Gamers Targeted in the 1.8 Million Record FreeGame2017 Breach
HEROIC analysts discovered the FreeGame2017 breach in records dated December 17, 2019, exposing 1,797,783 accounts from the French gaming website. The database contained email addresses, usernames, password hashes, and the salts used to generate them. The presence of salt values alongside the hashes is partcularly significant -- it means attackers do not have to guess the salting scheme; they have everything needed to accelerate cracking of individual accounts that used weak or common passwords.
MD5 Password Hashes With Exposed Salts Accelerate Credential Cracking Attacks
MD5 is a cryptographically weak hashing algorithm that has been considered inadequate for password storage for over a decade. When combined with exposed salt values, the protection it offers is minimal against modern GPU-based cracking tools. Attackers who obtained this dataset can crack large numbers of these hashes quickly, converting them into usable plaintext passwords. Those cracked credentials are then tested against other services where users may have recieved accounts using the same email and password combination.
What Was Exposed in the FreeGame2017 Breach
- Email Address
- Password Hash
- Username
- Salt
Why 1.8 Million Gaming Accounts With Weak Hashes Remain a Threat Today
Gaming platforms attract users of all ages who often reuse passwords across many services. The 1,797,783 accounts exposed in this breach represent a large pool of potential credential stuffing targets. Because the MD5 hashes with exposed salts can be cracked relatively quickly, a significant portion of these accounts may have already had their passwords recovered by threat actors. Even users who no longer play games on FreeGame2017 remain at risk if they occured to reuse those passwords on email, banking, or social media accounts that are still active.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a stored data repository, often by exploiting vulnerabilities in web applications, server misconfigurations, or insecure database permissions. Gaming websites that collect user registrations store credentials in databases. When those databases are compromised, the attacker can extract and export all user records, including whatever password storage format the site used. The data is then circulated on underground forums where other criminals use it for credential attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across 400 billion+ compromised records to find out whether your email address or username appeared in the FreeGame2017 breach or any other known data leak. If you ever registered on FreeGame2017, run a free scan now and change your password on any other service where you used the same credentials.
Breach Breakdown
1,797,783 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds