The Duelyst Breach Put 207 Hashed Passwords and Emails Online in 2016
HEROIC analysts identified a database breach affecting Duelyst, a now-defunct online card game, dating back to February 26, 2016. The exposed file is small compared to major breaches, containing 207 records, but it includes email addresses, usernames, IP addresses, and passwords stored as sha256crypt hashes.
Why the Duelyst Breach Still Matters
Only 207 accounts were affected, which is a small number next to breaches that expose millions of records. But size is not the only measure of risk. Anyone in this data set who reused their Duelyst email, username, or password on another account is exposed regardless of how few other people were affected alongside them.
What Was Exposed in the Duelyst Breach
- Email addresses
- Usernames
- IP addresses
- Passwords (stored as sha256crypt hashes)
Why This Matters
Unlike breaches where passwords are stored in plain text, Duelyst's passwords were hashed with sha256crypt, which means an attacker cannot read them directly. However, hashed passwords are not unbreakable. Attackers can run password-cracking tools against hashes, especially for common or weak passwords, and eventually recover the original password. Combined with the email address and IP address also present in this leak, a cracked password becomes a starting point for credential stuffing attempts against other accounts.
How This Database Breach Happened
This incident has the signature of a direct database export, meaning an attacker gained access to Duelyst's backend and pulled the user table directly rather than collecting credentials one at a time. The fact that passwords were hashed shows the developers followed better security practices than many of the breaches HEROIC tracks, but a hash is only as strong as the password behind it. Weak or reused passwords can still be cracked with time and the right tools.
Check If You Are Affected
Even small, old breaches like this one are worth checking, especially if you have ever reused a password across multiple accounts. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, so you can see exactly where your information has appeared and update any passwords still at risk.
Breach Breakdown
207 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds