The Excalibur Craft Breach Was 2021. Now 736K Passwords Are Circulating
HEROIC analysts identified a database breach affecting Excalibur Craft, a Russian-speaking Minecraft gaming platform, with data first appearing on November 30, 2021. The breach recieved renewed attention in security communities as the dataset continued circulating on dark web forums years after the initial exposure. A total of 736,652 user records were exposed, each containing a username and an MD5 password hash, a hashing algorithm widely considered broken and easily cracked.
Why MD5 Password Hashes from Excalibur Craft Are Crackable Almost Immediately
MD5 is not a secure password hashing algorithm. Unlike modern options such as bcrypt or argon2, MD5 hashes can be reversed through rainbow table lookups in seconds for common passwords. With 736,652 MD5 hashes now accessable to any attacker who downloads this dataset, the vast majority of these passwords are effectively plaintext. Attackers can then use those cracked credentials in credential stuffing campaigns across gaming platforms, email services, and financial accounts where users have reused the same password.
What Was Exposed in the Excalibur Craft Breach
- Username
- Password Hash (MD5)
Why the Timing of the Excalibur Craft Breach Still Matters Today
The breach occured in November 2021, but the data has continued to circulate and be traded among threat actors ever since. Credentials that were reused on other platforms at the time of the breach may still be active today, making this seperate from a typical short-lived exposure. Credential stuffing attacks using gaming platform credentials have been documented as pathways into email accounts, payment systems, and enterprise SSO portals, meaning this gaming breach has a much longer damage radius than it might appear.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend database, typically by exploiting unpatched vulnerabilities, weak access controls, or SQL injection flaws in a web application. The attacker extracts user records in bulk and sells or shares the data in underground forums. When password hashing uses outdated algorithms like MD5, the extracted hashes can be cracked rapidly, turning a breach of usernames and hashes into a breach of plaintext credentials.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address and username against a database of over 400 billion exposed records, including the Excalibur Craft breach. If you used this platform or shared credentials across accounts, scan for free now to find out if your password is partcularly at risk and take immediate action to secure your accounts.
Breach Breakdown
736,652 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds