5201 INTERWEBZ Breach: Gaming Cheats Platform Compromised
We've been tracking a resurgence of older breaches appearing on newer platforms, often repackaged and resold to less sophisticated actors. What caught our attention wasn't the scale of the **INTERWEBZ** breach itself, but the fact that it was surfacing again almost a decade after the initial incident. This highlights the long tail of data breaches and the continued risk posed by even relatively small leaks if the compromized credentials are still valid or reused elsewhere. The data, though limited in scope, provides a valuable snapshot of the threat landscape from 2015 and the hashing practices prevalent at the time.
The Resurfaced INTERWEBZ Breach: 5.2k Gamers Exposed
The **INTERWEBZ** breach, originally dating back to **June 2015**, involved the compromise of a database associated with a CSGO (Counter-Strike: Global Offensive) cheats website. The breach was rediscovered during our routine monitoring of dark web forums where older data dumps are frequently traded. The significance lies less in the immediate impact and more in the persistant availability of this data for credential stuffing attacks against potentially still-active accounts or related services. This re-emergence underscores the enduring value of even relatively small breaches to malicious actors.
The breach data includes usernames, email addresses, IP addresses, and password hashes. The passwords were stored using **IPB (Invision Power Board)** hashes, which, while not the weakest of hashing algorithms, are still susceptible to cracking with modern hardware and techniques. The relatively small size of the breach – **5,201** records – initially led us to dismiss it, but the consistent reappearence of this data on various platforms, including Telegram channels dedicated to gaming account compromises, suggests it's being actively leveraged.
Breach Stats:
- Total records exposed: 5,201
- Types of data included: Email Address, Username, IP Address, Password Hash, Salt
- Sensitive content types: Email addresses, Password hashes, IP addresses
- Source structure: Database export (likely SQL)
- Leak location(s): Dark web forums, Telegram channels
- Date leaked: June 1, 2015 (initially); resurfaced in Q1 2024
The **INTERWEBZ** breach has been previously documented on data breach notification sites like Have I Been Pwned?, confirming its initial exposure in 2015. The re-circulation of this data aligns with a broader trend of threat actors compiling and trading older breaches for password reuse attacks. This data is often combined with newer breaches to increase the chances of successful account takeovers. As noted by security researcher Troy Hunt, older breaches are often a goldmine for attackers due to password reuse. This breach is just one example of that.
Breach Breakdown
5,201 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds