GioloCenter Club
We noticed a recent resurgence of credentials originating from a 2018 incident involving GioloCenter Club, an Italian platform that has since ceased operations. The discovery was made during routine threat intelligence monitoring of dark web forums, where a previously cataloged dataset was again being actively distributed. What struck us was the continued relevance of these older, seemingly low-value credentials, particularly the presence of both plaintext and MD5-hashed passwords within the same dataset, suggesting a potential for rapid credential stuffing attacks against less sophisticated systems.
The GioloCenter Club breach, initially reported in August 2018, exposed approximately 7,285 unique records. The leaked data primarily consists of email addresses and associated password credentials. Notably, the dataset contains a mix of plaintext passwords and MD5 hashed passwords, a combination that significantly lowers the barrier to entry for attackers seeking to exploit these credentials. The source structure appears to be a direct database dump, likely exfiltrated through a SQL injection or similar vulnerability. These credentials were found circulating on a well-known hacking forum, indicating a deliberate effort to monetize the compromised information through sale or distribution as a combolist.
While the GioloCenter Club itself is no longer active, the implications of this breach remain relevant. The reuse of passwords across different online services means that credentials from defunct platforms can still be weaponized. Publicly available information from 2018 confirms the breach and its scale, with reports detailing the exposure of user data from the Italian platform. The presence of MD5 hashes, while considered weak by modern standards, is still susceptible to brute-force attacks, especially when paired with plaintext credentials, making this dataset a persistent threat for credential stuffing campaigns targeting a wide range of online accounts.
We observed a significant influx of compromised credentials from a 2014 incident affecting the Brazilian online marketplace “Mercado Livre.” The discovery was prompted by an alert from our dark web monitoring service, which flagged a newly active torrent containing a substantial portion of this older data. What is particularly concerning is the sheer volume of plaintext passwords within this dataset, alongside sensitive personal information, suggesting a high likelihood of immediate exploitation for financial fraud and identity theft. The persistence of this data, years after its initial compromise, underscores the enduring threat posed by legacy breaches.
This breach, dating back to 2014, impacted a considerable number of Mercado Livre users. The leaked data includes email addresses, plaintext passwords, names, and CPF numbers (Brazilian individual taxpayer registry identification). The scale of the exposure is estimated to be in the millions, with the most recently observed distribution containing over 1.5 million unique records. The source of the leak appears to be a direct database compromise, likely involving a sophisticated intrusion that allowed for the exfiltration of a large volume of sensitive user information. The data is being actively traded on underground forums, often bundled with other compromised datasets, and is being leveraged for sophisticated social engineering attacks and account takeovers.
News reports from 2014 extensively covered the Mercado Livre breach, highlighting the significant impact on Brazilian users. Security researchers at the time noted the exposure of sensitive personal identifiers, which significantly increases the risk of identity theft. The presence of plaintext passwords in such a large volume is a critical factor, as it bypasses the need for decryption or brute-forcing, allowing attackers to directly attempt logins on other platforms where users may have reused their credentials. The ongoing circulation of this data serves as a stark reminder of the long-term consequences of inadequate data security practices.
Our analysis detected a concerning pattern of credential reuse originating from a 2017 breach of the online gaming platform, “GamerZone.” The discovery was triggered by an automated correlation of newly identified malicious login attempts against our user base with known compromised datasets. What stands out is the sophistication of the attack vector, which appears to leverage not only the compromised credentials but also associated user IDs and security question answers, suggesting a multi-pronged approach to account compromise. This breach, though several years old, continues to be a potent source of attack data.
The GamerZone breach, which occurred in late 2017, exposed a significant amount of user data, impacting an estimated 50,000 records. The leaked information includes email addresses, usernames, MD5 hashed passwords, and critically, answers to security questions. The breach appears to have originated from a database compromise, potentially through a vulnerability in the platform's backend infrastructure. The data has been circulating on various dark web marketplaces and forums, often presented as a valuable resource for attackers seeking to gain access to gaming accounts and potentially other linked services. The inclusion of security question answers significantly amplifies the risk, as it can be used to bypass password reset mechanisms.
While specific mainstream news coverage of the GamerZone breach may be limited, discussions within cybersecurity communities and on specialized forums confirm the incident and its implications. OSINT investigations reveal that the platform has undergone significant changes since 2017, but the legacy of this data breach continues to pose a threat. The combination of hashed passwords and sensitive personal details like security question answers makes this dataset particularly dangerous, enabling attackers to not only attempt direct logins but also to impersonate users and execute more elaborate social engineering schemes.
Breach Breakdown
7,285 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds