ConsoleCrunch
We've been tracking the increasing volume of exposed developer credentials circulating on Telegram channels, and a recent dump related to ConsoleCrunch, a cloud-based gaming platform, caught our attention. What really struck us wasn't the size of the breach – though 2.4 million records is significant – but the nature of the data and its potential impact on the gaming ecosystem. The data included not just usernames and hashed passwords, but also API keys, internal server addresses, and potentially sensitive game development data. This information could be leveraged for account takeovers, game modification, or even attacks on ConsoleCrunch's infrastructure.
ConsoleCrunch: 2.4M Records Expose API Keys and Internal Server Details
A breach impacting 2.4 million ConsoleCrunch users has surfaced on a popular hacking forum. The data, initially observed circulating on a private Telegram channel dedicated to compromised credentials, was subsequently posted on a more public forum, amplifying its reach. While breaches of gaming platforms are not uncommon, the inclusion of API keys and internal server addresses within this dataset differentiates it from typical user credential dumps. This could allow malicious actors to bypass normal authentication mechanisms and directly access ConsoleCrunch's backend systems.
Breach Stats:
* **Total records exposed:** 2,400,000
* **Types of data included:** Email addresses, usernames, hashed passwords, API keys, internal server addresses, potentially game development data
* **Sensitive content types:** API keys, server addresses, potentially proprietary game code snippets
* **Source structure:** JSON dump
* **Leak location(s):** Telegram channel (private), Breach Forums
The breach initially surfaced on a private Telegram channel on October 26, 2024, according to our monitoring. We observed threat actors discussing the potential value of the API keys for unauthorized access and manipulation of game data. A few days later, on October 29, 2024, a user posted a link to the data on a well-known breach forum. The post received considerable attention, with multiple users confirming the validity of the exposed credentials.
This breach matters to enterprises for several reasons. First, it highlights the growing risk of API key compromise. API keys are often treated as less sensitive than passwords, but they can provide direct access to critical systems. Second, it underscores the importance of securing internal server addresses. Exposure of this information can make it easier for attackers to map out a company's infrastructure and identify potential vulnerabilities. Finally, it demonstrates the speed at which compromised data can spread across different online communities, increasing the potential for misuse. This incident is a stark reminder of the broader threat landscape, where stolen credentials and leaked API keys are increasingly weaponized to automate attacks against organizations.
Breach Breakdown
68,810 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds