Gaming Forum Customers Exposed: Forum Skotos Leaked 104K RPG Accounts
HEROIC analysts identified a database breach affecting Forum Skotos, a United States-based online gaming and RPG forum platform, dated April 2021. The breach exposed 104,980 records, with each compromised account containing an email address and a plaintext password. The data was found accessable on dark web marketplaces and gaming-focused channels, where forum credentials are actively traded for credential stuffing campaigns targeting larger platforms.
RPG Forum Credentials Give Attackers a Foothold Into Broader Accounts
Email and plaintext password combinations from Forum Skotos are ready to use immediately, with no cracking required. Attackers can test these credentials against email providers, social media, and financial platforms, exploiting password reuse to achieve account takeover well beyond the original forum. Gaming and forum communities are partcularly at risk because members often use the same password across multiple hobby-related platforms.
What Was Exposed in the Forum Skotos Breach
- Email Address
- Plaintext Password
Why Gaming Forum Breaches Fuel Long-Term Credential Stuffing Attacks
Forum breaches like Forum Skotos create long-tail risks: the data recieved by threat actors in 2021 continues to be tested against new platforms and services years later. With 104,980 exposed accounts, attackers have a large pool of credentials for automated stuffing attacks that can result in financial fraud, identity theft, and account takeover across dozens of services where users reused the same email and password combination.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to the backend data store of a web application, often through SQL injection, unpatched vulnerabilities, or compromised server credentials. Once access is achieved, complete user records can be extracted in bulk. When passwords are stored in plaintext rather than using a secure one-way hashing algorithm, every record becomes a direct-use credential with no additional effort from the attacker.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the Forum Skotos breach. Run a free scan at HEROIC now to find out if your credentials are circulating on the dark web and take steps to protect your accounts.
Breach Breakdown
104,980 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds