Habbo
We've been tracking an uptick in credential stuffing attacks targeting online gaming platforms, and what started as routine monitoring took an unexpected turn when we identified a substantial leak originating from Habbo, the virtual world popular with teens and young adults. What really struck us wasn't the volume of records, although significant, but the age of the platform and the potential for compromised accounts to contain a trove of personal information accumulated over years of user activity. The data had been circulating on a relatively obscure forum, but the potential reach, combined with the enduring popularity of Habbo, raised immediate concerns. The setup here felt different because the exposed information wasn't just about current accounts; it offered a glimpse into a digital past for many users.
The virtual hotel with real-world risks: 1.7M Habbo accounts exposed
A significant data breach has exposed approximately 1.7 million user accounts from Habbo, the long-running online virtual world. The leaked data includes a mix of usernames, email addresses, hashed passwords, and other account-related information. We discovered the leak while monitoring underground forums known for trading compromised credentials. What caught our attention was the structured format of the data and the specific targeting of a platform with a large, and often younger, user base. This breach matters to enterprises because it highlights the enduring risk associated with legacy platforms and the potential for old breaches to be resurrected and exploited. It also underscores the importance of robust password management and account security practices, particularly for services that cater to younger demographics.
- Total records exposed: 1,783,389
- Types of data included: Usernames, email addresses, salted & hashed passwords (SHA-1), registration IPs, creation dates, avatars, and other account metadata.
- Sensitive content types: Potentially PII depending on user profiles.
- Source structure: SQL database export.
- Leak location(s): A now-defunct forum dedicated to data trading and leaks.
The breach appears to have surfaced sometime in late 2023, though it may represent older, previously unreleased data. A user on the forum offered the data for sale, claiming it was a complete dump of the Habbo user database from an unspecified date. The passwords, while hashed, were using the outdated SHA-1 algorithm, making them susceptible to cracking with modern techniques. The inclusion of registration IPs adds another layer of potential risk, as it could be used to identify users and their locations at the time of account creation.
Security researcher Troy Hunt added the breached data to Have I Been Pwned, confirming the validity of the records and allowing users to check if their Habbo accounts were compromised. This public acknowledgement lends further credibility to the breach and highlights the potential impact on a wide range of users. As Hunt notes, the re-emergence of old data breaches is a common phenomenon, often driven by attackers seeking to profit from previously unexploited credentials. This incident aligns with broader threat themes related to credential stuffing and the monetization of stolen data on underground marketplaces. The risk extends beyond individual users; organizations should be aware that employees who used corporate email addresses to register on Habbo may now be at increased risk of targeted attacks.
Breach Breakdown
612,047 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds