If You Had a FACEIT Account in 2017, Your Password May Already Be Exposed
HEROIC analysts spotted the FACEIT breach while monitoring dark web marketplaces and breach aggregation sites for fresh activity on older gaming platform leaks. Sometime in 2017, the esports gaming platform FACEIT experienced a database compromise that exposed 230,705 user accounts. The breach included email addresses and passwords stored in plaintext, meaning the data was immediately useful to attackers with no cracking required. Our team noticed a spike in mentions of this dataset in threads focused on gaming account takeovers, suggesting it is still being actively used in attacks today.
Plaintext Passwords on a Gaming Platform Create Cross-Platform Risk
FACEIT is a competitive gaming platform connected to Steam and other gaming services. When attackers obtain a gaming account's plaintext password, they do not just gain access to the game account. They try that same password on the user's email, Steam account, and any other platforms where the person may have reused it. This is a classic credential stuffing scenario, and it is beleived that a large percentage of affected users had reused their FACEIT password on at least one other service, multiplying the damage far beyond the gaming platform itself.
What Was Exposed in the FACEIT Breach
- Email Address
- Plaintext Password
Why This Matters to Anyone Who Ever Used FACEIT
Even if you no longer use FACEIT, if you had an account in 2017 and have not changed that password everywhere you used it, your accounts remain at risk. Attackers do not delete old breach data. They keep using it. Credential stuffing tools can test the same leaked email and password pair against hundreds of websites in minutes. The result can be account takeover, unauthorized purchases, identity theft, and in some cases, access to workplace systems if people recieved the same password for personal and professional use.
How Database Breaches Work
A database breach happens when an attacker finds a way into the server or system where a company stores its user records. Common methods include exploiting unpatched software vulnerabilities, using stolen login credentials to access admin tools, or taking advantage of misconfigured servers. Once access is gained, the attacker can export millions of records quietly. When those records include plaintext passwords, the stolen data requires no additional processing before it can be used.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to check whether your email address appeared in the FACEIT breach or any other known data leak. Go to HEROIC.com and run a free scan to find out what information attackers may already have about you.
Breach Breakdown
230,705 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds