The Cheatsheet Creator Breach Contains Exactly 13,232 Email and Password Pairs
In August 2018, Cheatsheet Creator, a now-defunct United States-based online tool used by fantasy football enthusiasts to build reference sheets and draft cheatsheets, suffered a database breach. The compromised data, encompassing 13,232 unique records, was subsequently shared on a popular hacking forum. The precision of that number matters: 13,232 is not a rounded estimate. It is the exact count of individual accounts, each belonging to a real person who registered for a service they trusted with their email address and password. That data is still out there, still circulateing through cybercrime networks, and still being tested against other services today.
Why This Is Dangerous
What makes the Cheatsheet Creator breach particularly concerning is the password storage method. The dataset contains a mix of PHPass hashed passwords and, in some cases, plaintext passwords. PHPass is a password hashing framework historically associated with older WordPress and phpBB installations. While it is marginally better than raw MD5, it is still considered inadequate by modern standards and is susceptible to brute-force attacks using GPU-accelerated cracking tools. Plaintext passwords require no cracking at all. An attacker who obtains a plaintext password from a 2018 breach can test it against every major email provider, banking app, and social network in a matter of seconds using automated credential stuffing tools. The threat is not historical; it is ongoing and immediate for anyone who reused their Cheatsheet Creator password elsewhare.
What Was Exposed
- Email Addresses - Unique email addresses for each of the 13,232 affected accounts, usable for phishing, account enumeration, and targeted spam campaigns
- Password Hashes (PHPass / Plaintext) - A combination of PHPass hashed passwords and, in some cases, passwords stored in plaintext, making a significant portion of this dataset immediately actionable for attackers without any cracking required
Why This Matters
Fantasy sports platforms attract users who often maintain accounts across dozens of sports, gaming, and entertainment services, frequently using the same login credentials across all of them. A breach of a niche tool like Cheatsheet Creator is precisely the kind of low-profile exposure that victims never hear about. The platform is no longer active, which means there is no breach notification, no mandatory disclosure, and no reminder to change your password. The data circulates quietly in combolist compilations, merged with thousands of other small breaches into massive credential dumps that fuel industrial-scale account takeover operations. The 13,232 records in this dataset represent real attack surface that has been available to threat actors for over six years.
How Database Breaches Work
Database breaches at small online platforms like Cheatsheet Creator typically exploit vulnerabilities in web frameworks or content management systems. PHPass hashing was commonly deployed in applications built on older WordPress or phpBB codebases, suggesting the platform may have relied on a standard CMS installation with default or outdated security configurations. Attackers identify these targets through automated vulnerability scanning, exploit known weaknesses in the codebase, and extract the user table directly. The raw dump is then processed and uploaded to forums or sold in private markets. Because the platform is defunct, the breach went largely unnoticed and unaddressed, leaving 13,232 users with no warning and no recourse. This is the defining characteristick of small-site breaches: maximum impact on victims, minimum accountability for the operator.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion compromised records, including the exact 13,232 records from the Cheatsheet Creator breach. If you ever created an account on cheatsheetcreator.com, or if you used the same email and password combination on any other site, you should check your exposure right now. Enter your email address to receive instant results. If your credentials appear in this or any other breach, change the affected password immediately and enable two-factor authentication on every account where it is available.
Breach Breakdown
13,232 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds