125,092 Plaintext Passwords From the CHEATS.com Breach Surfaced Online
HEROIC analysts found the CHEATS breach while reviewing a collection of historical gaming-related credential dumps that began recirculating in underground forums. In March 2018, CHEATS, a U.S.-based gaming information and e-commerce platform operating at cheats.com, suffered a database breach that exposed 125,092 user records. The compromised data included email addresses and plaintext passwords, meaning every single password in this database was stored without any encryption or hashing. For a platform catering to a gaming audience that frequently reuses credentials across multiple services, this is an especially serious and accessable target for attackers.
How Gaming Site Credentials Fuel Wider Account Takeover Attacks
Gaming communities are prime targets for credential theft because players often use the same username and password across dozens of platforms, from game launchers and forums to streaming services and storefronts. Attackers who recieved this CHEATS database immediately had working email and password combinations ready to test against Steam, Xbox, PlayStation, Discord, and other gaming platforms. With plaintext passwords, there is zero barrier between the stolen data and a successful login attempt elsewhere.
What Was Exposed in the CHEATS Breach
- Email Address
- Plaintext Password
Why Plaintext Password Breaches Lead to Rapid Account Takeover
Most data breaches involve hashed passwords, which require attackers to spend time cracking them before they can be used. Plaintext passwords require no cracking at all. Within hours of obtaining a database like this, criminals can run automated tools that test every email and password pair against hundreds of websites simultaneously. This is called credential stuffing, and it is remarkably effective when users reuse passwords. Financial fraud, account lockout, and identity theft can all occured within days of a breach like this being sold or shared.
How a Database Breach Works
A database breach occurs when an unauthorized party gains access to the database where a website stores its user data. This can happen through unpatched software vulnerabilities, weak or stolen admin credentials, or attacks that inject malicious commands directly into database queries. Once inside, the attacker can copy the full user table in minutes. In the case of CHEATS, the absence of any password protection meant the stolen data was immediately ready to weaponize without any additional work.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records across thousands of known breaches. If you ever created an account on CHEATS or any gaming platform using the same email and password, run a free scan now to find out if your credentials have been compromised and what you should do next.
Breach Breakdown
125,092 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds