If You Joined the WPT Amateur Poker League, Check Your Password
HEROIC analysts have recorded a database breach affecting the WPT Amateur Poker League, the amateur arm of the World Poker Tour, dated January 4, 2014, involving 148,210 exposed records. According to the incident record, the site was hacked by a Twitter user known as @smitt3nz, who publicly disclosed the accounts along with plaintext passwords for each. The exposed data on record is email addresses and plaintext passwords.
Why Plaintext Passwords Make This Worse
Because the passwords were never hashed or encrypted, whoever obtained this data could read and use every single password immediately, with no cracking required. That is a meaningfully higher level of risk than a breach involving hashed passwords, and it means the window between the breach and actual account compromise was effectively zero.
What Was Exposed in the WPT Amateur Poker League Breach
- Email addresses
- Plaintext passwords
Why This Matters
Poker platforms are tied to real names, payment methods, and sometimes linked bank accounts, so a compromised login is not just an inconvenience, it is a potential path to financial fraud. Because the passwords were plaintext and instantly usable, attackers could move straight to credential stuffing, testing the same email and password combination against banking sites, email providers, and other online accounts without needing to crack anything first.
How This Type of Breach Happens
This incident is classified as a database breach, meaning an individual attacker gained direct access to the website's backend and extracted the full user table rather than targeting people one at a time. The fact that a single, publicly identified individual was able to carry out this breach and dump plaintext passwords for 148,210 accounts underscores how a single unpatched vulnerability can expose an entire user base at once.
Check If You Are Affected
If you ever had an account with the WPT Amateur Poker League, change that password everywhere you may have reused it and check your broader exposure. HEROIC's free breach scanner searches more than 400 billion breached records to show you instantly what has been exposed under your email address.
Breach Breakdown
148,210 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds