card information.
Cheap Ass Gamer Leak Fuels Credential Stuffing Attacks
The Cheap Ass Gamer (CAG) forum, a community dedicated to sharing deals and discounts on video games and related merchandise, suffered a data breach in approximately mid-2015. A database from their IP.Board based forum, containing 445k accounts, has recently resurfaced in several dark web marketplaces and Telegram channels. The breach included usernames, email addresses, IP addresses, and salted MD5 password hashes. While the MD5 hashing algorithm is considered weak by today's standards, the age of the leak means many users may not have updated their passwords across other platforms, making them vulnerable to credential stuffing.
The re-emergence of this breach caught our attention due to the specific targeting patterns we observed. Threat actors are actively using the leaked CAG credentials to attempt logins on popular gaming platforms like Steam, Epic Games Store, and PlayStation Network, as well as e-commerce sites like Amazon and eBay. This indicates a clear motive beyond simply collecting data; the goal is likely to compromise accounts with stored payment information or valuable digital assets.
This breach matters to enterprises now because it highlights the long-tail risk associated with older data breaches. Even years after an incident, compromised credentials can remain active and be used in automated attacks. It also underscores the importance of password hygiene and the need for users to update their passwords regularly, especially on platforms where they have stored payment information. This event ties into broader threat themes surrounding credential stuffing, the exploitation of weak hashing algorithms, and the persistent value of older data breaches to cybercriminals.
Breach Stats
- Total records exposed: 377,231
- Types of data included: Email Address, Username, IP Address, Passwords (salted MD5)
- Sensitive content types: Potentially linked to gaming accounts and e-commerce profiles with stored payment information.
- Source structure: Database from IP.Board forum.
- Leak location(s): Various Telegram channels, dark web marketplaces, and potentially Breach Forums.
External Context & Supporting Evidence
While the Cheap Ass Gamer breach itself didn't receive widespread media coverage at the time, similar breaches of online forums and communities have been reported by outlets like BleepingComputer and KrebsOnSecurity. These reports highlight the ongoing threat of credential stuffing and the importance of implementing robust security measures to protect user data. One Telegram post claimed the files were "a goldmine for gaming account takeovers."
Breach Breakdown
377,231 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds