Names and Passwords Exposed. The ge.tt Breach Hit 1.7 Million Users.
HEROIC analysts uncovered the ge.tt breach while tracking a wave of older file-sharing service records that recieved fresh circulation on underground trading platforms in late 2017. The Danish file-sharing site ge.tt had its database accessed by a threat actor who walked away with 1,697,588 user records. The stolen data included real names, email addresses, and password hashes, giving criminals a detailed profile on each affected user. A well-known threat actor operating under the name Gnosticplayers claimed responsibility for the theft, which occured at the end of December 2017.
Why Real Names Plus Password Hashes Are a Dangerous Combination
When a breach includes both real names and password hashes, attackers have more to work with than just an email and a scrambled password. They can use the real name to craft convincing phishing messages, attempt password resets on other sites, or build a profile of the victim for identity theft. SHA1 hashes, the type used by ge.tt, are considered weak by modern standards and can often be cracked using widely available tools, turning those hashed passwords back into readable text that works on other websites.
What Was Exposed in the ge.tt Breach
- Email Address
- First Name
- Last Name
- Password Hash
Why the ge.tt Breach Still Creates Risk Years Later
Nearly 1.7 million records from a file-sharing site might not sound alarming, but the real names included in this breach make it seperate from a simple login dump. Attackers can combine names and emails to run targeted phishing campaigns or attempt account recovery attacks on other platforms. Credential stuffing, financial fraud, and identity theft all become more effective when the attacker knows who they are targeting by name. The ge.tt data continues to appear in aggregated breach collections used by automated attack tools.
How a Database Breach Works
A database breach occurs when an attacker finds a vulnerability in a website or its underlying server software and uses it to gain unauthorized access to stored user data. The attacker copies the database contents and exits, often without setting off any alarms. The site continues running normally while the stolen data is quietly moved to private channels and later sold or published on dark web forums.
Check If Your Data Was Exposed
HEROIC runs a free breach scanner supported by a database of over 400 billion compromised records. Enter your email address to see whether your information appeared in the ge.tt breach or any of the thousands of other incidents we track. Find out before someone else uses your data against you.
Breach Breakdown
1,697,588 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds