The GameTuts Breach Exposed 543,003 Accounts and Password Hashes
HEROIC analysts identified a 2015 breach of GameTuts, a video game website that later shut down in 2016, that exposed 543,003 accounts. The leaked data includes email addresses, usernames, IP addresses, and passwords protected with vBulletin's hashing format.
Why the GameTuts Breach Is Dangerous
vBulletin's older hashing format has long been within reach of common password-cracking tools. Given that this breach dates back roughly a decade, a significant portion of these password hashes have likely already been cracked and reused by attackers in other campaigns.
What Was Exposed in the GameTuts Breach
- Email addresses
- Usernames
- IP addresses
- Password hashes (vBulletin format)
Why This Matters
With over half a million accounts involved, this breach provides attackers with a large pool of credentials for automated credential stuffing attacks against email, social media, and other services. The fact that GameTuts shut down years ago does not reduce the risk, since many people never changed passwords they used there once the site went offline.
How This Database Breach Happened
This incident is classified as a database breach, meaning attackers extracted user records directly from GameTuts' vBulletin forum backend. Even after a breached site disappears, database dumps like this one continue circulating and getting repackaged on forums for years afterward.
Check If You Are Affected
If you ever had an account on GameTuts, it is worth checking whether your details were part of this leak. HEROIC's free breach scanner searches more than 400 billion leaked records, including this breach, so you can see your exposure right away.
Breach Breakdown
543,003 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds