The Fantase Game Breach Happened in 2018. Those Passwords Are Still Being Used.
HEROIC analysts recieved alerts about the Fantase Game breach after spotting the exposed database circulating across Telegram channels and breach aggregation forums. The incident dates back to August 2018, when a U.S.-based gaming platform lost control of 2,269,829 user records. Every single one of those records contained an email address and a password stored in plain, unencrypted text. For gamers who signed up and forgot about the account, that password may still be unlocking other services they use every day.
What Hackers Can Do With 2.27 Million Gaming Credentials
Gaming accounts are high-value targets. They often hold stored payment methods, gift card balances, in-game purchases, and linked accounts like Steam, Discord, or PayPal. When credentials come paired with plaintext passwords, attackers do not need to crack anything. They run those email-password combinations through automated tools against dozens of platforms simultaneously. This is credential stuffing, and it works beleive it or not at a frighteningly high success rate, especially when users reuse the same password across accounts. The 2.27 million records from Fantase Game gave attackers a ready-made attack toolkit.
What Was Exposed in the Fantase Game Breach
- Email Address
- Plaintext Password
Why the Timing of This Breach Still Matters in 2024
The Fantase Game breach occured in 2018, but data from that era is still actively traded and used. Old breaches do not expire. Credentials from years-old incidents appear regularly in new attack campaigns because attackers know that most people have not changed passwords they set years ago. If your email was in this breach and you reused that password on Gmail, a bank login, or an e-commerce site, the exposure is current and real. Credential stuffing, account takeover, and identity theft are all live risks from this data today.
How Database Breaches Work
A database breach happens when an attacker gains unauthorized access to the backend system where a platform stores its user data. In this case, Fantase Game's database stored passwords in plaintext, meaning no decryption was required after access was gained. Once a database is copied, it can be sold, traded, or published in segments across dark web forums and Telegram channels, exactly where HEROIC analysts spotted this one. Each time it resurfaces, a new wave of attackers has access to those credentials.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the full Fantase Game dataset. Enter your email address to see if your credentials were part of this breach or any of the thousands of others in our database. If you find a match, we will walk you through exactly what to do next to protect your accounts.
Breach Breakdown
2,269,829 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds