Breach Intelligence Report 12 Dec 2025

Inside the FICGS Breach: How 18,042 Chess Player Passwords Leaked

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 18,042
Source Type Database,Combolist
Origin Darkweb
Password Type MD5

HEROIC analysts uncovered a dataset tied to FICGS, a United States based online chess and Go platform, during a routine dark web sweep. The breach itself dates back to August 26, 2018, and the data has continued to circulate on a cybercrime forum ever since. In total, 18,042 records were exposed, each pairing an email address with an MD5 hashed password.

Why This Is Dangerous

MD5 is one of the oldest and weakest password hashing algorithms still found in old breach data, and it was never built to withstand the cracking power available today. An attacker with this dataset can run the hashes through precomputed tables or GPU based cracking tools and recover a large share of the original passwords quickly. Once cracked, each recovered password is paired with a real email address, giving an attacker a working login pair to try elsewhere.

What Was Exposed

  • Email addresses
  • Password hashes (MD5)

Why This Matters

A breach at a chess platform might seem low stakes, but the real danger is password reuse, not the platform itself. If a FICGS player used the same email and password combination on their email provider, banking app, or social media account, a cracked credential from this leak becomes a skeleton key. This is exactly how credential stuffing works: automated tools take leaked pairs like these and test them against thousands of other sites, leading to account takeover, identity theft, and in some cases direct financial fraud.

How MD5 Hashing Fails Against Modern Cracking

FICGS stored passwords using MD5, a hashing method built in the early 1990s for data integrity checks, not password security. It produces the same output every time for the same input, has no built in slowdown, and can be brute forced billions of times per second on consumer graphics cards. Combined with rainbow tables, precomputed lists of hashes matched to common passwords, MD5 hashed credentials from a database dump like this one can often be cracked in bulk rather than one at a time, which is why breaches like this get repackaged into combolists and sold or shared on cybercrime forums.

Check If You Are Affected

If you ever created a FICGS account, or reused that password anywhere else, it is worth finding out what was exposed. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this one, and shows you exactly what data is out there so you can update any at risk passwords right away.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5
Date Leaked 12 Dec 2025
Check in 5 seconds

18,042 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,360 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $130.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance