Gamers Targeted: Gaming UHQ Part 4 Exposes 97,710 Passwords
HEROIC's threat intelligence systems discovered a gaming-focused stealer log collection labeled GAMING UHQ PART 4 being distributed on Telegram. Appearing in February 2023, this is part of a multi-volume series targeting gaming platform users, containing 97,710 records with email addresses, plaintext passwords, and the URLs of gaming services where these credentials were entered.
Plaintext Gaming Passwords Mean Instant Account Theft
All 97,710 passwords in this collection are stored in plaintext—no hashing, no encryption, no barrier between an attacker and your gaming accounts. Gaming credentials are highly prized in underground markets because compromised accounts often contain valuable digital assets: in-game currency, rare items, purchased game libraries, and linked payment methods. With plaintext access, attackers can log in immediately, transfer assets, and lock the original owner out.
What Was Exposed
- Email Addresses — accounts registered with gaming platforms, digital storefronts, and esports services
- Plaintext Passwords — unencrypted credentials curated for high-quality gaming account access
- URLs — login pages for gaming platforms, launchers, and online game services
Gaming Account Theft Extends Beyond Virtual Worlds
Credential stuffing with gaming credentials has consequences that extend well beyond losing a game account. Gamers who reuse their Steam, Epic, or Roblox password on email, banking, or cloud storage accounts give attackers a bridge from virtual entertainment to real-world financial harm. The 97,710 email-password pairs in this dump are tested against hundreds of services using automated tools, and each match opens a new avenue for fraud, from purchasing items with stored credit cards to accessing linked social media profiles.
Why Gaming Communities Are Prime Malware Targets
Gamers are disproportionately targeted by infostealer malware because of common distribution vectors within gaming communities. Free cheat engines, game cracks, mod tools, and "free skin generators" frequently contain hidden infostealer payloads. Malware like RedLine, Raccoon, or Lumma harvests all saved browser credentials and session cookies from infected gaming PCs. The stolen data is then organized into gaming-specific compilations like this UHQ series and sold to buyers specifically looking for accounts with valuable digital inventories.
Check If Your Credentials Were Exposed
HEROIC maintains one of the largest breach intelligence databases in the world, with over 400 billion records from data breaches, stealer logs, and dark web monitoring. Use HEROIC's free breach scanner to check whether your gaming email or any other account appears in the GAMING UHQ PART 4 dump or other known leaks. If your credentials are found, change your gaming platform passwords immediately, enable two-factor authentication on all gaming accounts, and review any linked payment methods for unauthorized charges.
Breach Breakdown
97,710 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds