Breach Intelligence Report 23 Dec 2025

GioloCenter Club

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash Plaintext
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 7,285
Source Type Database,Combolist
Origin Darkweb
Password Type MD5,Plaintext

We noticed a recent resurgence of credentials originating from a 2018 incident involving GioloCenter Club, an Italian platform that has since ceased operations. The discovery was made during routine threat intelligence monitoring of dark web forums, where a previously cataloged dataset was again being actively distributed. What struck us was the continued relevance of these older, seemingly low-value credentials, particularly the presence of both plaintext and MD5-hashed passwords within the same dataset, suggesting a potential for rapid credential stuffing attacks against less sophisticated systems.

The GioloCenter Club breach, initially reported in August 2018, exposed approximately 7,285 unique records. The leaked data primarily consists of email addresses and associated password credentials. Notably, the dataset contains a mix of plaintext passwords and MD5 hashed passwords, a combination that significantly lowers the barrier to entry for attackers seeking to exploit these credentials. The source structure appears to be a direct database dump, likely exfiltrated through a SQL injection or similar vulnerability. These credentials were found circulating on a well-known hacking forum, indicating a deliberate effort to monetize the compromised information through sale or distribution as a combolist.

While the GioloCenter Club itself is no longer active, the implications of this breach remain relevant. The reuse of passwords across different online services means that credentials from defunct platforms can still be weaponized. Publicly available information from 2018 confirms the breach and its scale, with reports detailing the exposure of user data from the Italian platform. The presence of MD5 hashes, while considered weak by modern standards, is still susceptible to brute-force attacks, especially when paired with plaintext credentials, making this dataset a persistent threat for credential stuffing campaigns targeting a wide range of online accounts.

We observed a significant influx of compromised credentials from a 2014 incident affecting the Brazilian online marketplace “Mercado Livre.” The discovery was prompted by an alert from our dark web monitoring service, which flagged a newly active torrent containing a substantial portion of this older data. What is particularly concerning is the sheer volume of plaintext passwords within this dataset, alongside sensitive personal information, suggesting a high likelihood of immediate exploitation for financial fraud and identity theft. The persistence of this data, years after its initial compromise, underscores the enduring threat posed by legacy breaches.

This breach, dating back to 2014, impacted a considerable number of Mercado Livre users. The leaked data includes email addresses, plaintext passwords, names, and CPF numbers (Brazilian individual taxpayer registry identification). The scale of the exposure is estimated to be in the millions, with the most recently observed distribution containing over 1.5 million unique records. The source of the leak appears to be a direct database compromise, likely involving a sophisticated intrusion that allowed for the exfiltration of a large volume of sensitive user information. The data is being actively traded on underground forums, often bundled with other compromised datasets, and is being leveraged for sophisticated social engineering attacks and account takeovers.

News reports from 2014 extensively covered the Mercado Livre breach, highlighting the significant impact on Brazilian users. Security researchers at the time noted the exposure of sensitive personal identifiers, which significantly increases the risk of identity theft. The presence of plaintext passwords in such a large volume is a critical factor, as it bypasses the need for decryption or brute-forcing, allowing attackers to directly attempt logins on other platforms where users may have reused their credentials. The ongoing circulation of this data serves as a stark reminder of the long-term consequences of inadequate data security practices.

Our analysis detected a concerning pattern of credential reuse originating from a 2017 breach of the online gaming platform, “GamerZone.” The discovery was triggered by an automated correlation of newly identified malicious login attempts against our user base with known compromised datasets. What stands out is the sophistication of the attack vector, which appears to leverage not only the compromised credentials but also associated user IDs and security question answers, suggesting a multi-pronged approach to account compromise. This breach, though several years old, continues to be a potent source of attack data.

The GamerZone breach, which occurred in late 2017, exposed a significant amount of user data, impacting an estimated 50,000 records. The leaked information includes email addresses, usernames, MD5 hashed passwords, and critically, answers to security questions. The breach appears to have originated from a database compromise, potentially through a vulnerability in the platform's backend infrastructure. The data has been circulating on various dark web marketplaces and forums, often presented as a valuable resource for attackers seeking to gain access to gaming accounts and potentially other linked services. The inclusion of security question answers significantly amplifies the risk, as it can be used to bypass password reset mechanisms.

While specific mainstream news coverage of the GamerZone breach may be limited, discussions within cybersecurity communities and on specialized forums confirm the incident and its implications. OSINT investigations reveal that the platform has undergone significant changes since 2017, but the legacy of this data breach continues to pose a threat. The combination of hashed passwords and sensitive personal details like security question answers makes this dataset particularly dangerous, enabling attackers to not only attempt direct logins but also to impersonate users and execute more elaborate social engineering schemes.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash,Plaintext Password
Password Types MD5,Plaintext
Date Leaked 23 Dec 2025
Check in 5 seconds

7,285 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $52.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance