Games-News
We noticed a recent resurfacing of credentials originating from a 2018 incident involving the German gaming news platform, Games-News. This particular breach, which occurred on August 26, 2018, involved the exposure of 5,520 records. What struck us was the continued utility of these older, MD5-hashed passwords within contemporary credential stuffing attacks, underscoring the persistent risks associated with weak hashing algorithms and the long tail of compromised data. The data set, comprising email addresses and their corresponding password hashes, was initially disseminated on a well-known hacking forum.
The Games-News breach, classified as a database compromise, saw the exfiltration of 5,520 user records. The exposed data included plaintext email addresses and MD5-hashed passwords. This type of exposure is particularly concerning as MD5, while considered outdated and cryptographically weak, remains susceptible to brute-force attacks and rainbow table lookups, especially when paired with common password patterns. The compromised data was subsequently made available on a prominent underground forum, likely contributing to its inclusion in various credential stuffing lists that continue to be leveraged by threat actors. The source structure of the leak suggests a direct database dump or a similar extraction method, highlighting a potential vulnerability in the platform's data storage or access controls at the time.
While this specific incident from 2018 did not garner significant mainstream media attention at the time of its occurrence, it is representative of a broader trend of older, less secure data being weaponized. Research into credential stuffing attacks consistently shows that compromised credentials from breaches dating back several years remain highly effective. The use of MD5 hashing in this instance is a stark reminder of the importance of employing modern, robust hashing algorithms like bcrypt or Argon2 to mitigate the risk of password cracking, even for data that is no longer actively managed by the compromised entity.
Breach Breakdown
5,520 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds