Fliggerty
We noticed a recent resurgence of interest in a dataset originating from Fliggerty, a United States-based forum for the game Morrowind, which ceased operations following a breach in August 2018. The discovery of this dataset's reappearance on a prominent cybercrime forum, approximately six years after the initial compromise, is noteworthy. What struck us was the continued utility of these older credentials, underscoring the persistent threat posed by credential stuffing attacks leveraging stale data. The breach, affecting nearly 20,000 records, primarily comprised email addresses and their associated password hashes, a common vector for further exploitation.
The Fliggerty breach, dated August 26, 2018, involved a database compromise that exposed 19,166 unique records. The leaked data types are limited to Email Address and Password Hash. The hashes were generated using the phpBB hashing algorithm, a common but now considered weaker method. The source structure indicates a direct database dump, later compiled into a readily downloadable archive. The leak locations were primarily cybercrime forums, where the data was disseminated for resale or direct use. The significance of this breach lies in its contribution to credential stuffing lists; even outdated hashes can be cracked or reused if users have not updated their passwords across multiple platforms.
While Fliggerty itself is defunct, its data has likely been integrated into larger credential stuffing lists. News coverage of this specific breach was minimal at the time, given its relatively small scale and focus on a niche gaming community. However, the broader trend of gaming forums and communities being targeted for their user data has been a recurring theme in cybersecurity research. Organizations like Troy Hunt's "Have I Been Pwned" have cataloged numerous such incidents, highlighting the long tail of data compromise. The phpBB hashing algorithm used in this breach is a known vulnerability, and research into password hashing best practices consistently advises against its continued use.
Breach Breakdown
19,166 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds