Inside the FICGS Breach: How 18,042 Chess Player Passwords Leaked
HEROIC analysts uncovered a dataset tied to FICGS, a United States based online chess and Go platform, during a routine dark web sweep. The breach itself dates back to August 26, 2018, and the data has continued to circulate on a cybercrime forum ever since. In total, 18,042 records were exposed, each pairing an email address with an MD5 hashed password.
Why This Is Dangerous
MD5 is one of the oldest and weakest password hashing algorithms still found in old breach data, and it was never built to withstand the cracking power available today. An attacker with this dataset can run the hashes through precomputed tables or GPU based cracking tools and recover a large share of the original passwords quickly. Once cracked, each recovered password is paired with a real email address, giving an attacker a working login pair to try elsewhere.
What Was Exposed
- Email addresses
- Password hashes (MD5)
Why This Matters
A breach at a chess platform might seem low stakes, but the real danger is password reuse, not the platform itself. If a FICGS player used the same email and password combination on their email provider, banking app, or social media account, a cracked credential from this leak becomes a skeleton key. This is exactly how credential stuffing works: automated tools take leaked pairs like these and test them against thousands of other sites, leading to account takeover, identity theft, and in some cases direct financial fraud.
How MD5 Hashing Fails Against Modern Cracking
FICGS stored passwords using MD5, a hashing method built in the early 1990s for data integrity checks, not password security. It produces the same output every time for the same input, has no built in slowdown, and can be brute forced billions of times per second on consumer graphics cards. Combined with rainbow tables, precomputed lists of hashes matched to common passwords, MD5 hashed credentials from a database dump like this one can often be cracked in bulk rather than one at a time, which is why breaches like this get repackaged into combolists and sold or shared on cybercrime forums.
Check If You Are Affected
If you ever created a FICGS account, or reused that password anywhere else, it is worth finding out what was exposed. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this one, and shows you exactly what data is out there so you can update any at risk passwords right away.
Breach Breakdown
18,042 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds